Operational safety

    Risk Shield — No-Risk Operations

    Hyper Softs is engineered to run with minimal external attack surface. This page explains the technical and operational controls that keep your platform independent, resilient and strictly bounded.

    Independent platform layer

    We do not operate as an extension of any upstream provider. Hyper Softs is a separate integration layer with its own agreements, credentials, traffic shaping and domain controls. If one upstream route is restricted, traffic is transparently retried through alternative authorised routes without exposing your player data or your panel architecture.

    Every launch is signed & time-boxed

    Game URLs are not plain upstream links. Each session is HMAC-SHA256 signed by our backend, bound to an expiry, and can only be accessed through our proxy. URLs cannot be replayed, shared, or hot-linked by third parties, including a provider who may want to trace or block raw traffic.

    Domain & origin whitelisting

    Every API key is tied to a whitelist of caller domains. Requests from unknown origins are rejected before they ever reach a game launch. This stops cross-origin abuse, credential leakage, and unauthorised reposting of your API on another domain.

    Rate limits & abuse detection

    Each API key and caller IP is tracked against rolling request limits. Burst traffic, repeated failed secrets, and anomalous launch patterns are throttled and logged. We cap wallet exposure per account and do not allow unlimited amplification.

    No single point of failure

    Our launch engine retries across multiple provider accounts and accepted currencies automatically. If a game UID is not available on one account, the same title is located on another authorised account before giving up. This resilience keeps your players active even when one upstream catalog is temporarily unavailable.

    Audit trail by design

    Every auth attempt, launch request, callback delivery and currency retry is recorded in a structured security log. Admins can inspect who called what, from which domain, and whether it succeeded. Disputes are resolved with data, not assumptions.

    Operating principles

    Strictly limited scale

    We do not pursue unlimited volume. Every account has bounded concurrency, wallet exposure and API call rates. Operating within limits is how we avoid becoming a disruptive force that attracts retaliation.

    Regional restriction

    Privacy Policy: हम India, Nepal और Sri Lanka में API service provide नहीं करते हैं। API services are not offered for operations in India, Nepal or Sri Lanka.

    Zero tolerance for attacks

    We do not attack, defame, disrupt or steal data from any other platform — and we apply the same standard to our own infrastructure. Attempts to abuse our service are logged, throttled and escalated through our hosting and network providers and, where appropriate, the relevant authorities.

    Read our full public statement on fair use, authorised supply and dispute handling.

    Fair Use & Business Conduct

    Have a security concern or dispute? Contact us directly — we respond to written queries and resolve issues with evidence, not retaliation.

    Contact on Telegram