REGULATORY GEOFENCING
Keep Every User Inside a Licensed Jurisdiction
Shufti Geo Fencing confirms a user is physically inside a permitted jurisdiction, continuously, on the same platform as KYC and AML. Every check produces one audit trail for the person and the place.
Location Assurance, Bound to Identity
Signal Fusion
One Engine, Every Location Signal

GPS Positioning
Precise coordinates from the device.

Wi-Fi Triangulation
Known networks corroborate or contradict the GPS reading.

Cellular Resolution
Tower data covers sessions where GPS degrades indoors.

VPN and Proxy Detection
Masked connection overrides the trust score outright.

GPS Spoofing Detection
Coordinates no second source supports are exposed and declined.

Device Integrity
Rooted, jailbroken and emulated devices are routed to review.
Full Capabilities
One Stack for Location and Compliance
Define the geofence: draw the boundary, enforce it
Boundary Polygon and Confidence Radius
Draw the permitted area as a polygon or radius, mapped to the licence by market.
OFAC / MiCA Geoblocking
Allow or block access by zone to meet OFAC and MiCA obligations, bound to the verified identity.
On-Premise Venue Beacon
Hold a metre-level fence inside a venue or close to a boundary line.
Identity Step-Up on Geo-Anomaly
A boundary crossing triggers re-verification before access continues.
Where it triggers: checks fire when you choose
App Open
A pre-KYC check at launch turns away a restricted user before any verification spend begins.
Registration
Location confirmed at sign-up binds the account to a verified jurisdiction from day one.
Login
Re-confirmed at each session start, catching a user who has travelled or is masking their connection.
Redemption and Withdrawal
Verified before funds leave the platform, when jurisdictional risk carries the most weight.
Risk and integrity: catch the location that lies
VPN, Proxy and TOR Detection
Detected and declined, even above the configured trust threshold.
GPS Spoofing Detection
A reading no other source supports is exposed against fused Wi-Fi and cellular, and declined.
Device Tampering
Rooted, jailbroken and emulated devices are routed to review.
IP and Device Mismatch
When IP and device location disagree, the check goes to review.
Jurisdiction control: restricted always wins
Allow Except Restricted
Allowed everywhere except the regions restricted, state by state or country by country.
Restricted Beats Allowed
A confirmed restricted location overrides a passing trust score every time.
Distance to Boundary
Re-check frequency rises as a user approaches a restricted border.
No App Update Needed
Region map changes apply in real time from the configuration console.
Session monitoring: confirmed through the whole session
Periodic Re-verification
Re-checked at login and roughly every 30 minutes, the cadence most compliance frameworks require.
Grace Period
A 30-second grace period absorbs a brief signal drop, so a real user is not cut off.
Border-Aware Frequency
Re-checks increase to every 5 seconds as a crossing becomes imminent.
Crossing and IP-Change Handling
The session is re-checked on any IP change and ended on a confirmed restricted position.
How It Works
Three Layers, One Verdict
01
STEP 01

Signal Layer
GPS, Wi-Fi and cellular are fused and cross-checked. A contradiction between sources is treated as fraud, not noise.
02
STEP 02

Trust Layer
Each check returns a trust score from 0 to 100 against a configurable threshold, 70 in Balanced mode. Risk signals override the score outright.
03
STEP 03

