Safety

What a safe rummy platform actually looks like.

Five topics in a ruled ledger: KYC walkthrough, RNG audit reading, payment signs, withdrawal disclaimer reading, support desk reading. Each topic is a row in the ledger; KYC does not swallow the page.

Five safety topics

Five starter reads in this section.

KYC walkthrough

PAN, address proof and a phone-OTP step. The order matters, the redactions matter, and the named document types matter when a regulator asks later.

RNG audit reading

An annual third-party RNG audit covers deck-shuffle integrity and discard-pile randomness. The 2026 iTech Labs audit note is the most cited reference.

Payment signs

Minimum deposit, maximum daily ceiling, processing window, and the UPI handle or bank account the platform uses. Four questions the payment page should answer.

Withdrawal reading

The withdrawal disclaimer should name a processing window (commonly 24 to 72 hours for UPI) and a verification step that gates the first withdrawal.

Support desk reading

The platform should expose a customer-care channel inside the lobby. A platform that responds with a chatbot and never names a human is a platform to walk away from.

KYC walkthrough, the four steps

The order matters; the redactions matter; the named document types matter. The desk treats KYC as the first trust handshake between the reader and the platform.

Step 1: phone OTP

The phone OTP step gates the rest of the KYC walkthrough. The reader enters a phone number, receives a numeric OTP, and confirms. The phone number is the verification anchor for the rest of the walkthrough.

Step 2: PAN submission

PAN submission follows the phone OTP step. The platform validates the PAN against the issuing authority. The redaction on the submitted copy should keep the PAN number visible (the platform needs it) and the personal fields redacted.

Step 3: address proof

Address proof can be an Aadhaar card, a utility bill, a bank statement, or a rental agreement. The redaction should keep the document type visible and the personal fields redacted. The platform that accepts a wider range of address proofs is the platform that handles edge cases better.

Step 4: account verification

Account verification completes the walkthrough. The reader's account is now eligible for the first withdrawal. The processing window for the first withdrawal is commonly 24 to 72 hours; the platform should name the window in the withdrawal disclaimer.

A passport, a PAN-style card and a printed address proof laid out on a walnut desk, each with a clean redacted placeholder band

RNG audit reading

The 2026 iTech Labs RNG audit note is the most cited reference on the desk. The audit covers deck-shuffle integrity and discard-pile randomness on one regulated platform.

What the audit covers

The audit covers deck-shuffle integrity (the entropy of the shuffle) and discard-pile randomness (the entropy of the discard pile across a sample of hands). The audit is named as evidence, not endorsement; the desk does not publish a platform rating derived from the audit.

What the audit does not cover

The audit does not cover payout rates, win rates, or platform ratings. The desk refuses to publish any number that the audit does not name. The audit covers one regulated platform at one point in time; later updates land in the .

Reading an RNG audit

Audit nameiTech Labs 2026 RNG audit note
Audit date21 March 2026
CoverageDeck-shuffle entropy + discard-pile randomness
Platform scopeOne regulated platform, named as evidence
Update cadenceAnnual; updates land in the news feed

Withdrawal disclaimer reading

The withdrawal disclaimer should answer four questions. A disclaimer that does not name a processing window is a disclaimer to ask about before depositing.

The four questions

One: what is the minimum withdrawal amount? Two: what is the maximum withdrawal per day? Three: what is the processing window (commonly 24 to 72 hours for UPI)? Four: what verification step gates the first withdrawal?

What a red flag looks like

A disclaimer that does not name a processing window is a red flag. A disclaimer that names a "variable" processing window with no upper bound is a red flag. A disclaimer that hides the minimum and maximum behind a separate T&C PDF is a red flag. Three red flags together is enough to walk away.

A modern smartphone on a wooden desk, screen showing a generic settings panel with a soft horizontal slider and masked placeholder values

Support desk reading

What a working support channel looks like.

