How iGregulator verifies
In short. We show revoked,
suspended or surrendered only when a
regulator's own publication says so and we read it, and active
only when the regulator listed it as current on our latest read (a Curaçao licence still
under the CGA's final assessment is shown as active, marked provisional). A licence that simply disappears
from a register becomes not_in_register — an observation about
the register, not a revocation — and only after it has been missing from every read for
60 hours; a page we can't read changes nothing. Every status cites the
page it was read from and when, and since 17 September 2026 we keep a stored copy of the
register and enforcement pages behind it. The Tobique Gaming Commission publishes no
revocations, so a Tobique licence is only ever active or
not_in_register. Mistakes are marked and corrected in the open,
never deleted — see the
corrections log.
We read the public registers of seven gambling regulators every night and report what they say — each status with the regulator page it came from and when we read it. This page describes how that works, checked against the code that does it, including where it can go wrong.
- Regulators
- 7 — UKGC, MGA, CW, KH, AN, TGC, IOM
- Registers read
- Nightly, 03:00–04:25 UTC
- Freshness window
- 24 or 48 hours per register — live on the status page
What we are — and aren't
- Not a regulator. We don't grant, assess, suspend or withdraw licences, and nothing here is a licensing decision.
- The regulator's register is the source of truth. We read it, map its wording onto one status vocabulary, and cite the page. If we disagree with the register, the register wins — and we want to hear about it (corrections).
- We report what we read, in both directions. No status is inferred to fill a gap: we never say “licensed” without reading it, and never say “revoked” because a record went quiet.
Source hierarchy
Four kinds of source, in order of authority. Only the first three can change what we say about a licence.
- The regulator's register — its download, PDF, web page or the data embedded in that page. It says who is listed and, for most registers, a status word too.
- The regulator's own status publications — enforcement
registers, revoked- and suspended-licence lists, advisory notices, a former-licence-holders
page, a per-licence verification page. These are the only sources allowed to set
revoked,suspendedorsurrendered. - The regulator's per-domain verification pages — Curaçao
certificates (
cert.cga.cw) and Tobique validation seals (validate.thetgc.ca), which say which domains a licence covers. We fetch them only from the regulator's own hosts; a certificate on any other host, such as a look-alike portal, is refused before it is fetched. - Everything else — for discovery only. Search-engine results, seals embedded in casino footers, third-party brand lists, archived copies of older register pages. They tell us where to look. They never set a status and never link a domain to a licence on their own: a link is written only after we read the regulator's page and it lists that domain.
When two regulator sources disagree
- A published decision outranks a listing. A register that still lists a licence doesn't undo a revocation, suspension or surrender the regulator published elsewhere (Curaçao, Kahnawake). Being listed moves “last listed”, not the status.
- An old decision doesn't overrule a listing we have watched since. Kahnawake's notices and Malta's enforcement register go back years; a licence listed today isn't suspended by an entry older than everything we've seen of that listing.
- Malta's per-licence page outranks its list view. If a licence's
own verification page stated its status within the last 72 hours, the list no longer
showing it doesn't make it
not_in_register. - Two publications of one register that disagree give
unknown. The Isle of Man register page and the spreadsheet it links are read together; where they differ on a status, we don't pick one.
Where each status comes from
Every register is read once a night. Where a regulator publishes its decisions somewhere other than its register, that publication is read on every run too — in the same run as the register, except Malta's enforcement register, a separate job at 05:00 UTC.
| Jurisdiction | The register we read | Where revoked / suspended / surrendered come from | Per-domain page |
|---|---|---|---|
| UKGC UK Gambling Commission |
Business licence register download (business-licence-data.zip,
CSV files)
|
The export's own status column — Revoked,
Suspended, Surrendered,
Lapsed | — |
| MGA Malta Gaming Authority | Licensee register (a
JavaScript app, read in a headless browser), plus each licensee's verification page —
the only MGA page allowed to say active |
The per-licence verification page (Suspended,
Surrendered, Expired); the
MGA Enforcement Register (revocations, suspensions)
| — |
| CW Curaçao Gaming Authority |
OGL register PDF, linked from the CGA's
registry page, plus the
CGA certificate registry (cert.cga.cw/token), which lists
licences the PDF omits
| The CGA Enforcement Register PDF (revoked, suspended, not extended), linked from the same page; the OGL PDF's own status cell | CGA certificates |
| KH Kahnawake Gaming Commission | Permit-holders page (Interactive Gaming and CSPA tables) — it prints no status |
KGC advisory notices: revocation, suspension, voluntary termination (→
surrendered)
| — |
| AN Anjouan Gaming Authority | Licence register (data embedded in the page) | The Authority's revoked-licences and suspended-licences pages; the register's own status word | — |
| TGC Tobique Gaming Commission | Licence-holders page |
Nothing — Tobique publishes no decisions, so a licence that leaves its list can only
ever be not_in_register | Tobique validation seals |
| IOM Isle of Man Gambling Supervision Commission | Online gambling licensee register, cross-checked against the spreadsheet it links |
The
Former Licence Holders page: Surrendered → surrendered,
Cancelled → revoked; any other
word sets nothing
| — |
A status word we have never seen is never read as active: it is
recorded as unknown (or skipped) and logged, until we decide what
it means from the real text.
