iGaming Platform Uptime, SLA & Incident Record
Contractual uptime, dated availability, broader production history and incident recovery answer different questions. This ledger keeps those conclusions separate and leaves non-established terms unresolved.
Last updated August 20, 2026
Three different reliability layers
An uptime target is not necessarily a contractual guarantee. A contractual percentage does not show measured availability, and neither proves fast recovery or a meaningful customer remedy. Procurement must establish the measured service, exclusions, maintenance treatment, severity clocks, restoration target, service credits and termination rights as separate terms.
4
contractual uptime conclusions
5
availability or SLA conclusions
1
usable RPO/RTO conclusions
Availability and remedies
| Provider | Score | Contractual SLA | Availability / SLA evidence | Operating record | Technical incident response | Service credits |
|---|---|---|---|---|---|---|
| EveryMatrix | 8.8 | Unresolved Guaranteed uptime threshold and standard service-credit trigger remain contract-specific. | 99.98% The 99.98% figure covers operating availability rather than a contractual SLA or a platform-wide service level. | 99.98% uptime for peak traffic and major events Peak-traffic and major-event availability is 99.98%. This is an operating figure rather than a group-wide contractual SLA. | Unresolved A P1/P2/P3 response-time and resolution-time matrix across all modules remains unresolved. | One 2025 Norsk Tipping procurement included a service-level schedule with standardized compensation. Triggers and rates remain unavailable, and the schedule is not a universal EveryMatrix SLA. |
| Playtech | 8.7 | Unresolved Availability percentage, exclusions, maintenance treatment and remedies are deployment- and contract-specific. | Unresolved Historical availability percentage and incident history remain unresolved. | Long tier-one production record and major-event scale; historical uptime percentage unresolved The platform spans roughly 50 IMS deployments and supports very large regulated operators; normalized portfolio-wide availability and incident history remain unresolved. | 24/7 coverage; numeric P1/P2 response targets are contractual Support teams operate 24/7; severity definitions plus response and restoration targets are contract-specific. | Service-credit triggers, caps, exclusions and sole-remedy language are contract-specific. |
| SOFTSWISS | 8.3 | 99.999% for Game Aggregator Game Aggregator has a 99.999% uptime SLA. Other modules can carry different contractual targets. | Game Aggregator: 99.999% SLA; Casino Platform: 99.99% uptime These figures are product-specific. Long-term status and incident history remain unresolved. | Unresolved Game Aggregator has a 99.999% SLA and Casino Platform has 99.99% uptime. These product-specific figures do not establish a portfolio-wide historical track record; long-term status and incident history remain unresolved. | About 1 hour historical average first response; contractual target deal-specific | Service credits are negotiated. The 99.999% Game Aggregator SLA leaves the credit formula, exclusions and claim process contract-specific. |
| Pragmatic Solutions | 8.2 | 98.6% One executed 2023 customer agreement guarantees 98.6% monthly availability and service credits; current standard terms are deal-specific. | Unresolved A platform-wide historical uptime percentage remains unresolved. | 99.99% historical operating figure; 2023 customer SLA floor of 98.6% monthly availability The operating target and the much weaker contractual floor have different scopes. A platform-wide historical uptime series remains unresolved. | One 2023 customer agreement: P1 15 minutes; P2 1 hour; P3 2 hours; P4 1 business day Historical customer-specific targets. P1 workaround target was three hours and permanent fix one business day; P2 workaround six hours and permanent fix one business day. | One 2023 customer agreement uses 5%, 10% and 15% monthly revenue-share credits, subject to an annual cap. |
| Aristocrat Interactive | 8.1 | Unresolved Guaranteed uptime thresholds and service-credit triggers are contract-specific. | Unresolved A consolidated uptime history for the combined Interactive portfolio remains unresolved. | NeoGames' Michigan iLottery platform has a live operating record dating to 2014 and ranked ahead of competing bids for reliability; measured uptime history remains unresolved This scope covers the NeoGames Michigan iLottery deployment, not a measured uptime series or the combined PAM, sportsbook, Fusion and CXS portfolio. | Unresolved Michigan defines player customer-service response benchmarks; severity-specific B2B technical acknowledgement and restoration targets remain unresolved. | Michigan liquidated damages include US$1,000 per minute beyond the availability threshold and US$500 per minute for a qualifying data-centre communication outage; the final executed availability threshold is unpublished. |
