Trust & security
Security, privacy and standards at TablePlay
Guests play on their own phones and venues trust us with their data. That is why we built TablePlay from the ground up on the principles of recognised international standards. This page explains honestly, without spin, what we have assessed, what is already in place and where we are heading.
Honest about our status
We do not want any confusion about this. TablePlay is not yet officially certified for these standards. What we have done:
- Our code and processes have been assessed for readiness against these standards.
- The related security and privacy controls have been implemented or reviewed.
- Where we found gaps, they have largely been addressed and documented.
- Official certification still requires an external audit by an accredited body. That is what we are working towards.
Information security
We have set up access control, secrets management, logging, incident handling and secure development on the principles of ISO/IEC 27001. Because we run in the cloud (Vercel and Supabase), we also account for the cloud-specific standards ISO/IEC 27017 and 27018 and the shared responsibilities with our providers.
In practice this includes fail-closed authentication, tenant isolation with row-level security, rate limiting, CSRF and origin checks, a Content Security Policy and MFA for admin sessions.
Privacy and data protection
Privacy is built in (privacy by design). We work on the principles of ISO/IEC 27701 and comply with the GDPR: clear retention periods, data deletion, handling of access and deletion requests (DSAR), processor agreements and a data-breach process.
Our data processing agreement, sub-processor list and privacy statement are in the footer. You can submit a privacy request directly on the site.
Secure payments
Payments run through Stripe, a payment partner that is genuinely PCI DSS Level 1 certified, the highest standard in the payment industry. Card details never touch our own servers. On our side we ensure secure webhooks, idempotency and strict control over payment and billing flows.
Continuity and back-ups
We account for the principles of ISO 22301 for business continuity: back-ups, recovery procedures and outage scenarios, so a venue running on TablePlay is not left stranded.
Quality
Our way of working and quality approach are set up on the principles of ISO 9001, so processes are repeatable, auditable and improvable.
Accessibility
We test the site and game environment for accessibility against WCAG 2.2 level AA: keyboard operation, language metadata, clear forms and error messages. This also prepares us for the European Accessibility Act.
Where we are heading
Our intended certification combination is ISO/IEC 27001 together with ISO/IEC 27701 and PCI DSS, later optionally supplemented with SOC 2 Type II and ISO 22301. Once a standard is officially achieved, we will state that here with the real certificate and its mark.
Questions about security?
Work at a chain or larger venue and want to know more about our approach, or have something to report? Email us at support@tableplay.online.
