Club House Casino Security Australia — Encryption & Fair Play

Encryption and Data Protection

Club House Casino, operated by Dama N.V. under Curaçao GCB licence OGL/2023/174/0082, protects player data through defence-in-depth encryption covering both transport and storage. All traffic between player devices and the operator’s servers runs over TLS 1.3, the current standard for secure transport, with strong cipher suites and forward secrecy enforced by server configuration. Older TLS versions and weak ciphers are disabled at the server.

Data at rest is protected with AES-256 encryption applied at the database layer, with encryption keys held in a dedicated key management service separated from the database hosts. Payment card handling is compliant with the Payment Card Industry Data Security Standard, meaning that primary account numbers are tokenised at the payment gateway and the operator’s own systems never see or store the full card number.

Account Security — 2FA and Biometrics

Two-factor authentication is available on every account and strongly recommended for players who fund the account with material sums. The TOTP-based 2FA implementation supports authenticator apps such as Google Authenticator, Authy, and Microsoft Authenticator, generating six-digit codes that expire after 30 seconds. Recovery codes are issued at 2FA enrolment and should be stored securely offline.

Mobile users on iOS and Android may enable biometric authentication using FaceID, TouchID, or Android fingerprint or face unlock, replacing the password entry with a device-level biometric check. Login alerts run separately from 2FA and send an email notification for every successful login, listing the approximate location, device type, and IP address.

RNG and Game Fairness

Random number generators underpin every game outcome at Club House Casino, and independent certification confirms that each RNG produces statistically random results across sufficient sample sizes. iTech Labs and equivalent testing houses issue certification against internationally recognised standards, and the operator holds current certificates covering both proprietary and third-party game engines.

Provider studios supplying games to the operator hold their own game-level certifications from testing houses recognised by the Curaçao GCB. Return-to-player figures are published on each game’s information panel, and the operator does not adjust RTP settings on games where the provider offers configurable options in a way that reduces the player-facing figure without disclosure.

Segregated Player Funds

Player deposits are held in a segregated trust account maintained separately from the operator’s own working capital, protecting player balances in the event of operator insolvency or business disruption. Segregation is a mandatory condition of the Curaçao GCB licence, and the regulator conducts periodic reviews to confirm compliance.

Withdrawal capacity is maintained at a level sufficient to meet expected redemption demand under stress scenarios, and the treasury team monitors segregated balances continuously to confirm coverage. Commingling of player and operational funds is prohibited by internal policy as well as licence condition.

Anti-Fraud Systems

Device fingerprinting captures a signature of each device that accesses the account, combining browser characteristics, operating system information, and hardware indicators to produce a unique identifier that persists across sessions. Sudden appearance of a new fingerprint on an established account triggers enhanced verification.

IP address screening cross-references the login IP against threat intelligence feeds identifying known proxy exits, VPN concentrators, and previously abused address ranges. Behavioural anomaly detection watches for changes in play patterns, deposit behaviour, and account settings that may indicate account takeover.

Incident Response

The security incident response programme covers detection, containment, eradication, and post-incident review. Detection combines automated monitoring across infrastructure, application, and behavioural signals, with on-call responders reachable around the clock. Containment procedures isolate affected systems and, where necessary, restrict account access.

Breach notification runs within 24 hours of confirmed exposure of personal data, with notifications sent to affected players and, where legally required, to the Curaçao GCB and other applicable regulators. Post-mortem reviews cover root cause, timeline, and remediation actions, and material findings are published in summary form.

Bug Bounty Program

The responsible disclosure programme welcomes security research from external researchers acting in good faith and offers financial rewards for vulnerabilities confirmed by the security team. The payout scale ranges from A$250 for low-severity issues through to A$10,000 or more for critical vulnerabilities affecting authentication, payment processing, or bulk data exposure.

Programme rules cover scope, safe harbour, and reporting format, and researchers who follow the rules are protected from legal action arising from their testing activity. Reports are submitted to [email protected] with encrypted content where sensitive, and the security team acknowledges reports within two business days. For a full brand review, see the tested AU brand overview.

Reviewed by Marcus Whitlam, Senior AU Casino Editor. Last updated 10 July 2026.