Specialized offensive security for betting operators, online casinos and gaming platforms — RNG, KYC, AML and regulatory compliance.
Why now
Brazil's regulated betting market (Law 14.790/2023) puts operators under daily scrutiny. Bonus fraud, multi-accounting, bots, RTP manipulation and DDoS attacks against the platform can cost the SPA/MF license and millions in fraud.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Random number generator validation, theoretical vs practical RTP, seed manipulation.
Registration bypass, deepfake, money mule accounts, multi-accounting.
Farming detection, cashback abuse, rollover bypass.
PIX, deposit/withdrawal, AML, threshold rules.
Internal access, balance manipulation, administrative adjustments.
Client reverse engineering, bot detection, communication integrity.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Dedicated iGaming page already on the site (Pentest for iGaming).
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. We operate aligned to the GLI certifications required for licensing in multiple jurisdictions.
Yes. The pentest can be part of the technical dossier for the Secretariat of Prizes and Bets of the Ministry of Finance.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.