Security Engineered For The Games
You Can't Risk Losing Control Of
A fully encrypted, NDA-enforced Player Experience (Px) platform built to safeguard unreleased builds, early concepts, and high-stakes ideas. Enterprise-grade protection for game studios, publishers, GUR teams, and anyone shaping the future of play.


Trusted by game teams worldwide and aligned with industry-standard security practices.
Trusted by game teams worldwide and aligned with industry-standard security practices.
Built To Secure
Every Layer Of Your Research Workflow
Performance-ready systems, strict controls, and continuous oversight built to support studios running research at scale.
Secure Cloud Setup
Your builds live in fortified, compliant cloud environments designed to keep unauthorized access out.
Secure Cloud Setup
Your builds live in fortified, compliant cloud environments designed to keep unauthorized access out.
Data Encryption (End-to-End)
Every game build is protected in transit with TLS 1.2+, and is locked down from upload to insight.
Data Encryption (End-to-End)
Every game build is protected in transit with TLS 1.2+, and is locked down from upload to insight.
Active Oversight
Every access, download, and interaction is logged and monitored to flag suspicious behaviour instantly.
Active Oversight
Every access, download, and interaction is logged and monitored to flag suspicious behaviour instantly.
Standards-Aligned Architecture
Security is baked into our infrastructure with hardened configurations and industry-standard control frameworks.
Standards-Aligned Architecture
Security is baked into our infrastructure with hardened configurations and industry-standard control frameworks.
Secure Software Development
Our development process includes built-in security checks, controlled permissions, and disciplined engineering practices.
Secure Software Development
Our development process includes built-in security checks, controlled permissions, and disciplined engineering practices.
Confidentiality by Default
Every tester signs a binding NDA, and every session is tied to device metadata for full accountability.
Confidentiality by Default
Every tester signs a binding NDA, and every session is tied to device metadata for full accountability.
Controlled Asset Access
All builds, recordings, and study assets remain access-restricted and fully encrypted throughout their lifecycle.
Controlled Asset Access
All builds, recordings, and study assets remain access-restricted and fully encrypted throughout their lifecycle.

Kill Switch (Remote Build Deactivation)
Build access ends the moment the test concludes, remotely and automatically. The build cannot be opened outside the Lysto app and becomes completely inaccessible after the session.

Auto-Deletion After Session End
All gameplay recordings are automatically deleted from the player's device once the session concludes.

Secure Build Distribution
Builds are encrypted end-to-end and accessible only to verified testers who have cleared NDA consent and identity checks.

Strict NDA Gatekeeping
Players cannot access your build until they have signed a legally enforceable NDA.

Screenshot Protection
Unauthorized capture attempts are detected, traced to the tester's identity, and instantly flagged by us.

Role-Based Access (Studio Control)
Once submitted, submissions are only accessible to authorized studio personnel. You decide who sees builds, who sees insights, and who gets access, down to the permission level.

Role-Based Access (Studio Control)
Once submitted, submissions are only accessible to authorized studio personnel. You decide who sees builds, who sees insights, and who gets access, down to the permission level.
Where Authentic Player Experience Meets Uncompromised
Where Authentic Player Experience Meets Uncompromised
Build Protection
Build Protection
Lysto locks down every layer of your playtest - infrastructure, panel, permissions, and distribution, so your teams can run research at speed without exposing your build or compromising insight quality.
Lysto locks down every layer of your playtest - infrastructure, panel, permissions, and distribution, so your teams can run research at speed without exposing your build or compromising insight quality.