Cadence and freshness
| Jurisdiction | Read (UTC) | Last read (UTC) | Freshness |
|---|---|---|---|
| UKGC · UK Gambling Commission | 03:00 | stale | |
| MGA · Malta Gaming Authority | 03:15 | fresh | |
| CW · Curaçao Gaming Authority | 03:30 | fresh | |
| KH · Kahnawake Gaming Commission | 03:45 | fresh | |
| AN · Anjouan Gaming Authority | 04:00 | fresh | |
| TGC · Tobique Gaming Commission | 04:15 | stale | |
| IOM · Isle of Man Gambling Supervision Commission | 04:25 | fresh |
Last read and freshness as of 2026-09-30 20:21 UTC, from the keyless /v1/health/coverage endpoint when this page was built; your browser refreshes them on load. The same figures are on the status page.
- Verification pages. A rolling nightly pass at 05:15 UTC re-reads up to 500 stored pages per jurisdiction, least recently checked first — every Tobique seal each night, each Curaçao certificate every 2–3 days — at about one request a second, backing off when the regulator rate-limits us. A domain's status moves only on a clean read of the regulator's own words, in either direction.
- Discovery. Weekly, on Sundays: a sweep of the CGA certificate registry for licences and domains the OGL PDF omits, and a search for Tobique seals on candidate casino sites.
- Freshness window. A register is stale when its latest successful
read is older than 24 hours (UKGC, AN, TGC, IOM) or 48 hours (MGA, CW, KH — heavier
sources, where one failed night is routine). Stale means old, not wrong: a stale register
keeps its last good read, dated.
/v1/health/coveragereports it and acoverage.degradedwebhook fires. - Last read is the latest time we confirmed any record of that register against the register itself.
Capture and evidence
- We keep the bytes. Every register, enforcement publication and notice feed we read — page, PDF, ZIP or data — is stored, compressed, on our server, and indexed by its URL, its SHA-256 and when we first and last fetched exactly those bytes. A register that republishes the same content for days is stored once.
- Every status cites its own source. A licence carries three
fields about its current status, separate from the register it is listed in: the page that
published the status (
status_source_url), the latest time we read that page still saying it (status_observed_at), and the stored copy of that read, where we keep one. A Curaçao revocation cites the CGA Enforcement Register, an Anjouan suspension the suspended-licences page, a Kahnawake termination the notice itself. - A citation moves only with a read that agrees. A night's read refreshes a status's source only if it says the same status and it is the same page. A revocation read from an enforcement register is never re-credited to the main register because that register still lists the licence.
- Every change is an event. A licence's history records each
status change with its date, the source page, a note on what we saw and, where we stored
them, the SHA-256 of the bytes behind it (
snapshot_sha256in the API) — checkable against your own copy of the regulator's page.
What we don't have
- No stored copy before 17 September 2026. Statuses and events from before then cite a page and a date, but we kept only a hash of what we read — which proves two reads matched, not what either said.
- Per-domain verification pages aren't stored. The nightly pass re-reads thousands of small certificate and seal pages; a change it makes cites the page and when we read it, without a stored copy. A certificate-registry page is stored when we record a status event from it.
- Malta's register has no single document. It is a JavaScript app, so its stored copy is the rows we read, not the page.
- A failed write doesn't stop a read. If a copy can't be stored (a full disk, say), the read still counts and is recorded without the bytes. Missing evidence is bad; a register we stop reading is worse.
- The copies are our working papers. The API gives their fingerprints, not the files.
The dates we publish
status_observed_at- — the latest read, on the page that published it, that still says the status we show.
last_listed_at- — when the register last listed the licence.
not_listed_since- — the first read that no longer listed it.
_meta.scraped_at- — when we last confirmed the record against its register.
snapshot_fetched_at- — on a history event, when we first fetched the bytes behind it.
_meta.source_modified_at-
— reserved for the regulator's own “last updated” date. Always
null: we don't record it for any register yet.