| Altenar | 8.0 | Unresolved A guaranteed uptime threshold and service-credit trigger remain contract-specific. | Unresolved Customer-facing incident history and multi-period uptime remain unresolved. | Near-zero downtime for rolling Kubernetes deployments; historical uptime and a contractual SLA remain unresolved | Designed to respond within 10 minutes The 10-minute response target is non-contractual. Severity-specific acknowledgement clocks, restoration targets and service-credit remedies remain contract-specific. | The Altenar SLA and service-credit schedule are contract-specific. |
| Kambi | 8.0 | Unresolved Availability percentages, service-credit triggers and measurement rules are deployment- and contract-specific. | Unresolved Proven at major-event scale; historical uptime percentage remains unresolved. | World Cup-scale delivery, but an April 2026 multi-client disruption generated contractual credits; uptime percentage unresolved The 17 April 2026 multi-client disruption generated contractual credits. Exact root cause, duration, availability impact and credit formula remain unresolved. | 24/7 tiered incident response; severity targets are contractual Round-the-clock partner and technical support is backed by dedicated Partner Support and technical account management. | Availability remedies are expected in an enterprise managed-service SLA; the trigger and credit schedule are negotiated and private. |
| Light & Wonder | 7.7 | Unresolved The guaranteed uptime percentage and service-credit threshold are unresolved. Availability engineering does not itself define the operator contract guarantee. | Unresolved A measured availability series for the current iGaming stack is unresolved. The absence of an established material outage is not measured uptime. | Unresolved OPS and OGS availability history is unresolved. Regulatory approvals and service scale do not establish measured uptime. | Severity-based contractual SLA; major incidents can be escalated through monitored voicemail | Contract-specific. |
| Pariplay | 7.5 | Unresolved Availability percentages and service-credit triggers for Fusion and the RGS are contract-specific. 24/7 support is not a quantified uptime guarantee. | Unresolved Normalized service availability and incident history remain unresolved; no portfolio-wide historical uptime rate is established. | Unresolved A normalized availability history for Fusion and the RGS is unresolved. 24/7 operation and regulatory approval do not establish measured uptime. | Severity-based contractual SLA; response targets deal-specific | Contract-specific. |
| Digitain | 7.1 | 99.9% The feed availability SLA is 99.9% with custom options. A whole-platform guarantee and service-credit schedule remain contract-specific. | Unresolved Historical component availability and incident history remain unresolved for Centrivo, sportsbook, casino and Paydrom. | Platform-wide availability and incident series unresolved; no material platform outage established through July 2026 Scope-specific availability is 99.9%, and migration is designed for zero downtime. Platform-wide measured uptime remains unresolved. | Immediate response for critical API and casino issues; numeric first-response and resolution SLA unresolved Critical issues receive immediate response and 24/7 technical assistance with senior engineers. A severity matrix and measurable whole-platform response and resolution commitment remain unresolved. | Service-credit formula and availability trigger remain unresolved. |
| White Hat Gaming | 7.1 | 99.7% One February 2025 operator contract includes service credits. Measurement excludes accepted maintenance and a broad set of third-party, customer and exceptional events. | Unresolved No usable provider-wide historical uptime series exists. | One 2025 PAM contract warrants 99.7% monthly availability; historical portfolio-wide uptime is unresolved The SLA excludes numerous third-party, customer, forecast-overrun and infrastructure events. Contractual availability is not the same as observed availability. | P1: 15 minutes; P2: 2 hours; P3: 24 hours P1 updates are due every 30 minutes, P2 updates hourly and P1/P2 post-incident reports within two business days. Resolution times are agreed per incident. | Service credits apply below 99.7% monthly availability. The table is redacted, applies only to affected states/users and is the customer's sole availability remedy. |
| GR8 Tech | 7.0 | Unresolved This is an operating availability figure, not a guarantee or service-credit schedule shared by every contract. | 99.95–99.99% Availability figures range from 99.95% to 99.99% across different scopes and dates; normalized 12-month component-level availability remains unresolved. | 99.95–99.99% operating figures; zero downtime during the 2022 World Cup Availability figures span 99.95%, 99.96% and 99.99% and are not directly comparable; the signed SLA controls. A normalized historical status series is unresolved. | Unresolved P1/P2/P3 response and resolution targets are product- and contract-specific. | Service-credit schedules and availability-credit formulas are contract-specific. |
