Skip to content
A person operating a slots game on a handheld tablet.

Platform

National Platform for Countering Illegal Online Gambling

A closed loop that runs from discovery to verified effect. Each step produces a record; each record supports the next decision; the cycle repeats continuously rather than campaign by campaign.

The closed loop

Eight steps, run continuously

The value is not in any single step but in the loop closing. Detection without verification produces lists; verification without measurement produces activity reports. The full cycle produces enforcement that can be demonstrated.

  1. 1

    Detect

    Continuous discovery from certificate transparency logs, newly registered domain feeds, search APIs, passive DNS, advertising libraries, app store catalogues, typosquat generation and public complaints. Discovery runs constantly rather than in periodic sweeps, so a new domain is a candidate from the moment it becomes observable.

  2. 2

    Enrich

    Within five minutes each candidate is enriched with registration data, DNS history, infrastructure and hosting, full page and screenshot capture as seen from inside the country, payment methods offered and localisation signals. Capture from inside the jurisdiction matters: what a domestic player is shown is the fact in issue.

  3. 3

    Score

    Deterministic, fully logged rules produce the assessment, with an optional machine-learning ranking layer that orders the queue by likelihood of relevance. The ranking layer can never be the sole basis for a decision, and the rule path that produced a score is reproducible after the fact.

  4. 4

    Decide

    An authorised official lists the domain. The analyst who prepared the recommendation cannot approve it. The decision record captures the official's identity, the timestamp, the evidence set relied on and the statutory provision applied.

  5. 5

    List

    The decision is published to a signed, versioned register within fifteen minutes, with reasons and a statutory citation. Every version of the register is retained and signed, so the state of the list on any past date can be reconstructed exactly.

  6. 6

    Enforce

    Five simultaneous pressure points: access, payment, advertising, app distribution and hosting infrastructure. Acting on one channel alone is absorbed by the operator; acting on all five at once removes the routes to the player and the routes to the money at the same time.

  7. 7

    Verify

    Probes inside the country confirm the block held, at every provider, every day. Verification is independent of provider self-reporting, and a lapse is raised as an exception with the date, the provider and the observed behaviour.

  8. 8

    Measure

    Channelisation, false-positive rate and provider implementation are reported quarterly. Measuring the false-positive rate as openly as the enforcement volume is what keeps the register credible with courts, providers and the public.

Data model

Three registers, one framework

The registers are interconnected rather than parallel. A domain decision immediately gives a bank grounds to act, and a licence status change automatically changes a domain's legal status.

Licensed operators

The authoritative record of who holds a licence, for which products, under which conditions and for what period. Everything downstream resolves against it.

Illegal websites

Domains listed by official decision, with reasons, statutory citation, evidence references and version history.

Payment merchants

Merchant identities and acquiring relationships associated with listed domains, so financial-sector action rests on the same evidentiary record as the listing.

Because the three registers share one identity model, an enforcement action does not have to be re-argued in each sector. The same decision record that supports an access restriction supports the payment intervention and the advertising takedown.

Scope

Boundaries we set deliberately

A system that reaches further than its mandate is harder to defend and easier to challenge. These limits are designed in, and they are a source of strength.

  • It does not inspect citizens' traffic or perform deep packet inspection.

  • It does not process players' personal data in the enforcement perimeter.

  • It does not install state equipment in provider networks.

  • The provider applies the block on its own resolvers using a standard response policy zone that needs no new equipment.

The narrower perimeter also lowers the operational burden on providers. Implementation uses a standard mechanism the provider already operates, which shortens onboarding and removes the argument that compliance requires capital expenditure.

Request a technical briefing

We brief regulators, ministries and licensing authorities on the architecture, evidentiary model and delivery sequence in detail.

Request a briefing