Safety
What a safe rummy platform actually looks like.
Five topics in a ruled ledger: KYC walkthrough, RNG audit reading, payment signs, withdrawal disclaimer reading, support desk reading. Each topic is a row in the ledger; KYC does not swallow the page.
Five safety topics
Five starter reads in this section.
KYC walkthrough
PAN, address proof and a phone-OTP step. The order matters, the redactions matter, and the named document types matter when a regulator asks later.
RNG audit reading
An annual third-party RNG audit covers deck-shuffle integrity and discard-pile randomness. The 2026 iTech Labs audit note is the most cited reference.
Payment signs
Minimum deposit, maximum daily ceiling, processing window, and the UPI handle or bank account the platform uses. Four questions the payment page should answer.
Withdrawal reading
The withdrawal disclaimer should name a processing window (commonly 24 to 72 hours for UPI) and a verification step that gates the first withdrawal.
Support desk reading
The platform should expose a customer-care channel inside the lobby. A platform that responds with a chatbot and never names a human is a platform to walk away from.
KYC walkthrough, the four steps
The order matters; the redactions matter; the named document types matter. The desk treats KYC as the first trust handshake between the reader and the platform.
Step 1: phone OTP
The phone OTP step gates the rest of the KYC walkthrough. The reader enters a phone number, receives a numeric OTP, and confirms. The phone number is the verification anchor for the rest of the walkthrough.
Step 2: PAN submission
PAN submission follows the phone OTP step. The platform validates the PAN against the issuing authority. The redaction on the submitted copy should keep the PAN number visible (the platform needs it) and the personal fields redacted.
Step 3: address proof
Address proof can be an Aadhaar card, a utility bill, a bank statement, or a rental agreement. The redaction should keep the document type visible and the personal fields redacted. The platform that accepts a wider range of address proofs is the platform that handles edge cases better.
Step 4: account verification
Account verification completes the walkthrough. The reader's account is now eligible for the first withdrawal. The processing window for the first withdrawal is commonly 24 to 72 hours; the platform should name the window in the withdrawal disclaimer.
RNG audit reading
The 2026 iTech Labs RNG audit note is the most cited reference on the desk. The audit covers deck-shuffle integrity and discard-pile randomness on one regulated platform.
What the audit covers
The audit covers deck-shuffle integrity (the entropy of the shuffle) and discard-pile randomness (the entropy of the discard pile across a sample of hands). The audit is named as evidence, not endorsement; the desk does not publish a platform rating derived from the audit.
What the audit does not cover
The audit does not cover payout rates, win rates, or platform ratings. The desk refuses to publish any number that the audit does not name. The audit covers one regulated platform at one point in time; later updates land in the .
Reading an RNG audit
Withdrawal disclaimer reading
The withdrawal disclaimer should answer four questions. A disclaimer that does not name a processing window is a disclaimer to ask about before depositing.
The four questions
One: what is the minimum withdrawal amount? Two: what is the maximum withdrawal per day? Three: what is the processing window (commonly 24 to 72 hours for UPI)? Four: what verification step gates the first withdrawal?
What a red flag looks like
A disclaimer that does not name a processing window is a red flag. A disclaimer that names a "variable" processing window with no upper bound is a red flag. A disclaimer that hides the minimum and maximum behind a separate T&C PDF is a red flag. Three red flags together is enough to walk away.
Support desk reading
What a working support channel looks like.
Lobby design reading
Three checks for the lobby surface.
Are the rules in the lobby?
A regulated platform publishes the rules inside the lobby, not behind a separate T&C PDF. The reader should be able to read the rules without scrolling past the deposit button.
Is the responsible-play link visible?
The responsible-play link should sit in the lobby footer or the account settings menu. A platform that hides the link behind a separate app download is a platform to walk away from.
Is the customer-care channel visible?
The customer-care channel should be reachable from the lobby, not from a separate support site. The channel should name a working email and a working phone.
KYC walkthrough in detail
The four steps, the documents, the redactions.
Step 1 in detail: phone OTP
The phone OTP step gates the rest of the walkthrough. The phone number is the verification anchor for the platform's KYC system. The reader should use a phone number that the reader can answer during business hours; the OTP window is commonly five minutes.
Step 2 in detail: PAN submission
PAN submission follows the phone OTP. The platform validates the PAN against the issuing authority. The submitted copy should keep the PAN number visible (the platform needs it) and the personal fields redacted (the desk recommends a single redaction band across the name and address).
Step 3 in detail: address proof
Address proof can be an Aadhaar card, a utility bill, a bank statement, or a rental agreement. The redaction should keep the document type visible (Aadhaar, utility bill) and the personal fields redacted. The platform that accepts a wider range of address proofs is the platform that handles edge cases better.
Step 4 in detail: account verification
Account verification completes the walkthrough. The reader's account is now eligible for the first withdrawal. The processing window for the first withdrawal is commonly 24 to 72 hours; the platform should name the window in the withdrawal disclaimer.
Support desk reading in detail
Four observable signals, ranked by what they reveal.
Working email
Named in the lobby; responds within one business day during business hours. The platform that names a generic info@ address without a department structure is a platform that treats support as a queue, not as a relationship.
Working phone
Named in the lobby; staffed during business hours; recorded for verification. The platform that names a phone number without business hours is a platform that has not committed to a support window.
Named agent
The first response names a human agent with a ticket ID. The desk treats that as the verification anchor for the rest of the support relationship. The platform that responds only with ticket IDs and never names a human is the platform to walk away from.
Escalation path
The platform publishes an escalation path for unresolved queries, including a named regulator or ombudsman. The platform that has no escalation path beyond the chatbot is a platform that does not recognise the reader's right to escalate.
RNG audit reading in detail
Five observations about an audit certificate.
Observation 1: the audit name
The audit name is the verification anchor. The 2026 iTech Labs RNG audit note is named as evidence; the desk publishes the name and the date. A platform that does not name the auditor is a platform that has not been audited.
Observation 2: the audit scope
The audit scope is what the audit covers. The 2026 iTech Labs audit covers deck-shuffle integrity and discard-pile randomness on one regulated platform. The desk publishes the scope; the reader can verify what the audit covers and what it does not.
Observation 3: the audit date
The audit date is the freshness anchor. The 2026 iTech Labs audit note is dated 21 March 2026. The desk publishes the date; the reader can verify the freshness. An audit dated more than a year old is a stale audit.
Observation 4: the platform scope
The platform scope is the named platform. The audit covers one regulated platform; the desk does not extrapolate the audit to other platforms. A platform that claims an audit from another platform is making an unsupported claim.
Observation 5: the next update
The next update lands in the desk's . The reader can subscribe to the news feed for the next audit note. The desk publishes the next audit name and date when it lands.
Next desk
Read the responsible-play desk.
The responsible-play desk walks through the reader-side controls: five self-rules, weekly log, room-mate script, helplines, self-exclusion and state restrictions. The reviews desk pairs the platform knowledge with the eight pre-deposit checks.