| GiG | 6.8 | Unresolved A universal contractual availability percentage remains unresolved. The 99.9% operating figure is not a guaranteed SLA. | Unresolved Component-level status history and a defined measurement period remain unresolved. A three-day server outage occurred in summer 2023. | 99.9% operating target; longitudinal measurement history unresolved The 99.9% uptime figure lacks a measurement period, component scope and status history. A three-day server failure in summer 2023 resulted from insufficient redundancy, followed by procurement of two additional servers. | Unresolved P1/P2/P3 response and resolution targets are contract-specific. | Platform failures can trigger B2B client compensation through service credits. The credit table and uptime measurement remain private. |
| Bragg Gaming Group | 6.7 | Unresolved Guaranteed whole-platform uptime and service-credit triggers are contract-specific and unresolved. A managed-service commitment is not the same as a quantified SLA guarantee. | Unresolved Historical production availability remains unresolved. The absence of an established major outage is not an uptime series. | No material customer-platform outage established; historical uptime series unresolved | Unresolved A severity-specific B2B acknowledgement, update and restoration schedule remains contract-specific and unresolved. | The service-credit formula, cap, exclusions and claim process are contract-specific and unresolved. Support and availability commitments do not establish contractual credits. |
| Slotegrator | 6.3 | Unresolved Guaranteed availability and service-credit thresholds are contract-specific and unresolved. | Unresolved Portfolio-wide status history and measured uptime remain unresolved. The 99.9% figure is anonymous and case-specific rather than a contractual platform benchmark. | Status history and audited uptime series unresolved The 99.9% figure is anonymous, case-specific and neither a contractual nor portfolio-wide measured platform record. | Unresolved P1/P2/P3 response and resolution targets are contract-specific and unresolved. | The service-credit schedule is contract-specific and unresolved. |
| BetConstruct | 6.0 | Unresolved Guaranteed uptime and service-credit triggers are contract-specific and unresolved. | 99.61%-100% across major components in the latest 90-day window As of 2 August 2026, Sportsbook was 99.99%, Casino Platform 99.82%, Payments 99.98%, Casino Bet Settlement and Casino Bets Placement 99.61%, BackOffice Panel 99.65%, and API/Swarm/SSO 100%. This is measured availability, not a contractual SLA. | 99.99% betting platform, 99.99% sportsbook, 99.86% casino platform and 100% API over the measured 90-day window As of 2 August 2026, component uptime was 99.61% for casino settlement, 99.68% for third-party availability, 99.98% for payments, 100% for BetConstruct Back Office and 99.65% for the separate BackOffice Panel. A casino-rollback incident occurred on 25 July alongside frequent releases and third-party maintenance, so these component figures are not a contractual whole-platform SLA. | Unresolved Support is available 24/7; severity tiers and contractual first-response and resolution targets remain contract-specific. | The service-credit schedule is contract-specific and unresolved. |
| SoftGamings | 5.8 | Unresolved The contractual uptime percentage and service-credit schedule remain unresolved. | 99.98% platform in 2025; 99.99% for Loyalty, Sportsbook and PayCryptos As of June 2026, the 2025 platform figure is 99.98% and Loyalty, Sportsbook and PayCryptos are 99.99%; measurement method and outage history remain unresolved. | High uptime and millions of daily transactions; historical status series unresolved | Unresolved Manager contact within one business day is established, but a technical B2B severity and response-time schedule remains unresolved. | Contract-specific and unresolved. |
| Soft2Bet | 4.8 | Unresolved 99.99% is the platform headline; contractual guarantee and service credits are contract-specific and unresolved. | Unresolved Historical uptime series remains unresolved. | 99.99% Historical uptime and incident series remain unresolved. | Unresolved Player-support targets cover live chat, phone and email; B2B incident acknowledgement, update and restoration targets remain unresolved. | Contract-specific and unresolved. |
Incidents and recovery
| Provider | Security incident conclusion | Data-breach conclusion | Recovery capability | RPO / RTO |
|---|---|---|---|---|
| EveryMatrix | No material platform security incident is established as of 9 August 2026. Incident coverage remains incomplete. | No customer-data breach attributable to the EveryMatrix platform group is established through 9 August 2026. | The platform includes redundancy, auto-recovery, fault isolation and fast backup restoration, with maintained and tested business-continuity plans. RPO, RTO and backup frequency remain unavailable. | Unresolved Recovery-point and recovery-time objectives are contract-specific. |
