Money moves only when every gate says yes
Most of these gates exist to say no. A contest that can't be read clearly voids and refunds rather than guessing. A payout without tax and identity records on file is denied by default. A settlement that arrives twice moves money once. Here's the machine, and here's what it refuses to do.
PLLAY is in a demo phase — contests and credits run end to end, and every control described here is live against them, but cash rails are switched off at the database level. This is the machine as built, before it moves anyone's money.
Seven gates. Any one of them can stop it.
Watch what happens when something is wrong — a blocked location, footage that never resolves, a duplicate settlement, a payout missing its paperwork. Refusing correctly is the harder half of handling money.
Location is checked against three independent signals — network, account, and billing. Any one of them disagreeing stops the entry, and every check is written to an audit log.
Illustration of the enforcement path — not a live transaction feed.
Gate five is read off the broadcast, not entered by hand — PLLAY Vision AI settles from the video itself. How skill scoring works · Official contest rules · The same answers, in plain language
Four layers, each enforced somewhere you can't argue with
The database, the front door, the contest itself, and the infrastructure underneath. Pick a layer.
Settlement that cannot double-pay, a split enforced by database constraint, refunds checked nightly, and identity gates that fail closed.
Every request answers for itself
Authentication, authorization and credential scope, for a partner integrating against PLLAY directly — key-based, admin-provisioned, and scoped to the partner that holds the key.
Every request to PLLAY's partner API authenticates with a key before anything else runs. Key-based authentication, a documented rate limit, and signed, retried webhook delivery are live in production today.
A key is scoped to the partner it was issued to — there is no shared or ambient credential that reaches more than one partner's data. What a request is allowed to touch is a property of which key made it, not a setting the request can override.
Every partner credential is provisioned and revoked directly by PLLAY — there is no self-serve signup. Access is a controlled, admin-managed relationship with a named partner, not an API key anyone can generate for themselves.
What we don't claim
Any company can publish the first half of this page. This is the half you can hold us to — the gaps as they stand today, in our own words, before someone else finds them.
We hold no independent security certification. Our infrastructure providers hold theirs, and that is their credential, not ours.
Creator payouts require a compliance clearance recorded by an administrator. That is a person confirming a check, not an automated screen against published sanctions lists. Wiring a screening provider is required work before real-money launch.
The requirement is enforced, but the verification behind it currently auto-approves while the platform is pre-launch. It cannot be pointed at real money in that state — the system refuses to start if the two ever disagree.
The platform is in a demo phase. Credits and contest mathematics run end to end, and every control described above is live against them, but cash rails are switched off at the database level. Everything here is the machine we built before turning them on.
This list shrinks by shipping, not by editing.
Incident contact
Found something wrong — a settlement that doesn't match, a security concern, a suspected gap in one of the controls above? support@pllay.io reaches the same team that operates this page, not a queue.
Reviewing PLLAY for a partnership?
Publishers, platforms and investors get the same enforcement path described here, and we're happy to walk a technical team through it in detail.