A Secure, Screened, Global Player Panel
A Secure, Screened, Global Player Panel
You Can Depend On
You Can Depend On
From NDA enforcement to identity checks and behavioural monitoring, the curated global player panel upholds the level of authenticity, reliability, and control your research requires.
From NDA enforcement to identity checks and behavioural monitoring, the curated global player panel upholds the level of authenticity, reliability, and control your research requires.
Mandatory NDA Compliance
Mandatory NDA Compliance
Every participant signs a legally binding NDA before gaining access to any builds, with agreements timestamped and stored for traceability.
Every participant signs a legally binding NDA before gaining access to any builds, with agreements timestamped and stored for traceability.
Strict Qualification Process
Strict Qualification Process
Only pre-screened players who meet demographic and behavioural requirements are invited to participate.
Only pre-screened players who meet demographic and behavioural requirements are invited to participate.
Verified Player Identities
Verified Player Identities
Sessions are linked to device IDs, and session metadata, ensuring participation comes from genuine, identifiable players.
Sessions are linked to device IDs, and session metadata, ensuring participation comes from genuine, identifiable players.
Behaviour Monitoring and Enforcement
Behaviour Monitoring and Enforcement
Suspicious activity is detected in real time, and any issue can be contained quickly through instant access removal or build deactivation.
Suspicious activity is detected in real time, and any issue can be contained quickly through instant access removal or build deactivation.
Security Tailored to Every Platform Your Team Tests On
Security Tailored to Every Platform Your Team Tests On
Each platform comes with its own vulnerabilities. Lysto applies platform-specific safeguards and controlled distribution methods to ensure each type of playtest remains contained, compliant, and secure.
Secure Cloud Streaming Inside the Lysto PC App
Secure Cloud Streaming Inside the Lysto PC App
PC playtests run securely inside the Lysto PC App using cloud streaming. Players never download or install the game build, ensuring your game files remain protected at all times.
PC playtests run securely inside the Lysto PC App using cloud streaming. Players never download or install the game build, ensuring your game files remain protected at all times.
No Local Executables or Files
No Local Executables or Files
Since the build is streamed, no game files, installers, or executables are stored on the player's device. Nothing can be extracted, copied, or reused after the session.
Since the build is streamed, no game files, installers, or executables are stored on the player's device. Nothing can be extracted, copied, or reused after the session.
Browser Games Open Directly in the Lysto PC App
Browser Games Open Directly in the Lysto PC App
Browser-based games launch securely within the Lysto PC App without exposing the original game URL, source code, or hosting environment to players.
Browser-based games launch securely within the Lysto PC App without exposing the original game URL, source code, or hosting environment to players.
Protected Playtest Environment
Protected Playtest Environment
Every playtest runs inside a secure, isolated environment that prevents external tools, unauthorized file access, and debugging attempts, keeping your builds safe throughout testing.
Every playtest runs inside a secure, isolated environment that prevents external tools, unauthorized file access, and debugging attempts, keeping your builds safe throughout testing.
Immediate Access Revocation
Immediate Access Revocation
As soon as the playtest is completed and gameplay is uploaded, access is revoked instantly. No residual files, cached data, or playable content remain on the player's device.
As soon as the playtest is completed and gameplay is uploaded, access is revoked instantly. No residual files, cached data, or playable content remain on the player's device.
Agents Security
XORIN
EIRIN
XORIN SECURITY
Security At A Glance
Security and trust are fundamental to Xorin. We work to protect our customers' projects, data, and accounts through security-conscious engineering, controlled access, ongoing testing, and responsible handling of vulnerabilities.
Protecting customer data
We apply safeguards appropriate to the sensitivity of the data handled by our services. These include authenticated access, encrypted network connections, credential redaction in logs, request size limits, rate limiting, and separation of customer account data.
Access to production systems and customer data is limited to authorized personnel with a legitimate operational need. We review access as our systems and team evolve.
Customers should avoid submitting secrets unless they are required for a task and should review the security and data-use terms of any third-party provider they choose to use with Xorin.
Secure development
Security is considered throughout Xorin's development lifecycle. We use code review, automated testing, dependency review, and defensive validation to reduce risk before changes reach customers.
We monitor our services, investigate unexpected behavior, and prioritize security fixes according to their severity and potential customer impact.
Account and credential security
Xorin uses authenticated sessions and secure network connections for hosted services. Sensitive authentication values are excluded or redacted from application logs where they can be identified.
Customers are responsible for protecting their devices, account credentials, and any third-party API keys they configure. We recommend using unique credentials, applying the least privilege available, rotating keys regularly, and revoking credentials that may have been exposed.
Payments
Payment card details are collected and processed by Xorin's payment provider. Xorin does not receive or store full payment card numbers.
Responsible disclosure
We welcome reports from security researchers and customers who believe they have found a vulnerability in Xorin.
Email contact@lysto.io with the subject Security disclosure and include:
the affected component and version;
a description of the issue and its potential impact;
reproducible steps or a minimal proof of concept;
relevant logs or screenshots with secrets and personal data removed; and
a safe way for us to contact you
Please act in good faith and avoid privacy violations, data loss, service disruption, social engineering, and access to data that is not yours. Allow us a reasonable opportunity to investigate and protect affected customers before making an issue public.
