Prove where the
device is. Enforce
the jurisdiction.

Geofencing today relies on IP addresses, a network routing artifact that identifies where infrastructure is registered, not where the person is. Octet produces a cryptographic proof of physical location, tied to a specific device, hardware-signed and independently verifiable. It cannot be faked with a VPN, spoofed, or replayed.


01

State-level compliance

NEW JERSEY NEW YORK 800 km² GEOHASH DEVICE 198.51.100.3 800 km² GEOHASH DEVICE 86.22.86.46

iCloud Private Relay turns a point on the map into an 800 km² area. Near borders, device IPs resolve to the wrong state. 44% of NJ sports bets are placed within 2 miles of a state line.[5]

Sports betting is licensed state by state: every wager must originate from a permitted jurisdiction. Prediction markets face 20+ lawsuits over whether states or the CFTC control jurisdiction.[1] Regardless of outcome, platforms need proof the user is in a permitted state, per transaction.

Apple's iCloud Private Relay illustrates the problem. When a user turns on Private Relay, their IP address is assigned to an 800 km² area, about the size of Singapore.[2] A 2023 measurement study found median errors exceeding 1,000 miles for Private Relay IPv4 users.[3] Apple publishes egress IP locations to help geolocation vendors stay current; it does not help. MaxMind, the dominant provider, is wrong about a user's location more than one in three times by its own confidence threshold, and publishes 100 km as a normal example of error.[4] At the NY/NJ border, a single Private Relay region covers Manhattan, Jersey City, and Newark. At Primm, Nevada, it spans into California, where sports betting is illegal.

02

Sanctions compliance

TURKEY IRAN PERMITTED SANCTIONED DEVICE 91.108.4.22 5.34.207.81

620 km average disagreement between databases on the same IP address. Near borders, IPs resolve to the wrong country.

OFAC comprehensively embargoes Cuba, Iran, and North Korea, along with the occupied Ukrainian regions, and runs targeted programs against nine more jurisdictions, including Russia. Every major exchange screens with IP geolocation. The average disagreement between databases on the same IP is 620 km.[6] Land borders between sanctioned and non-sanctioned countries are narrower than this. 68.3 million people in sanctioned jurisdictions live within 100 km of a non-sanctioned border; 150.1 million within 200 km.[7] Their IPs resolve to the wrong country without a VPN. North Korean IT workers infiltrate crypto companies through remote hiring, claiming permitted jurisdictions. An IP address cannot distinguish a developer in Austin from one in Pyongyang.

03

Ex-US jurisdiction

USA USA EUROPE → AFRICA → MIDDLE EAST → ← ASIA ← SE ASIA ← OCEANIA ↓ S. AMERICA ↓ CARIBBEAN

An estimated 1.5–2M US users access offshore exchanges that explicitly geofence and block US IPs.

Reg S lets issuers sell tokens without SEC registration, provided they are not sold to US persons during a compliance period of up to one year. Sensor Tower confirmed 877,000 US-based monthly active users on just three offshore exchanges that explicitly block US users: Bybit, Bitget, and OKX.[8] Total US-based users on offshore exchanges that geofence the US: an estimated 1.5–2 million.[9][10] Any Reg S offering relying on IP-based controls faces the same exposure.

IP-based geolocation is used because no better passive signal existed.

Define the policy.
Enforce at the device level.
Verify the proof.

Octet runs as an SDK inside your app. No pop-up, no permissions prompt. When your app asks for a jurisdiction check, the SDK fuses inertial, GPS, and RF signals into a proof and signs it with a hardware key that never leaves the Secure Enclave (iOS) or StrongBox (Android). The result is a predicate: in jurisdiction, or not. Coordinates never leave the device.

IN CA
LOS ANGELES, CALIFORNIA
OREGON CALIFORNIA NOT IN CA
CA / OREGON BORDER
CALIFORNIA NEVADA NOT IN CA
CA / NEVADA BORDER

Trajectory computed on-device. Never leaves. Only the signed proof is shared.

PROOF in_jurisdiction: true | policy: US-CA | sig: MEUCIQDx7f... | coordinates: null

How you deploy Octet

Magistrate

Define your policy

You set rules: "user must be in New York," "not in a sanctioned country," "within 50m of London HQ." The policy ships to the SDK on every device.

Web dashboard
SDK

Prove the location

Lives inside your app. Fuses inertial, GPS, and RF signals into a signed proof. The user sees nothing. The signing key is locked inside the Secure Enclave or StrongBox; it cannot be extracted or faked.

Your mobile app
Your server

Verify the proof

Receives the proof alongside the user's action. Verifies the signature with a public key. Verification happens on your side. Octet is not in the loop.

Your backend

The SDK never talks to your server. Your server never talks to the device. The proof is signed inside the Secure Enclave or StrongBox, the same hardware that secures Face ID, Apple Wallet, and Google Pay. We manage the key lifecycle. You control verification.


An IP address identifies where network infrastructure is registered, not where the person is.

It tells you which organisation holds a block of addresses in a registry. The industry relies on it because GPS is spoofable, requires permissions, and is unavailable in browsers. IP geolocation is used because no better passive signal existed.

ONE IP ADDRESS, THREE DATABASES, THREE COUNTRIES
620km avg. database disagreement Nur et al., IEEE 2023 · 6.3M IPs IRAN IRAN TURKEY IRAQ TURKMENISTAN AFGHANISTAN PAKISTAN Persian Gulf MAXMIND Urmia, Iran SANCTIONED IP2LOCATION Van, Turkey PERMITTED DB-IP Diyarbakır, Turkey PERMITTED

Same IP address. Three databases. One says Iran: sanctioned. Two say Turkey: permitted. No VPN involved. This is database-level disagreement at a border.

