For investors, acquirers and boards
Technology due diligence for iGaming deals
A data room tells you what the seller wants you to see. We tell you what the platform will cost you to own. Argon reviews the architecture, the code, the infrastructure bill, the compliance exposure and the team behind an iGaming target, then hands your investment committee a severity-ranked report with remediation priced in engineering weeks.
01
Where teams get stuck
- The deck says scalable, nobody has tested it
- Peak concurrency, game round throughput and payment provider limits are rarely modelled. We load-test the claim or show you why it cannot be tested yet.
- No one can price the remediation
- Every acquirer hears "some technical debt". Few get a number. We convert findings into effort, sequence and cost so the figure can move into the model.
- Compliance debt hides in the code
- Geo restrictions applied in the front end, audit trails that cannot be reconstructed, player funds that are not provably segregated. These become your licence problem on day one.
iGaming consideration
A ledger that cannot be replayed, or a wallet write without idempotency, is a regulatory and financial exposure, not a bug backlog item. We test this first, every time.
02
What we do
- Architecture assessment
- Service boundaries, coupling, single points of failure, data flows and whether the design can carry a second brand or a second jurisdiction without a rebuild.
- Money path integrity
- Wallet, ledger, bonus engine and payment reconciliation. We trace deposits, wagers, wins, bonuses and withdrawals looking for double-apply, stranded funds, missing idempotency and unreconciled game rounds.
- Codebase and engineering practice
- Static analysis, dependency and vulnerability scanning, test coverage, review discipline, branch and release process, plus the parts a scanner cannot see.
- Infrastructure, scalability and run cost
- Cloud account structure, environment parity, deployment safety, observability and the actual monthly bill against actual traffic, including the waste.
- Security and data protection
- Authentication and session handling, service-to-service trust, secret management, PII exposure, KYC document storage and third-party data leakage.
- Compliance and certification readiness
- How licence conditions, RNG and platform certification, responsible gaming obligations and reporting requirements are enforced in software, and what a regulator or auditor would find.
- Supplier and integration dependency map
- Game aggregators, payment providers, KYC vendors and data suppliers. Contractual lock-in, protocol quality, failover behaviour and switching cost.
- Team and delivery capability
- Who actually holds the knowledge, key person risk, velocity against roadmap and whether the team can deliver what the plan assumes post-close.
03
What you receive
- Written report with every finding rated on severity and effort
- As-is architecture and data-flow diagrams, reconstructed by us and verified with the target
- Remediation plan sequenced into a first 90 days and a first 12 months, priced in engineering weeks
- Risk register mapped to deal impact, including anything we consider a red flag
- Infrastructure cost model with identified savings and required investment
- Live readout to the investment committee, plus a written answer to every follow-up question
04
How the work runs
01
Scope and access
We agree the questions the deal actually turns on, sign NDAs, and get read access to repositories, cloud accounts, monitoring and documentation.
02
Automated analysis
Static analysis, dependency and container scanning, infrastructure-as-code review, cost and telemetry extraction. Cheap findings first, before anyone spends interview time.
03
Interviews
Structured sessions with engineering leadership, the people who carry the pager, product, and whoever owns compliance. The gaps between those four accounts are usually where the risk sits.
04
Deep dives
Hands-on tracing of the money paths, the integration layer and anything the earlier phases flagged. This is where an iGaming specialist earns the fee.
05
Reporting
Findings, evidence, severity, effort and sequence. Written for an investment committee, with an engineering appendix that will survive a technical challenge from the other side.
06
Readout and follow-through
We present, defend the findings, and stay available through to close. If you buy, the remediation plan is already a backlog.
05
Why iGaming differs
- Player funds are not a normal balance column
- A ledger that cannot be replayed, or a wallet write without idempotency, is a regulatory and financial exposure, not a bug backlog item. We test this first, every time.
- Licence scope shapes the valuation
- Whether the platform can be certified for the next market, and what it would take, often moves the number more than the code quality does.
- Aggregator lock-in is a hidden liability
- Game supply, payments and KYC contracts frequently carry exclusivity, minimum revenue or exit terms that the technology cannot route around quickly.
06
Tools and methods
- Code and security
- SonarQube · Semgrep · Trivy · npm audit · OWASP ASVS
- Infrastructure
- Terraform review · Checkov · AWS Cost Explorer · CloudWatch · Kubernetes audit
- Performance
- k6 · Artillery · database profilers · APM traces
- Reporting
- Excalidraw · Lucidchart · structured risk register
- Typical team
- Architect, senior engineer, QA lead, plus compliance input
07
Questions
How long does it take?
Two weeks for a focused review of a single platform, three to four when there are multiple products, several jurisdictions or a hostile timeline. We can produce an early verbal red-flag readout inside five working days if the deal needs it.
Can you work without the seller cooperating?
Partly. We can assess the public surface, the app binaries, performance, infrastructure fingerprints and compliance posture from outside. Everything involving the ledger and the codebase needs access, and we will tell you plainly which conclusions are inference rather than evidence.
Is our involvement confidential?
Yes. We work under NDA as standard, we do not name clients or targets without written permission, and we can operate under your advisor as a subcontractor if the deal needs that layer.
What if you find a deal breaker?
You hear it the day we find it, by phone, before it reaches a document. That is the whole point of hiring people who have run these platforms.
Do you do post-close remediation as well?
Often, and there is no obligation either way. The report is written so your own team, or any third party, can execute it. If you want us to lead it, the diligence team already knows the codebase.
Related
- Engagements
- Under NDA as standard
- People
- Background-checked engineers
- Data
- GDPR and DPA ready
- Infrastructure
- World-renowned cloud providers
Next step
Tell us what you are building, or what you are about to buy.
One working day to a reply, from an engineer rather than an account manager. Under NDA as standard, before anything is shared.