We will acknowledge the report, investigate it, and coordinate remediation and disclosure with the reporter. Xorin does not currently operate a public bug bounty program; rewards should not be assumed unless agreed in writing before testing.
Security advisories
Security advisories and required update instructions will be published here when a vulnerability requires customer action.
There are currently no published Xorin security advisories.
Agents Security
XORIN
EIRIN
XORIN SECURITY
Security At A Glance
Security and trust are fundamental to Xorin. We work to protect our customers' projects, data, and accounts through security-conscious engineering, controlled access, ongoing testing, and responsible handling of vulnerabilities.
Protecting customer data
We apply safeguards appropriate to the sensitivity of the data handled by our services. These include authenticated access, encrypted network connections, credential redaction in logs, request size limits, rate limiting, and separation of customer account data.
Access to production systems and customer data is limited to authorized personnel with a legitimate operational need. We review access as our systems and team evolve.
Customers should avoid submitting secrets unless they are required for a task and should review the security and data-use terms of any third-party provider they choose to use with Xorin.
Secure development
Security is considered throughout Xorin's development lifecycle. We use code review, automated testing, dependency review, and defensive validation to reduce risk before changes reach customers.
We monitor our services, investigate unexpected behavior, and prioritize security fixes according to their severity and potential customer impact.
Account and credential security
Xorin uses authenticated sessions and secure network connections for hosted services. Sensitive authentication values are excluded or redacted from application logs where they can be identified.
Customers are responsible for protecting their devices, account credentials, and any third-party API keys they configure. We recommend using unique credentials, applying the least privilege available, rotating keys regularly, and revoking credentials that may have been exposed.
Payments
Payment card details are collected and processed by Xorin's payment provider. Xorin does not receive or store full payment card numbers.
Responsible disclosure
We welcome reports from security researchers and customers who believe they have found a vulnerability in Xorin.
Email contact@lysto.io with the subject Security disclosure and include:
the affected component and version;
a description of the issue and its potential impact;
reproducible steps or a minimal proof of concept;
relevant logs or screenshots with secrets and personal data removed; and
a safe way for us to contact you
Please act in good faith and avoid privacy violations, data loss, service disruption, social engineering, and access to data that is not yours. Allow us a reasonable opportunity to investigate and protect affected customers before making an issue public.
We will acknowledge the report, investigate it, and coordinate remediation and disclosure with the reporter. Xorin does not currently operate a public bug bounty program; rewards should not be assumed unless agreed in writing before testing.
Security advisories
Security advisories and required update instructions will be published here when a vulnerability requires customer action.
There are currently no published Xorin security advisories.
Agents Security
XORIN
EIRIN
XORIN SECURITY
Security At A Glance
Security and trust are fundamental to Xorin. We work to protect our customers' projects, data, and accounts through security-conscious engineering, controlled access, ongoing testing, and responsible handling of vulnerabilities.
Protecting customer data
We apply safeguards appropriate to the sensitivity of the data handled by our services. These include authenticated access, encrypted network connections, credential redaction in logs, request size limits, rate limiting, and separation of customer account data.
Access to production systems and customer data is limited to authorized personnel with a legitimate operational need. We review access as our systems and team evolve.
Customers should avoid submitting secrets unless they are required for a task and should review the security and data-use terms of any third-party provider they choose to use with Xorin.
Secure development
Security is considered throughout Xorin's development lifecycle. We use code review, automated testing, dependency review, and defensive validation to reduce risk before changes reach customers.
We monitor our services, investigate unexpected behavior, and prioritize security fixes according to their severity and potential customer impact.
Account and credential security
Xorin uses authenticated sessions and secure network connections for hosted services. Sensitive authentication values are excluded or redacted from application logs where they can be identified.
Customers are responsible for protecting their devices, account credentials, and any third-party API keys they configure. We recommend using unique credentials, applying the least privilege available, rotating keys regularly, and revoking credentials that may have been exposed.
Payments
Payment card details are collected and processed by Xorin's payment provider. Xorin does not receive or store full payment card numbers.
Responsible disclosure
We welcome reports from security researchers and customers who believe they have found a vulnerability in Xorin.
Email contact@lysto.io with the subject Security disclosure and include:
the affected component and version;
a description of the issue and its potential impact;
reproducible steps or a minimal proof of concept;
relevant logs or screenshots with secrets and personal data removed; and
a safe way for us to contact you
Please act in good faith and avoid privacy violations, data loss, service disruption, social engineering, and access to data that is not yours. Allow us a reasonable opportunity to investigate and protect affected customers before making an issue public.
We will acknowledge the report, investigate it, and coordinate remediation and disclosure with the reporter. Xorin does not currently operate a public bug bounty program; rewards should not be assumed unless agreed in writing before testing.
Security advisories
Security advisories and required update instructions will be published here when a vulnerability requires customer action.
There are currently no published Xorin security advisories.
Platform
Platform
Become playtesters
Play Games. Earn Rewards
mobile app

Scan to get started
PC app
for playtesters
Want To Test New Games?

