Skip to content

Geofencing ​

Control where your AI requests can originate from and which AI providers can be used based on geographic location.

Overview ​

Geofencing in VeriPrompt provides two layers of geographic access control:

  1. Client IP Security: Block or allow requests based on where the API call originates (cybersecurity feature)
  2. Provider Geofencing: Route requests only to AI providers in approved geographic regions (routing policy feature)

Typical Use Cases ​

  • Regulatory Compliance: Ensure data stays within specific jurisdictions (GDPR, data residency)
  • Security Policies: Block requests from high-risk countries
  • Enterprise Requirements: Restrict AI usage to approved regions only
  • Data Sovereignty: Keep sensitive prompts within national borders
  • CDN-Aware Routing: Handle AI providers that use CDNs like Cloudflare correctly

How It Works ​

Client IP Geofencing ​

When a request arrives at the gateway:

  1. The client's IP address is extracted from request headers
  2. IP is looked up to determine the country (cached for performance)
  3. Country is checked against project/prompt geofencing rules
  4. Request is blocked if the client location violates the policy

Provider Country Filtering ​

When selecting AI providers:

  1. Each provider has a configured locationCountry
  2. Your geo rules define which countries are allowed or denied
  3. Providers in denied countries are filtered out
  4. Only providers in allowed regions receive your prompts

Configuration ​

Setting Geo Rules on a Project ​

Geo rules can be set at the project level and optionally overridden per prompt:

json
{
  "geoFenceRules": {
    "allow": {
      "countries": ["US", "CA", "GB", "DE", "FR"],
      "memberships": ["EU", "NATO"]
    },
    "deny": {
      "countries": ["CN", "RU", "KP"]
    },
    "proxyBehavior": "IGNORE_PROXY"
  }
}

Rule Evaluation ​

  • Deny rules take precedence: If a country is in both allow and deny, it's denied
  • Empty allow list: All countries are allowed (except those in deny list)
  • Empty deny list: No countries are blocked (only allow list applies)
  • Both specified: Must be in allow list AND not in deny list
  • Membership expansion: Keywords like "EU" expand to all member country codes

CDN/Proxy Handling ​

Many AI providers use Content Delivery Networks (CDNs) like Cloudflare, Fastly, or Akamai to improve performance and security. This can cause issues with geofencing because:

  • An EU-based AI provider using Cloudflare might have their API endpoint resolve to a US IP address
  • A routing policy requiring "EU only" would incorrectly block this legitimate EU provider

The Problem ​

Your Routing Policy: allow: { memberships: ["EU"] }

AI Provider:
  - Registered Location: Germany (DE)
  - Uses Cloudflare CDN
  - Resolved IP: 104.16.x.x (Cloudflare, US)

Result WITHOUT proxy handling: ❌ BLOCKED (IP shows US)
Result WITH proxy handling:    ✅ ALLOWED (uses registered DE location)

Proxy Behavior Options ​

VeriPrompt supports three proxy behavior modes in your routing policy:

ModeDescriptionUse Case
IGNORE_PROXYDefault. Use the provider's registered location from the catalog, ignoring CDN/proxy IP detection.Recommended for most users. Prevents false positives when legitimate providers use CDNs.
RESPECT_PROXYUse the resolved IP's geolocation even if behind a CDN.Strict compliance where you need to know the actual network path. May cause false positives.
BLOCK_PROXYBlock any provider detected as using a CDN/proxy.Maximum security when you require direct connections only.

Configuration Examples ​

json
{
  "geoFenceRules": {
    "allow": {
      "memberships": ["EU"]
    },
    "proxyBehavior": "IGNORE_PROXY"
  }
}

This allows any provider registered in an EU country, even if their API endpoint resolves to a CDN IP in a different location.

Strict Mode (Use IP Location) ​

json
{
  "geoFenceRules": {
    "allow": {
      "countries": ["US", "CA"]
    },
    "proxyBehavior": "RESPECT_PROXY"
  }
}

This requires the resolved IP address to be in US or Canada, regardless of where the provider is registered.

Block CDN/Proxy (Direct Connections Only) ​

json
{
  "geoFenceRules": {
    "allow": {
      "countries": ["DE"]
    },
    "proxyBehavior": "BLOCK_PROXY"
  }
}

This blocks any provider using a CDN or proxy, only allowing direct connections.

