Geofencing today relies on IP addresses, a network routing artifact that identifies where infrastructure is registered, not where the person is. Octet produces a cryptographic proof of physical location, tied to a specific device, hardware-signed and independently verifiable. It cannot be faked with a VPN, spoofed, or replayed.
iCloud Private Relay turns a point on the map into an 800 km² area. Near borders, device IPs resolve to the wrong state. 44% of NJ sports bets are placed within 2 miles of a state line.[5]
Sports betting is licensed state by state: every wager must originate from a permitted jurisdiction. Prediction markets face 20+ lawsuits over whether states or the CFTC control jurisdiction.[1] Regardless of outcome, platforms need proof the user is in a permitted state, per transaction.
Apple's iCloud Private Relay illustrates the problem. When a user turns on Private Relay, their IP address is assigned to an 800 km² area, about the size of Singapore.[2] A 2023 measurement study found median errors exceeding 1,000 miles for Private Relay IPv4 users.[3] Apple publishes egress IP locations to help geolocation vendors stay current; it does not help. MaxMind, the dominant provider, is wrong about a user's location more than one in three times by its own confidence threshold, and publishes 100 km as a normal example of error.[4] At the NY/NJ border, a single Private Relay region covers Manhattan, Jersey City, and Newark. At Primm, Nevada, it spans into California, where sports betting is illegal.
620 km average disagreement between databases on the same IP address. Near borders, IPs resolve to the wrong country.
OFAC comprehensively embargoes Cuba, Iran, and North Korea, along with the occupied Ukrainian regions, and runs targeted programs against nine more jurisdictions, including Russia. Every major exchange screens with IP geolocation. The average disagreement between databases on the same IP is 620 km.[6] Land borders between sanctioned and non-sanctioned countries are narrower than this. 68.3 million people in sanctioned jurisdictions live within 100 km of a non-sanctioned border; 150.1 million within 200 km.[7] Their IPs resolve to the wrong country without a VPN. North Korean IT workers infiltrate crypto companies through remote hiring, claiming permitted jurisdictions. An IP address cannot distinguish a developer in Austin from one in Pyongyang.
An estimated 1.5–2M US users access offshore exchanges that explicitly geofence and block US IPs.
Reg S lets issuers sell tokens without SEC registration, provided they are not sold to US persons during a compliance period of up to one year. Sensor Tower confirmed 877,000 US-based monthly active users on just three offshore exchanges that explicitly block US users: Bybit, Bitget, and OKX.[8] Total US-based users on offshore exchanges that geofence the US: an estimated 1.5–2 million.[9][10] Any Reg S offering relying on IP-based controls faces the same exposure.
IP-based geolocation is used because no better passive signal existed.
Octet runs as an SDK inside your app. No pop-up, no permissions prompt. When your app asks for a jurisdiction check, the SDK fuses inertial, GPS, and RF signals into a proof and signs it with a hardware key that never leaves the Secure Enclave (iOS) or StrongBox (Android). The result is a predicate: in jurisdiction, or not. Coordinates never leave the device.
Trajectory computed on-device. Never leaves. Only the signed proof is shared.
You set rules: "user must be in New York," "not in a sanctioned country," "within 50m of London HQ." The policy ships to the SDK on every device.
Web dashboardLives inside your app. Fuses inertial, GPS, and RF signals into a signed proof. The user sees nothing. The signing key is locked inside the Secure Enclave or StrongBox; it cannot be extracted or faked.
Your mobile appReceives the proof alongside the user's action. Verifies the signature with a public key. Verification happens on your side. Octet is not in the loop.
Your backendThe SDK never talks to your server. Your server never talks to the device. The proof is signed inside the Secure Enclave or StrongBox, the same hardware that secures Face ID, Apple Wallet, and Google Pay. We manage the key lifecycle. You control verification.
It tells you which organisation holds a block of addresses in a registry. The industry relies on it because GPS is spoofable, requires permissions, and is unavailable in browsers. IP geolocation is used because no better passive signal existed.
Same IP address. Three databases. One says Iran: sanctioned. Two say Turkey: permitted. No VPN involved. This is database-level disagreement at a border.
people in sanctioned countries live within 100km of a non-sanctioned border.[7] No VPN needed.
within 200km. At this range, databases routinely disagree on which country the user is in.
The same error works in reverse. 16.4 million people in non-sanctioned countries live within 100km of a sanctioned border. 33.5 million within 200km. A Turkish resident in Hakkari, an Azerbaijani in Astara, a Pakistani in Quetta: their IP resolves to sanctioned address space. They are wrongly blocked.
A compliance false positive that is also a detection false negative: enforcement resources spent on the wrong people. IP blocks get reallocated between registries, update cycles lag by weeks, and registry policy allows registration country to differ from usage country. At border-city scale, this is structural.
Sub-km proof of permitted-state presence before every wager. Invisible to the user. VPN-proof.
From database-level guessing to cryptographic certainty. Resilient to VPNs, CGNAT, Starlink, border proximity.
Proof of jurisdiction at every transaction. Ex-US without KYC. Flow-back prevention on secondary trades.
Full methodology and 14 additional references at IP Address Cannot Prove Where Someone Is