Appearance
Geofencing
Control where your AI requests can originate from and which AI providers can be used based on geographic location.
Overview
Geofencing in VeriPrompt provides two layers of geographic access control:
- Client IP Security: Block or allow requests based on where the API call originates (cybersecurity feature)
- Provider Geofencing: Route requests only to AI providers in approved geographic regions (routing policy feature)
Typical Use Cases
- Regulatory Compliance: Ensure data stays within specific jurisdictions (GDPR, data residency)
- Security Policies: Block requests from high-risk countries
- Enterprise Requirements: Restrict AI usage to approved regions only
- Data Sovereignty: Keep sensitive prompts within national borders
- CDN-Aware Routing: Handle AI providers that use CDNs like Cloudflare correctly
How It Works
Client IP Geofencing
When a request arrives at the gateway:
- The client's IP address is extracted from request headers
- IP is looked up to determine the country (cached for performance)
- Country is checked against project/prompt geofencing rules
- Request is blocked if the client location violates the policy
Provider Country Filtering
When selecting AI providers:
- Each provider has a configured
locationCountry - Your geo rules define which countries are allowed or denied
- Providers in denied countries are filtered out
- Only providers in allowed regions receive your prompts
Configuration
Setting Geo Rules on a Project
Geo rules can be set at the project level and optionally overridden per prompt:
json
{
"geoFenceRules": {
"allow": {
"countries": ["US", "CA", "GB", "DE", "FR"],
"memberships": ["EU", "NATO"]
},
"deny": {
"countries": ["CN", "RU", "KP"]
},
"proxyBehavior": "IGNORE_PROXY"
}
}Rule Evaluation
- Deny rules take precedence: If a country is in both allow and deny, it's denied
- Empty allow list: All countries are allowed (except those in deny list)
- Empty deny list: No countries are blocked (only allow list applies)
- Both specified: Must be in allow list AND not in deny list
- Membership expansion: Keywords like "EU" expand to all member country codes
CDN/Proxy Handling
Many AI providers use Content Delivery Networks (CDNs) like Cloudflare, Fastly, or Akamai to improve performance and security. This can cause issues with geofencing because:
- An EU-based AI provider using Cloudflare might have their API endpoint resolve to a US IP address
- A routing policy requiring "EU only" would incorrectly block this legitimate EU provider
The Problem
Your Routing Policy: allow: { memberships: ["EU"] }
AI Provider:
- Registered Location: Germany (DE)
- Uses Cloudflare CDN
- Resolved IP: 104.16.x.x (Cloudflare, US)
Result WITHOUT proxy handling: ❌ BLOCKED (IP shows US)
Result WITH proxy handling: ✅ ALLOWED (uses registered DE location)Proxy Behavior Options
VeriPrompt supports three proxy behavior modes in your routing policy:
| Mode | Description | Use Case |
|---|---|---|
IGNORE_PROXY | Default. Use the provider's registered location from the catalog, ignoring CDN/proxy IP detection. | Recommended for most users. Prevents false positives when legitimate providers use CDNs. |
RESPECT_PROXY | Use the resolved IP's geolocation even if behind a CDN. | Strict compliance where you need to know the actual network path. May cause false positives. |
BLOCK_PROXY | Block any provider detected as using a CDN/proxy. | Maximum security when you require direct connections only. |
Configuration Examples
Default Behavior (Recommended)
json
{
"geoFenceRules": {
"allow": {
"memberships": ["EU"]
},
"proxyBehavior": "IGNORE_PROXY"
}
}This allows any provider registered in an EU country, even if their API endpoint resolves to a CDN IP in a different location.
Strict Mode (Use IP Location)
json
{
"geoFenceRules": {
"allow": {
"countries": ["US", "CA"]
},
"proxyBehavior": "RESPECT_PROXY"
}
}This requires the resolved IP address to be in US or Canada, regardless of where the provider is registered.
Block CDN/Proxy (Direct Connections Only)
json
{
"geoFenceRules": {
"allow": {
"countries": ["DE"]
},
"proxyBehavior": "BLOCK_PROXY"
}
}This blocks any provider using a CDN or proxy, only allowing direct connections.