Working emailNamed in the lobby; responds within one business day during business hours
Working phoneNamed in the lobby; staffed during business hours; recorded for verification
Named agentThe first response names a human agent with a ticket ID; the desk treats that as the verification anchor for the rest of the support relationship
Escalation pathThe platform publishes an escalation path for unresolved queries, including a named regulator or ombudsman

Lobby design reading

Three checks for the lobby surface.

Are the rules in the lobby?

A regulated platform publishes the rules inside the lobby, not behind a separate T&C PDF. The reader should be able to read the rules without scrolling past the deposit button.

Is the responsible-play link visible?

The responsible-play link should sit in the lobby footer or the account settings menu. A platform that hides the link behind a separate app download is a platform to walk away from.

Is the customer-care channel visible?

The customer-care channel should be reachable from the lobby, not from a separate support site. The channel should name a working email and a working phone.

KYC walkthrough in detail

The four steps, the documents, the redactions.

Step 1 in detail: phone OTP

The phone OTP step gates the rest of the walkthrough. The phone number is the verification anchor for the platform's KYC system. The reader should use a phone number that the reader can answer during business hours; the OTP window is commonly five minutes.

Step 2 in detail: PAN submission

PAN submission follows the phone OTP. The platform validates the PAN against the issuing authority. The submitted copy should keep the PAN number visible (the platform needs it) and the personal fields redacted (the desk recommends a single redaction band across the name and address).

Step 3 in detail: address proof

Address proof can be an Aadhaar card, a utility bill, a bank statement, or a rental agreement. The redaction should keep the document type visible (Aadhaar, utility bill) and the personal fields redacted. The platform that accepts a wider range of address proofs is the platform that handles edge cases better.

Step 4 in detail: account verification

Account verification completes the walkthrough. The reader's account is now eligible for the first withdrawal. The processing window for the first withdrawal is commonly 24 to 72 hours; the platform should name the window in the withdrawal disclaimer.

Support desk reading in detail

Four observable signals, ranked by what they reveal.

Working email

Named in the lobby; responds within one business day during business hours. The platform that names a generic info@ address without a department structure is a platform that treats support as a queue, not as a relationship.

Working phone

Named in the lobby; staffed during business hours; recorded for verification. The platform that names a phone number without business hours is a platform that has not committed to a support window.

Named agent

The first response names a human agent with a ticket ID. The desk treats that as the verification anchor for the rest of the support relationship. The platform that responds only with ticket IDs and never names a human is the platform to walk away from.

Escalation path

The platform publishes an escalation path for unresolved queries, including a named regulator or ombudsman. The platform that has no escalation path beyond the chatbot is a platform that does not recognise the reader's right to escalate.

RNG audit reading in detail

Five observations about an audit certificate.

Observation 1: the audit name

The audit name is the verification anchor. The 2026 iTech Labs RNG audit note is named as evidence; the desk publishes the name and the date. A platform that does not name the auditor is a platform that has not been audited.

Observation 2: the audit scope

The audit scope is what the audit covers. The 2026 iTech Labs audit covers deck-shuffle integrity and discard-pile randomness on one regulated platform. The desk publishes the scope; the reader can verify what the audit covers and what it does not.

Observation 3: the audit date

The audit date is the freshness anchor. The 2026 iTech Labs audit note is dated 21 March 2026. The desk publishes the date; the reader can verify the freshness. An audit dated more than a year old is a stale audit.

Observation 4: the platform scope

The platform scope is the named platform. The audit covers one regulated platform; the desk does not extrapolate the audit to other platforms. A platform that claims an audit from another platform is making an unsupported claim.

Observation 5: the next update

The next update lands in the desk's . The reader can subscribe to the news feed for the next audit note. The desk publishes the next audit name and date when it lands.

Next desk

Read the responsible-play desk.

The responsible-play desk walks through the reader-side controls: five self-rules, weekly log, room-mate script, helplines, self-exclusion and state restrictions. The reviews desk pairs the platform knowledge with the eight pre-deposit checks.