Status vocabulary
Eight statuses. Only active means licensed now. The others are not
interchangeable, and choosing the wrong one is a claim about a real business.
| Status | What it means | Where it comes from |
|---|---|---|
active | Licensed now. | The register or verification page that sets status in that jurisdiction listed it as live on our latest read. |
pending | An application under assessment — not licensed yet. |
The register says so (UKGC Pending; the CGA's “Assessment in
progress” on a licence not yet granted).
|
suspended | The regulator suspended it. | A suspension the regulator published and we read. |
revoked | The regulator ended it — a revocation, or a cancellation for cause. |
A regulator publication we read (the Isle of Man's Cancelled,
under OGRA 2001 s.13, is one).
|
surrendered | The operator gave it up. Not enforcement. |
UKGC, MGA and GSC Surrendered, a KGC voluntary termination,
the CGA's “revoked … at the request of the operator”.
|
expired | It ran out or lapsed. | UKGC Lapsed, MGA Expired, the CGA's “not extended”. |
not_in_register | The register stopped listing it and published no reason. An observation about the register — not a revocation. |
Absence from complete reads past the grace period.
Comes with not_listed_since and
last_listed_at.
|
unknown | The register lists it, in words we can't classify. We claim neither way. | An unrecognised status word, or two publications of one register that disagree. |
active can carry a qualifier:
status_qualifier: provisional_under_assessment marks a Curaçao
licence past its stated term whose final assessment is outstanding — the CGA keeps it in
force until it decides. The regulator's own word is kept alongside every status as
upstream_status (empty for a licence the register no longer
lists).
Guards on every status write
-
unknownnever replaces a status we read. An unreadable cell is not evidence that a revocation went away. -
not_in_registernever replaces a published decision — a revoked licence naturally stops being listed. - Nothing goes back to
pendingonce granted.
Licence numbers that are ours
Kahnawake, Tobique and the Isle of Man publish no licence numbers. For them,
license_number (KH/IG/…,
KH/CSPA/…, TGC/B2C/…,
TGC/B2B/…, IOM/OGRA/…) is an iGregulator
reference that identifies the record in our API — don't quote it to the regulator. The UK
Gambling Commission amends a licence by stepping the last part of its number
(…-013 → …-014); we track that as one
licence with a new number, not a new licence and a lost one.
Absence is not revocation
On 17 September 2026 an operator disputed a revoked we showed for
its licence. No regulator had said it: the licence had dropped off the register, and our
code read that silence as a revocation — for 80 licences across six registers. We
corrected all of them, marked rather than deleted, and changed the rule everywhere: a
licence that leaves a register is not_in_register, and
revoked, suspended and
surrendered come only from a regulator publication we read. The
same review found 627 UK licences the Commission lists as
Surrendered shown as revoked; they read
surrendered now.
- A grace period. A licence must be missing from every read for
at least 60 hours — with nightly reads, the fourth night in a row — before
it becomes
not_in_register. One bad night proves nothing. - An empty read un-lists nothing. A pull that returns no licences is a failed read, not a register that emptied.
- A ratio guard. If more than 15% of a register's live licences (at UKGC, pending applications too) are missing from one read — once there are at least 20 of them — we change nothing and mark the run degraded. That is what a broken read looks like, not a regulator.
- Absence counts only in a list that is complete for that record. A Curaçao licence we know from the certificate registry is never un-listed for being missing from the OGL PDF, which omits licences.
- A register we can't read changes nothing. The run fails or is marked degraded, the last good read stays, and the register turns stale on the status page. An unreachable enforcement page is never treated as an empty one.
Mass-change holds and invariants
Some failures don't look like failures: the regulator serves a file, it parses, and it is wrong.
- UK Gambling Commission hold. Before writing anything we compare
the pull with what we hold. If it would change more than 25 statuses or more than 100
licence numbers, we write nothing and mark the run degraded until a second,
different export says the same thing; a real mass change comes back the next day
and goes through a day late. The same bytes twice are one read, not two. The Commission's
download URL has served a different export — one in which licences that had ended read
Active— three times: 20 August, 22 September and 29 September 2026. The first two were published for about a day each, before the hold existed; the third was held and nothing was written. - Isle of Man former-holders list. More than five status changes from it in one run are held the same way.
- Domain guards. A run that would de-list more than 20% of a register's live domains, or strip every domain from more than five operators that still hold a live licence, de-lists nothing and is marked degraded. The verification pass stops de-listing once a run reaches 20% of the links it covers.
- A person can accept a held change on purpose, after checking it.
Post-load invariants
After every load we compare counts before and after. Domain and operator rows never shrink (we delete nothing); no operator loses all its domains; the numbers of de-listed domains, white-label domains, trading names and active licences don't fall more than 10% in one run; a verification page is linked to one company, never two. A violation marks the run degraded and records exactly what moved. It never rolls anything back — undoing a load is a decision for a person.