Detected CDN Providers ​

VeriPrompt automatically detects the following CDN/proxy services:

ProviderDetection Method
CloudflareISP name, ASN 13335
FastlyISP name, ASN 54113
AkamaiISP name, ASN 16625/20940
AWS CloudFrontISP name, ASN 16509/14618
Google Cloud CDNISP name, ASN 15169/396982
Microsoft Azure CDNISP name, ASN 8075/8068
Bunny CDNISP name, ASN 206856
StackPath/MaxCDNISP name, ASN 33438/20446
Imperva (Incapsula)ISP name, ASN 19551

Response Details ​

When a provider is evaluated, the response includes proxy detection information:

json
{
  "allowed": true,
  "proxyDetected": true,
  "cdnProvider": "Cloudflare",
  "usedRegisteredLocation": true
}
FieldDescription
proxyDetectedWhether a CDN/proxy was detected
cdnProviderName of the detected CDN (if any)
usedRegisteredLocationTrue if the registered location was used instead of IP location

Example Configurations ​

EU Only (GDPR Compliance) ​

json
{
  "allow": {
    "countries": ["AT", "BE", "BG", "HR", "CY", "CZ", "DK", "EE", "FI", "FR",
                  "DE", "GR", "HU", "IE", "IT", "LV", "LT", "LU", "MT", "NL",
                  "PL", "PT", "RO", "SK", "SI", "ES", "SE"]
  }
}

Block High-Risk Countries ​

json
{
  "deny": {
    "countries": ["CN", "RU", "IR", "KP", "SY"]
  }
}

North America Only ​

json
{
  "allow": {
    "countries": ["US", "CA", "MX"]
  }
}

Error Responses ​

When a request is blocked by geofencing, you'll receive a 403 response:

json
{
  "error": "Request blocked by geofencing policy",
  "code": "CLIENT_LOCATION_DENIED",
  "details": {
    "clientCountry": "CN",
    "clientCity": "Beijing",
    "ruleSource": "PROJECT",
    "message": "Requests from China are not allowed by the configured geofencing policy."
  }
}

Error Codes ​

CodeDescription
CLIENT_LOCATION_DENIEDClient's IP is in a denied country
CLIENT_LOCATION_NOT_ALLOWEDClient's IP is not in the allow list
ALL_PROVIDERS_BLOCKEDAll providers filtered out by geo rules

Internal Service Compliance ​

Geofencing rules are not limited to the gateway API — they are also enforced for internal platform services (Guru, Prompt Optimizer, Architect, MCP Executor) that call AI providers on your behalf.

If your company has a default routing policy with geo.enforce: true, every provider resolved by internal services is checked against those geo rules before any request is sent. If the provider's locationCountry is not compliant, the service returns a policy violation error instead of routing your data to a non-compliant region.

Strict Location Requirement ​

When geo enforcement is active, providers must have a registered locationCountry. If a provider's location is unknown (NULL), the request is blocked with a "cannot verify geo compliance" error to prevent accidental data leakage to unknown jurisdictions.

Example: EU-Only Policy Blocking DeepSeek ​

Company policy: geo.enforce = true, geo.allow = ["EU countries"]
Service: Prompt Optimizer → configured to use deepseek/deepseek-chat
Provider location: CN (China)

Result: ❌ BLOCKED
Error: [Policy Violation] "prompt-optimizer" cannot use provider
       deepseek/deepseek-chat: Provider country CN is denied.

Resolution: Add a compliant provider via BYOK (Settings → Credentials) or change the service's provider assignment (Admin → Service Config).

Best Practices ​

  1. Start Permissive: Begin with deny lists for known high-risk countries rather than restrictive allow lists
  2. Test Thoroughly: Use VPN testing to verify rules work as expected
  3. Monitor Blocks: Review audit logs for blocked requests to catch misconfigurations
  4. Document Policies: Communicate geo restrictions to your development teams
  5. Consider Time Zones: Remember that developers traveling may be affected

Logging and Monitoring ​

All geofencing decisions are logged including:

  • Client IP address
  • Detected country
  • Which rule blocked the request
  • Timestamp and request metadata

Access these logs in your monitoring dashboard or via the API.

Learn More ​