us

216.73.217.98

REGULATORY GEOFENCING

Keep Every User Inside a Licensed Jurisdiction

Shufti Geo Fencing confirms a user is physically inside a permitted jurisdiction, continuously, on the same platform as KYC and AML. Every check produces one audit trail for the person and the place.

Geo Fencing app mockup — Inside Permitted Area status with Detect location, Check jurisdiction and One audit trail, on the same platform as KYC + AML
SHUFTI IMPACT METRICS

Location Assurance, Bound to Identity

3
Location signals fused per check
0–100
Trust score on every verdict
240+
Regions Actively Processed
Trusted by Leading Digital Enterprises Worldwide
Hero Cashew GemOne Banxy Bitget IronFX Penn National Gaming Rakuten Noteris Witzeal

Signal Fusion

One Engine, Every Location Signal

GPS Positioning

Precise coordinates from the device.

Wi-Fi Triangulation

Known networks corroborate or contradict the GPS reading.

Cellular Resolution

Tower data covers sessions where GPS degrades indoors.

VPN and Proxy Detection

Masked connection overrides the trust score outright.

GPS Spoofing Detection

Coordinates no second source supports are exposed and declined.

Device Integrity

Rooted, jailbroken and emulated devices are routed to review.

Full Capabilities

One Stack for Location and Compliance

Boundary Polygon and Confidence Radius OFAC / MiCA Geoblocking On-Premise Venue Beacon Identity Step-Up on Geo-Anomaly

Define the geofence: draw the boundary, enforce it

  • Boundary Polygon and Confidence Radius

    Draw the permitted area as a polygon or radius, mapped to the licence by market.

  • OFAC / MiCA Geoblocking

    Allow or block access by zone to meet OFAC and MiCA obligations, bound to the verified identity.

  • On-Premise Venue Beacon

    Hold a metre-level fence inside a venue or close to a boundary line.

  • Identity Step-Up on Geo-Anomaly

    A boundary crossing triggers re-verification before access continues.

App Open Registration Login Redemption and Withdrawal

Where it triggers: checks fire when you choose

  • App Open

    A pre-KYC check at launch turns away a restricted user before any verification spend begins.

  • Registration

    Location confirmed at sign-up binds the account to a verified jurisdiction from day one.

  • Login

    Re-confirmed at each session start, catching a user who has travelled or is masking their connection.

  • Redemption and Withdrawal

    Verified before funds leave the platform, when jurisdictional risk carries the most weight.

VPN, Proxy and TOR Detection GPS Spoofing Detection Device Tampering IP and Device Mismatch

Risk and integrity: catch the location that lies

  • VPN, Proxy and TOR Detection

    Detected and declined, even above the configured trust threshold.

  • GPS Spoofing Detection

    A reading no other source supports is exposed against fused Wi-Fi and cellular, and declined.

  • Device Tampering

    Rooted, jailbroken and emulated devices are routed to review.

  • IP and Device Mismatch

    When IP and device location disagree, the check goes to review.

Allow Except Restricted Restricted Beats Allowed Distance to Boundary No App Update Needed

Jurisdiction control: restricted always wins

  • Allow Except Restricted

    Allowed everywhere except the regions restricted, state by state or country by country.

  • Restricted Beats Allowed

    A confirmed restricted location overrides a passing trust score every time.

  • Distance to Boundary

    Re-check frequency rises as a user approaches a restricted border.

  • No App Update Needed

    Region map changes apply in real time from the configuration console.

Periodic Re-verification Grace Period Border-Aware Frequency Crossing and IP-Change Handling

Session monitoring: confirmed through the whole session

  • Periodic Re-verification

    Re-checked at login and roughly every 30 minutes, the cadence most compliance frameworks require.

  • Grace Period

    A 30-second grace period absorbs a brief signal drop, so a real user is not cut off.

  • Border-Aware Frequency

    Re-checks increase to every 5 seconds as a crossing becomes imminent.

  • Crossing and IP-Change Handling

    The session is re-checked on any IP change and ended on a confirmed restricted position.

How It Works

Three Layers, One Verdict

01

STEP 01

Signal fusion — GPS, Wi-Fi and cellular cross-checked and matched

Signal Layer

GPS, Wi-Fi and cellular are fused and cross-checked. A contradiction between sources is treated as fraud, not noise.

02

STEP 02

Investigation and trust scoring mockup

Trust Layer

Each check returns a trust score from 0 to 100 against a configurable threshold, 70 in Balanced mode. Risk signals override the score outright.

03

STEP 03

Audit logs and decision record mockup

Decision Layer

The position is checked against the region map, where restricted always wins. Shufti returns Allow, Review or Decline with a reason code and audit log. Identity, KYC and AML run on the same integration, giving the person and the place one shared audit trail.

Book Personalised Demo
Built for Compliance: Go live in minutes with our flexible API and lightweight SDKs

Single API, Seamless Integration

Build fully customisable verification flows with seamless backend integration.

