Card-data minimisation
The target card architecture keeps raw card credentials within the approved provider-hosted environment rather than storing them in Nexus or connected casino applications.
Nexus is designed around provider-hosted payment experiences, environment-held secrets, signed integrations, idempotent financial posting and restricted operational actions.
The target card architecture keeps raw card credentials within the approved provider-hosted environment rather than storing them in Nexus or connected casino applications.
Provider credentials and signing secrets are configured outside source control and can be separated by environment.
Provider-specific webhook verification and allow-list controls can be enforced before external events affect financial state.
Retries and duplicate provider notifications must not create duplicate financial movements.
Reconciliation, manual review and settlement approval remain distinct operational states rather than direct balance mutations.