Detected CDN Providers
VeriPrompt automatically detects the following CDN/proxy services:
| Provider | Detection Method |
|---|---|
| Cloudflare | ISP name, ASN 13335 |
| Fastly | ISP name, ASN 54113 |
| Akamai | ISP name, ASN 16625/20940 |
| AWS CloudFront | ISP name, ASN 16509/14618 |
| Google Cloud CDN | ISP name, ASN 15169/396982 |
| Microsoft Azure CDN | ISP name, ASN 8075/8068 |
| Bunny CDN | ISP name, ASN 206856 |
| StackPath/MaxCDN | ISP name, ASN 33438/20446 |
| Imperva (Incapsula) | ISP name, ASN 19551 |
Response Details
When a provider is evaluated, the response includes proxy detection information:
json
{
"allowed": true,
"proxyDetected": true,
"cdnProvider": "Cloudflare",
"usedRegisteredLocation": true
}| Field | Description |
|---|---|
proxyDetected | Whether a CDN/proxy was detected |
cdnProvider | Name of the detected CDN (if any) |
usedRegisteredLocation | True if the registered location was used instead of IP location |
Example Configurations
EU Only (GDPR Compliance)
json
{
"allow": {
"countries": ["AT", "BE", "BG", "HR", "CY", "CZ", "DK", "EE", "FI", "FR",
"DE", "GR", "HU", "IE", "IT", "LV", "LT", "LU", "MT", "NL",
"PL", "PT", "RO", "SK", "SI", "ES", "SE"]
}
}Block High-Risk Countries
json
{
"deny": {
"countries": ["CN", "RU", "IR", "KP", "SY"]
}
}North America Only
json
{
"allow": {
"countries": ["US", "CA", "MX"]
}
}Error Responses
When a request is blocked by geofencing, you'll receive a 403 response:
json
{
"error": "Request blocked by geofencing policy",
"code": "CLIENT_LOCATION_DENIED",
"details": {
"clientCountry": "CN",
"clientCity": "Beijing",
"ruleSource": "PROJECT",
"message": "Requests from China are not allowed by the configured geofencing policy."
}
}Error Codes
| Code | Description |
|---|---|
CLIENT_LOCATION_DENIED | Client's IP is in a denied country |
CLIENT_LOCATION_NOT_ALLOWED | Client's IP is not in the allow list |
ALL_PROVIDERS_BLOCKED | All providers filtered out by geo rules |
Internal Service Compliance
Geofencing rules are not limited to the gateway API — they are also enforced for internal platform services (Guru, Prompt Optimizer, Architect, MCP Executor) that call AI providers on your behalf.
If your company has a default routing policy with geo.enforce: true, every provider resolved by internal services is checked against those geo rules before any request is sent. If the provider's locationCountry is not compliant, the service returns a policy violation error instead of routing your data to a non-compliant region.
Strict Location Requirement
When geo enforcement is active, providers must have a registered locationCountry. If a provider's location is unknown (NULL), the request is blocked with a "cannot verify geo compliance" error to prevent accidental data leakage to unknown jurisdictions.
Example: EU-Only Policy Blocking DeepSeek
Company policy: geo.enforce = true, geo.allow = ["EU countries"]
Service: Prompt Optimizer → configured to use deepseek/deepseek-chat
Provider location: CN (China)
Result: ❌ BLOCKED
Error: [Policy Violation] "prompt-optimizer" cannot use provider
deepseek/deepseek-chat: Provider country CN is denied.Resolution: Add a compliant provider via BYOK (Settings → Credentials) or change the service's provider assignment (Admin → Service Config).
Best Practices
- Start Permissive: Begin with deny lists for known high-risk countries rather than restrictive allow lists
- Test Thoroughly: Use VPN testing to verify rules work as expected
- Monitor Blocks: Review audit logs for blocked requests to catch misconfigurations
- Document Policies: Communicate geo restrictions to your development teams
- Consider Time Zones: Remember that developers traveling may be affected
Logging and Monitoring
All geofencing decisions are logged including:
- Client IP address
- Detected country
- Which rule blocked the request
- Timestamp and request metadata
Access these logs in your monitoring dashboard or via the API.
Learn More
- Gateway Execute API - API reference with geo error codes
- Compliance Tools - Other compliance features
- Intelligent Routing - How provider selection works