BORDER POPULATION AT RISK
0

people in sanctioned countries live within 100km of a non-sanctioned border.[7] No VPN needed.

0

within 200km. At this range, databases routinely disagree on which country the user is in.

THE MIRROR PROBLEM

The same error works in reverse. 16.4 million people in non-sanctioned countries live within 100km of a sanctioned border. 33.5 million within 200km. A Turkish resident in Hakkari, an Azerbaijani in Astara, a Pakistani in Quetta: their IP resolves to sanctioned address space. They are wrongly blocked.

A compliance false positive that is also a detection false negative: enforcement resources spent on the wrong people. IP blocks get reallocated between registries, update cycles lag by weeks, and registry policy allows registration country to differ from usage country. At border-city scale, this is structural.

0 Average disagreement between databases on the same IP address
0 In sanctioned countries, within 100km of a non-sanctioned border
0 In sanctioned countries, within 200km of a non-sanctioned border
0 US-based MAUs confirmed on three offshore exchanges that geofence the US. Estimated total: 1.5–2M.

How platforms enforce jurisdiction today

KYC / Identity verification
IP Geolocation / Cloudflare
Octet
What it proves
~  Where a person says they live. A user who passed KYC last month can transact from inside Iran today.
×  Where network infrastructure is registered. 620 km average disagreement between databases on the same IP.
 Where the device physically is, right now. Hardware-signed. Sub-km.
VPN resilience
×  No location check. KYC verifies identity, not position.
×  A $5/month VPN defeats the geofence. Block VPNs, lose real users. Allow them, lose the control.
 Users keep their VPN. Location proved from device sensors, not the network.
Per-transaction enforcement
×  One-time check at onboarding. No enforcement after. User moves to a sanctioned country the next day.
×  Checked at login. No enforcement on secondary trades.
 Fresh proof at every transaction. Independently verifiable.
Sanctioned locations
×  Does not solve for jurisdiction. Permitted passport, sanctioned country: KYC passes.
×  620 km error at borders. 68.3M people resolve to the wrong country without a VPN.
 Cryptographic proof of physical location. Sub-km at borders.
Sanctioned individuals
 Screens against OFAC SDN list. Required and effective for sanctioned persons.
×  An IP address cannot identify a person.
~  Proves location, not identity. KYC still needed for sanctioned-person screening.
User friction
×  Document upload, selfie, manual review. Minutes to days. High drop-off.
~  Invisible, but unreliable. No friction because no real check is performed.
 Runs in background. No prompt, no permissions. Zero friction.
Data liability
×  Platform holds passports, IDs, addresses. Every KYC breach exposes millions.
×  Logs IP addresses.
 Boolean only. No coordinates leave the device. Nothing to breach.

Where jurisdiction matters and IP addresses fail.

State-level

Prediction markets & sports betting

Sub-km proof of permitted-state presence before every wager. Invisible to the user. VPN-proof.

OFAC / Sanctions

Sanctions compliance

From database-level guessing to cryptographic certainty. Resilient to VPNs, CGNAT, Starlink, border proximity.

Reg S / Ex-US

Digital asset trading platforms

Proof of jurisdiction at every transaction. Ex-US without KYC. Flow-back prevention on secondary trades.


Get started

Talk to the founders

Schedule a conversation
Read the research brief →

SOURCES

Full methodology and 14 additional references at IP Address Cannot Prove Where Someone Is

  1. ESPN · 20+ lawsuits contesting CFTC preemption vs state regulation of prediction markets (Mar 2026)
  2. Apple iCloud Private Relay Overview (Dec 2021) · Geohash architecture, country/time zone vs. general location distinction. iCloud Private Relay is bundled with every paid iCloud subscription; a user base that numbers in the hundreds of millions. It does not require separate sign-up; any iPhone running a current OS with a paid iCloud plan can enable it in four taps.
  3. Flynn, Bronzino & Schmitt, arXiv:2307.04009 (Jul 2023) · 1,000-mile median geolocation error for Private Relay IPv4 users; 800 km² geohash truncation area
  4. MaxMind support documentation · 67% confidence that the location of the end-user falls within the area defined by the accuracy radius; 100 km as stated example of normal error.
  5. GeoComply geolocation data via GeoComply and Sports Illustrated · 44% of NJ sports bets within 2 mi of state line
  6. Nur et al., IEEE BalkanCom 2023 · 620km average disagreement between geolocation databases (6.3M IPs tested)
  7. Border population data (68.3M / 150.1M within 100km / 200km of non-sanctioned borders) · UN DESA 2024 population estimates, geographic distance calculations. Full methodology at ip.octetproof.com
  8. CoinDesk / Sensor Tower (Nov 2024) · Bybit (451,800), Bitget (281,600), OKX (144,000): ~877K US MAUs despite all three geofencing the US. App-only measurement undercounts web/VPN access.
  9. Binance / OFAC settlement (Nov 2023) · OFAC found Binance relied on US users for substantial volume, actively encouraged VPN use to circumvent its own geofence. $968M settlement. Post-crackdown residual US access estimated at 500K–1M given 280M global user base.
  10. Hyperliquid traffic (2025) · Similarweb shows 17.3% of Hyperliquid web traffic from US, its largest single-country share, despite explicit US prohibition. ~570K total users implies ~100K US users on one no-KYC perp DEX alone.