Decision Layer
The position is checked against the region map, where restricted always wins. Shufti returns Allow, Review or Decline with a reason code and audit log. Identity, KYC and AML run on the same integration, giving the person and the place one shared audit trail.
Single API, Seamless Integration
Build fully customisable verification flows with seamless backend integration.
- Gain full control by customising verification flows end-to-end.
- Integrate seamlessly with your backend for quick implementation.
- Design flexible verification journeys tailored to your users.
Launch a native verification experience in your mobile app within minutes.
- Launch native verification within minutes on iOS or Android.
- Use ready-made UI with camera, capture, and real-time feedback.
- Customise flows to fit seamlessly into your mobile app.
With KYC Journey Builder, create personalised verification journeys without writing a single line of code.
- Customise your journey effortlessly with drag-and-drop functionality.
- Instantly see how your verification flow looks for your users.
- Easily connect with Hosted Verification for a consistent, branded experience.
Run Shufti within your own identical-capability infrastructure for maximum data control and privacy.
- Keep all sensitive information in-house to meet strict governance and data residency requirements.
- Keep sensitive information fully private and secure in-house.
- Deploy in highly regulated sectors without compromising compliance.
Evidence-Based AML Monitoring for Every Regulated Business
Real-world scenarios where TTM monitors for AML risk
Sell Only Where Licensed
Region-restricted goods sold in unlicensed markets expose operators to regulatory fines and enforcement action with little warning. Shufti gates each listing to its permitted jurisdictions against the configured region map, keeping buyers and sellers inside markets the operator is cleared to serve.
Compliance Officer
Regulators expect an audit trail that links the verified person to their confirmed location at every check point, and gaps in that record become findings. Shufti logs every verdict with trust score, reason code and timestamp on a GLI-certified, AGCO-approved engine, audit-ready before a regulator asks.
See Compliance Officers →Product Manager
Adding geolocation typically means a second vendor, a second integration and a second contract, each of which slows market entry and increases maintenance overhead. Shufti puts verified location and identity on one SDK, so new-market launches move faster with less drop-off at the jurisdiction-check step.
See Product Manager →Developer
Most geolocation integrations require significant build time, app updates for every region change and separate documentation from the identity stack. Native SDKs for iOS, Android, Web and React Native with a REST API, webhooks and a same-day sandbox. A typical integration takes around five days.
See Developer →Fraud Analyst
Location-only checks do not surface who is behind a masked or spoofed connection, making it hard to build a case or close an account with confidence. Shufti binds every VPN, proxy, spoofing and device-tampering override to the verified identity, giving the fraud team the link they need to act.
See Fraud Analyst →EVERYTHING YOU NEED TO KNOW IN ONE PLACE
Frequently Asked Questions
Who makes the final allow or decline call?
The operator does. Shufti returns a verdict of Allow, Review or Decline with a reason code, and the platform enforces it. Shufti never takes unilateral action on a user's session. That distinction matters in regulated markets where audit accountability sits with the licence holder.
Why use three location signals instead of one?
GPS alone is easy to spoof. IP alone is unreliable indoors. Wi-Fi triangulation alone degrades in open areas. Fusing all three means each signal validates the others, and a mismatch between them is treated as a risk signal rather than noise. The result is a position that holds up in an audit, not just in good network conditions.
A user passes the trust score but has a VPN active. What happens?
The check is declined. Risk signals override the score regardless of threshold. VPN, proxy, TOR and GPS spoofing are declined outright, and an IP-device mismatch or device tampering routes to review. The override is linked to the verified identity, so the fraud team knows exactly whose account it is.
How does the restricted-region policy work in practice?
Access is allowed everywhere by default, except the regions explicitly restricted in the console. Restrictions are configured per market across 240+ countries and regions. When a user lands on a restricted position, that always wins regardless of their trust score. Region map changes apply from the console in real time with no app update required.
Is location only checked at the point of login?
No. Location is re-confirmed at login and roughly every 30 minutes throughout the session, and increases to every 5 seconds as a user nears a restricted border. An IP change triggers an immediate re-check. A 30-second grace period absorbs a brief signal blip so a legitimate user is not cut off mid-session.
How is this different from proof of address?
Proof of address confirms where someone is registered at one point in time. Shufti Geo Fencing confirms where the user physically is during the session and detects manipulation no document can reveal. Most regulated operators run both: proof of address at onboarding, geofencing continuously.
Can the compliance team adjust settings without a developer?
Yes. Triggers, the trust threshold, the failure action and the region map are all managed in the console, and changes apply with no app update. Developer involvement is only needed for the initial integration, not for ongoing configuration.
How does it deploy and what does the contract cover?
Shufti Geo Fencing deploys as a native SDK for iOS, Android, Web and React Native, with a REST API and webhooks for server-side enforcement. One contract covers identity and location together. Shufti is second-source friendly with no exclusivity clause, and pricing is per verification with no per-ping penalty.
Evaluate Your Geo-Compliance Coverage
See how Shufti confirms user location, blocks spoofing and produces an audit-ready verdict your platform enforces, configured by your team.



