Compliance tech

How geolocation compliance works in regulated US iGaming

Smartphone displaying a navigation map inside a car
A phone running a location app. Regulated iGaming apps must verify a player's location before each wager. Photo: Tima Miroshnichenko / Pexels

The short answer

Regulated iGaming requires the operator to prove the player is physically inside the state before accepting a wager — verified on each transaction, not once at signup. Vendors like GeoComply fuse GPS, Wi-Fi, GSM/cell signals and IP data, screen for VPNs, emulators and remote-desktop tools, and deliberately err toward false rejections near borders, because letting one out-of-state bet through is a compliance failure while blocking a legal player is a support ticket.

In this article

A legal US iGaming app is not a website with a state picker — it is a wagering system that must certify your physical location, inside state lines, on every bet. That requirement, written into state regulations, created an entire vendor category: compliance-grade geolocation. GeoComply — the dominant supplier — describes its product as collecting GPS, Wi-Fi, GSM and IP signals and running hundreds of checks per transaction.

What the check actually does

  • Signal fusion: no single source is trusted. GPS can be spoofed, IPs can be VPN'd, so the system cross-references GPS, nearby Wi-Fi networks, cell-tower data and IP geolocation for a consistent picture.
  • Anti-spoofing screening: the check looks for VPNs, proxies, emulators, mock-location APIs, remote-desktop tools and jailbroken devices — the toolbox of anyone trying to fake a state border.
  • Per-transaction verification: location is re-verified continuously, not cached from login — a phone that crosses into a neighboring state mid-session stops wagering where the law stops.
  • Buffer-zone conservatism: regulators build border buffers into requirements, so a phone near the line may be rejected even when it is legally inside — vendors describe this as an intentional bias toward false negatives.

Where the requirement comes from

State gaming regulations — not federal law — impose the in-state wagering requirement, and each regulator writes its own rules. New Jersey's regulations (N.J.A.C. 13:69O) are the canonical example: internet gaming is lawful only for wagers placed by persons physically located in the state. Because the obligation attaches to the wager, operators route every bet through a certified geolocation check — and because license liability is on the operator, the system is tuned to reject borderline readings rather than risk a violation.

Geolocation is also what makes cross-state poker liquidity and the seven-state online casino map enforceable — every state boundary on those maps is ultimately drawn by this check, on every bet. For the integrity layer above it, see what a gaming lab certificate covers.

Sources