| Playtech | No material Group platform security incident is established through 2 August 2026. | No material Playtech platform or personal-data breach is established through 2 August 2026. | Business-continuity and disaster-recovery plans are tested routinely, with secure backups and rapid-restoration capabilities. Numeric RPO, RTO and deployment topology remain contract-specific. | Contract- and deployment-specific Numeric recovery objectives are jurisdiction-, data-centre- and contract-specific. |
| SOFTSWISS | The 2023 Affilka account takeovers and payout-detail substitution establish an account-security incident pattern, but not a breach of the core Casino Platform or player database. | No material SOFTSWISS core-platform data breach is established. The Affilka account incidents and separate CoinsPaid theft are relevant adjacent risks, not a Casino Platform player-data leak. | Yes | Unresolved Disaster recovery is supported; numeric RPO and RTO targets remain contract-specific. |
| Pragmatic Solutions | The May 2026 Coinbase Cartel extortion listing remains unconfirmed, with no established outage, data compromise or operational impact. | A May 2026 extortion listing exists, but access to or publication of data was not established. | The actual disaster-recovery topology and customer entitlement remain unresolved. | Unresolved Numeric RPO and RTO remain unresolved. |
| Aristocrat Interactive | These incidents belong to the parent/group, not the current Interactive production PAM. The 2023 MOVEit zero-day exfiltrated employee personal data and other files and affected 7,200 people, including Social Security numbers. A 2017–2018 incident involved an isolated development environment containing one casino customer's patron data; no patron-data extraction was established. | The 2023 MOVEit incident involved data exfiltration and 7,200 affected people. The earlier isolated-development-environment incident affected a test environment; patron-data extraction is not established. | Michigan iLottery has customer-specific recovery duties; there is no portfolio-wide DR standard. | Michigan iLottery benchmark: data recoverable within 2 hours; contract activities resumable within 6 hours Customer-specific Michigan benchmark, not a universal portfolio SLA. |
| Altenar | No material Altenar platform security incident is established as of 14 July 2026; this does not guarantee that no internal event occurred. | No Altenar data breach is established as of 14 July 2026; a universal historical absence status remains unresolved. | Kubernetes deployment and database replication do not establish a tested disaster-recovery service or contractual recovery commitment. | Unresolved RPO and RTO remain unresolved. |
| Kambi | No material Kambi security incident is established as of 9 August 2026; this does not assert a spotless internal record. | No material personal-data breach is established as of 9 August 2026. | Hybrid multi-datacenter plus AWS VPC architecture for a mission-critical, always-on book; specific RPO and RTO remain unresolved. | Unresolved Recovery-point and recovery-time objectives are contract-specific. Resilience, redundancy and regulated operations do not determine those targets. |
| Light & Wonder | No material Light & Wonder cyber incident is established through 2 August 2026. A 2024 CrowdStrike outage disrupted some operations but was a third-party global incident, not an iGaming-platform breach. | No material breach of the current Light & Wonder iGaming business is established through 2 August 2026. This does not prove that no internal event has ever occurred. | Yes — business-continuity and incident-response controls. | Unresolved Recovery-point and recovery-time objectives are unresolved. Resilient architecture and incident-management controls do not establish contractual recovery targets. |
| Pariplay | No material Pariplay-specific cyber incident is established as of 9 August 2026; parent-level incidents exist. Aristocrat's 2023 MOVEit employee-data event and earlier test-environment access incident were not Fusion service breaches. | No direct Pariplay customer-data breach is established through 2 August 2026. Aristocrat's 2023 MOVEit event affected employee data at parent level, not Fusion or Pariplay customer data. | Yes at service-governance level. ISO 27001 and regulated 24/7/365 operation imply continuity controls; RPO, RTO and topology remain unresolved. | Unresolved Recovery-point and recovery-time objectives are contract-specific. Regulated continuity controls do not determine contractual RPO or RTO values. |
| Digitain | No material Digitain platform security incident is established through 10 July 2026. Incident coverage is incomplete and does not warrant that no other operational incident occurred. | No Digitain customer-data breach is established through 10 July 2026. Incident coverage remains incomplete. | High availability, failure isolation, backup-server support, secure managed hosting and continuous monitoring establish operational disaster-recovery capability. Topology, test cadence, RPO and RTO remain unresolved. | Unresolved Contractual recovery-point and recovery-time objectives remain unresolved. |