  • Gain full control by customising verification flows end-to-end.
  • Integrate seamlessly with your backend for quick implementation.
  • Design flexible verification journeys tailored to your users.
Explore API Docs
RESTful API img

Launch a native verification experience in your mobile app within minutes.

  • Launch native verification within minutes on iOS or Android.
  • Use ready-made UI with camera, capture, and real-time feedback.
  • Customise flows to fit seamlessly into your mobile app.
Explore SDKs Docs
Lightweight SDK image

With KYC Journey Builder, create personalised verification journeys without writing a single line of code.

  • Customise your journey effortlessly with drag-and-drop functionality.
  • Instantly see how your verification flow looks for your users.
  • Easily connect with Hosted Verification for a consistent, branded experience.
Explore More
On-Premise Deployment image

Run Shufti within your own identical-capability infrastructure for maximum data control and privacy.

  • Keep all sensitive information in-house to meet strict governance and data residency requirements.
  • Keep sensitive information fully private and secure in-house.
  • Deploy in highly regulated sectors without compromising compliance.
Contact Sales
On-Premise Deployment image

Evidence-Based AML Monitoring for Every Regulated Business

Real-world scenarios where TTM monitors for AML risk

Sell Only Where Licensed

Region-restricted goods sold in unlicensed markets expose operators to regulatory fines and enforcement action with little warning. Shufti gates each listing to its permitted jurisdictions against the configured region map, keeping buyers and sellers inside markets the operator is cleared to serve.

Built for Your Team

One Integration,
Every Stakeholder

Book a Demo

Compliance Officer

Regulators expect an audit trail that links the verified person to their confirmed location at every check point, and gaps in that record become findings. Shufti logs every verdict with trust score, reason code and timestamp on a GLI-certified, AGCO-approved engine, audit-ready before a regulator asks.

See Compliance Officers →

Product Manager

Adding geolocation typically means a second vendor, a second integration and a second contract, each of which slows market entry and increases maintenance overhead. Shufti puts verified location and identity on one SDK, so new-market launches move faster with less drop-off at the jurisdiction-check step.

See Product Manager →

Developer

Most geolocation integrations require significant build time, app updates for every region change and separate documentation from the identity stack. Native SDKs for iOS, Android, Web and React Native with a REST API, webhooks and a same-day sandbox. A typical integration takes around five days.

See Developer →

Fraud Analyst

Location-only checks do not surface who is behind a masked or spoofed connection, making it hard to build a case or close an account with confidence. Shufti binds every VPN, proxy, spoofing and device-tampering override to the verified identity, giving the fraud team the link they need to act.

See Fraud Analyst →

EVERYTHING YOU NEED TO KNOW IN ONE PLACE

Frequently Asked Questions

Who makes the final allow or decline call?

The operator does. Shufti returns a verdict of Allow, Review or Decline with a reason code, and the platform enforces it. Shufti never takes unilateral action on a user's session. That distinction matters in regulated markets where audit accountability sits with the licence holder.

Why use three location signals instead of one?

GPS alone is easy to spoof. IP alone is unreliable indoors. Wi-Fi triangulation alone degrades in open areas. Fusing all three means each signal validates the others, and a mismatch between them is treated as a risk signal rather than noise. The result is a position that holds up in an audit, not just in good network conditions.

A user passes the trust score but has a VPN active. What happens?

The check is declined. Risk signals override the score regardless of threshold. VPN, proxy, TOR and GPS spoofing are declined outright, and an IP-device mismatch or device tampering routes to review. The override is linked to the verified identity, so the fraud team knows exactly whose account it is.

How does the restricted-region policy work in practice?

Access is allowed everywhere by default, except the regions explicitly restricted in the console. Restrictions are configured per market across 240+ countries and regions. When a user lands on a restricted position, that always wins regardless of their trust score. Region map changes apply from the console in real time with no app update required.

Is location only checked at the point of login?

No. Location is re-confirmed at login and roughly every 30 minutes throughout the session, and increases to every 5 seconds as a user nears a restricted border. An IP change triggers an immediate re-check. A 30-second grace period absorbs a brief signal blip so a legitimate user is not cut off mid-session.

How is this different from proof of address?

Proof of address confirms where someone is registered at one point in time. Shufti Geo Fencing confirms where the user physically is during the session and detects manipulation no document can reveal. Most regulated operators run both: proof of address at onboarding, geofencing continuously.

Can the compliance team adjust settings without a developer?

Yes. Triggers, the trust threshold, the failure action and the region map are all managed in the console, and changes apply with no app update. Developer involvement is only needed for the initial integration, not for ongoing configuration.

How does it deploy and what does the contract cover?

Shufti Geo Fencing deploys as a native SDK for iOS, Android, Web and React Native, with a REST API and webhooks for server-side enforcement. One contract covers identity and location together. Shufti is second-source friendly with no exclusivity clause, and pricing is per verification with no per-ping penalty.

Evaluate Your Geo-Compliance Coverage

See how Shufti confirms user location, blocks spoofing and produces an audit-ready verdict your platform enforces, configured by your team.