Domains and operators
- Many-to-many. A brand can be licensed by two companies in two
jurisdictions at once, so a domain can link to several operators, and each link carries
its own status and verification page. De-listing a Curaçao link never touches the same
domain's Anjouan link.
/v1/checkreturns every pair asjurisdictions[]. - A domain is linked only when a regulator source lists it — a register's own domain list (UKGC, Malta's verification pages, Kahnawake, Anjouan, the Isle of Man) or the regulator's certificate or seal (Curaçao, Tobique).
-
delistedmeans a complete read of the regulator's list no longer includes the domain for that licensee, or the regulator marks it inactive, withdrawn or not authorised. A certificate that names a different single domain says nothing about ours and is left alone. - Direct or white label.
white_label(the licensee authorises a third party's brand on the domain) appears only where a register marks it — today, the UK Gambling Commission's domain list. The other registers publish no such flag, and their links carry the default,direct. - A certificate names one company. A Curaçao certificate is attributed to an operator only when its company number, name and licence number all point to the same one. If they disagree, nothing is written and a person looks.
- Identity. An operator is matched from run to run by the register's own identifier; a row we can't key is skipped until the register gives it one. When a register renames a company, we keep the old name on record.
- What's ours. Grouping numbered mirror domains
(
brand1.com…brand120.com) under one brand page is our inference, for page indexing; each domain still answers on its own in the API. A/v1/checkmatch by name rather than by domain is ours too, labelledmediumorlowconfidence — the status it returns belongs to that operator, not to the site.
Corrections
- Marked, never deleted. A wrong status event keeps its row. It
gains a correction date and a note saying what was wrong, and is superseded. Licence pages
show it struck through with the note; the API returns
corrected_atandcorrection_note. - Point-in-time answers respect corrections.
as_offor a date inside a withdrawn event answerscorrectedwith no status — never the status we used to show, and never a guess at what it should have been. - A correction is not a regulator event. It fires no watchlist webhook, and our counts of what registers did leave it out.
- The log. Published corrections are listed at app.igregulator.io/corrections.
Report an error
Email founder@igregulator.io with the page, domain or licence and what the regulator's page says — a link helps. We check it against the regulator's page and our stored copy of what we read. If we are wrong, we correct it as above and say so.
Limitations
- Not legal advice. Our data is informational. Confirm decisions that matter with the regulator; our terms apply.
- Seven regulators, not all of them. A domain or company we don't find is “not found in these seven registers”, never “unlicensed”. What we can link depends on what each regulator publishes — see coverage methodology.
- Registers lag and go dark. A register can trail its regulator's decision by a day or more, and sites go offline or block automated reading. As of this update, one regulator's publications portal has been offline since late September 2026, and another register sits behind bot protection that turns most automated reads away. We keep the last good read, dated, and the status page shows which registers are stale.
- Enforcement history is incomplete. Many published actions are not yet matched to an operator; an empty list means none is linked, not a clean record.
- Our history starts when we started reading. Before our first
read of a register we have nothing to say, and
as_ofanswersbefore_trackingthere. - The mapping is ours. Turning regulators' words into eight statuses is our reading, documented above; the regulator's word is kept next to it.
Changes to this methodology
Methodology last updated . Changes to API fields and behaviour are in the changelog.
- 2026-09-30 — This page. At UKGC, an
application the export stops listing becomes
not_in_registerafter the grace period instead of stayingpending. - 2026-09-29 — The Isle of Man is the
seventh register; its Former Licence Holders page is the only source of
surrenderedandrevokedthere. Curaçao certificates are attributed only when company number, name and licence agree. - 2026-09-28 — A status cites the latest read that still says it, not the read that first set it. Operator renames are recorded.
- 2026-09-27 — The UK Gambling Commission
mass-change hold. The CGA's “revoked at the request of the operator” is
surrendered. Malta's per-licence page outranks its list view. A register row with no identifier is never loaded. - 2026-09-17/18 — Absence is
not_in_register, neverrevoked;surrenderedis its own status; every status cites its own source; we keep the bytes we read; enforcement publications are read on every run. - 2026-07 — The 60-hour grace period and post-load invariants on every register; a UK licence amendment is the same licence; domains link to operators many-to-many; absence counts only in the list that is complete for a record.
Read next
- Status — live freshness per register
- Coverage methodology — how domain coverage is measured per regulator
- Point-in-time lookups — a licence's status on a past date, within what we observed
- For AI agents — how to phrase a verdict from our data
- llms.txt — the machine-readable index