| White Hat Gaming | No White Hat cyber incident is established as of 2 August 2026. VIP Play's 2025 software defect affected its own internal systems and enabled unauthorized withdrawals through an external processor; it was not attributed to White Hat. | No White Hat cyber intrusion or player-data breach is established as of 2 August 2026; this is not a warranty that none occurred. | The architecture includes a Data Warehouse intended to recover all requisite PAM-generated data after a disaster affecting the hosting facility or hardware platform. Backup frequency and RPO/RTO remain unresolved. | Unresolved Numerical recovery point and recovery time targets remain unresolved. |
| GR8 Tech | No material GR8 Tech platform incident is established as of 9 August 2026. This is not proof that every internal incident was immaterial. | No GR8 Tech data breach is established as of 9 August 2026. Contract due diligence should still require the incident register and notification history. | The AWS/on-premises Kubernetes footprint, resilient storage and certification regime support a DR conclusion; topology, test results and recovery objectives remain unresolved. | Unresolved Recovery-point and recovery-time objectives are contract-specific. |
| GiG | No material platform security incident is established as of 9 August 2026; this is not an uptime or incident-history guarantee. | No data breach attributable to the current GiG Software platform group is established. | Business-continuity and disaster-recovery strategies are maintained; test results, topology, RPO and RTO remain unresolved. | Unresolved RPO and RTO are contract-specific; require exact terms and recent disaster-recovery test results. |
| Bragg Gaming Group | One internal cyber incident occurred in August 2025 and was resolved. It was limited to Bragg's internal computer environment, involved independent forensic review and had no established operational impact. | The August 2025 internal breach had no established personal-information impact. This does not mean unauthorised access never occurred. | Business continuity and recovery controls within regulated/ISO-scoped operations; exact topology is private. | Unresolved Recovery-point and recovery-time objectives remain contract-specific. Business-continuity controls do not establish contractual RPO or RTO targets. |
| Slotegrator | The April 2026 Amatic provider-side abnormal-game event affected Slotegrator clients but is not established as a Slotegrator core-platform breach. | No Slotegrator data breach is established. A 2021 impersonation scam was external. | Disaster-recovery topology, testing cadence and customer entitlement are unresolved. | Unresolved Recovery-point and recovery-time objectives are unresolved. |
| BetConstruct | No material security incident is established. A January 2022 domain-only breach entry lacks a record count and corroboration, so it is insufficient to classify a breach. Recorded service incidents are operational rather than security incidents. | No material BetConstruct data breach is established through 9 August 2026; this does not prove that none has ever occurred. | Staging services and strong measured availability support operational resilience; disaster-recovery design and contractual RPO/RTO commitments remain unresolved. | Unresolved Recovery-point and recovery-time objectives remain unresolved. |
| SoftGamings | No material SoftGamings platform incident is established through 2 August 2026; this does not exclude an unrecorded internal event. | No material SoftGamings data breach is established through 2 August 2026. The incomplete entity map limits the reach of this conclusion. | Business-continuity plans protect critical processes from major failures and disasters; numeric recovery targets remain unresolved. | Unresolved Numeric recovery-point and recovery-time objectives remain unresolved. |
| Soft2Bet | No material Soft2Bet platform cybersecurity incident is established through 2 August 2026; a universal historical absence status remains unresolved. | No player- or customer-data breach attributable to the Soft2Bet platform group is established through 2 August 2026. The linked-entity allegations concern regulatory and player-protection issues rather than a platform cybersecurity breach. | Redundant systems and disaster-recovery protocols are included. | Unresolved RPO and RTO remain unresolved. |
How absence is treated
“Unresolved” does not mean zero uptime protection or a failed control. It means the exact contract, dated product history, remedy or recovery objective is not established in the current provider conclusion. It must be resolved for the exact product, hosting topology and operator contract before it can be compared.