Geolocation compliance for DFS, sweepstakes and social gaming

Know where every entry comes from. Block the ones you shouldn't take.

BoundsCheck decides, in about 10 milliseconds, whether a player is inside a jurisdiction where your contest is allowed. Every decision is logged with its reasons, so you can show your work later.

Built by operators, for operators. It runs on our own daily fantasy platform before it runs on yours.

POST /v1/check9 ms
decision   ALLOW
region     US-TX · Travis County
activity   contest_entry · paid
policy     v2026.10.02
signals    gps ✓  accuracy 25 m  mocked ✗  vpn ✗
check_id   chk_7f3a…e91c
What it does

One API call before money moves.

Your app sends a device location with each paid entry, deposit or withdrawal. BoundsCheck checks it against current boundaries and your policy, returns allow or block with the reasons, and writes an audit row. You keep control of your UI, your players and your data.

01

Blocks by default

No fix, a stale fix, a mocked fix, or a location we can't resolve all return BLOCK. If the service is unreachable, your side fails closed. We never guess a player in.

02

Rules per state, per county, per format

Allow pick'em in one state and salary-cap only in another. Carve out a county. Set a minimum age that differs by state. Policy changes are versioned and take effect without an app release.

03

Fast enough to sit in the request path

Decisions return in roughly 10 ms from our side. Your eligible-states list is served with ETags so the client only re-downloads it when policy changes.

04

Monitor first, enforce when ready

Run in monitor mode to see what would have been blocked before you refuse anyone. Flip one setting to enforce. Flip it again to turn gating off in an emergency.

How it works

Four parts, one decision.

Each check runs through the same pipeline. Every stage records what it saw, so the audit row explains the decision rather than just stating it.

1
Device fix
Your client sends lat/lng, accuracy, timestamp, timezone, platform and mock flag.
2
Boundaries
The fix is resolved to a state and county using Census-grade polygons.
3
Fraud signals
Mock-provider, VPN and proxy indicators, IP-vs-GPS distance, accuracy and staleness.
4
Policy engine
Your versioned rules for that state, county, activity and contest format are applied.
5
Decision + audit
Allow or block, the reasons, and a check ID you store on the entry.

Boundaries

State and county polygons from U.S. Census TIGER data, not a radius around a city centroid. Border towns and county carve-outs resolve the way a regulator would draw them.

  • Point-in-polygon at state and county level
  • Accuracy radius considered: a fix that straddles a border is treated as unresolved
  • Boundary data refreshed on a schedule, with the version recorded on each check

Policy engine

Policy is a set of rules keyed on jurisdiction, activity and contest format. You edit it in a panel; we version it and record who changed what.

  • Activities: contest entry, deposit, withdrawal, or your own
  • Formats: pick'em, salary cap, head-to-head, and any you define
  • State minimum age, enforced against the resolved state
  • Eligible-states endpoint for your app's onboarding screens

Fraud signals

Location spoofing is cheap. We look for the common tells and treat an untrusted fix as no fix at all.

  • Mock-location providers and developer-mode flags
  • VPN, proxy and hosting-range detection on the request IP
  • IP geolocation compared against the GPS fix
  • Stale timestamps and timezone mismatches

Audit trail

Every check is stored with its inputs, the signals observed, the policy version applied and the result. Nothing is sampled.

  • Check ID returned on every call to store with the transaction
  • Searchable log of decisions and reasons
  • Change log for every policy edit, signed by the admin who made it
  • Export for a payment processor or regulator request
Who it's for

Operators who need real state-by-state blocking without an enterprise contract.

If you run paid contests across many states, you already know the map changes. BoundsCheck is for the teams who have been maintaining a hand-edited list of state codes and want something they can defend.

  • Daily fantasy sportsPick'em and salary-cap operators who need format-level rules and a clean record for each paid entry.
  • Sweepstakes and social casinoPromotional-sweepstakes models where a handful of states and counties must be excluded and proven excluded.
  • Free-to-play and prediction contestsProducts that are free today and want the gating in place before a paid tier launches.
  • Platforms and white-labelsOne policy engine serving several brands, each with its own rule set and audit log.

What you get

A REST API with two endpoints, a small client script for web, a reference implementation for iOS and Android, and an admin panel you can embed in your own back office. Flat monthly pricing by active players, with unlimited checks. No per-ping charges.

How we work with you

We're a small team and we integrate with you directly. Expect a shared channel, a monitor-mode period reviewing real traffic together, and a go-live plan for web first and mobile once your new build has adoption.

What BoundsCheck is not

BoundsCheck has not been tested by an independent gaming laboratory and is not licensed as a geolocation vendor in any regulated sports-betting or iGaming market. If you hold or are seeking a sportsbook or online casino license, your regulator will expect a vendor that has been through that process, and we are not yet that vendor.

We're clear about this because our customers need to be clear about it with their own counsel. BoundsCheck is built for contests and promotions where the operator sets the compliance standard and must be able to show it was met.

Contact

Tell us what you're running.

There's no self-serve signup yet. Send a note and we'll set up a walkthrough, share the API reference, and talk through how monitor mode would look on your traffic.

This opens a draft in your email client addressed to us. Nothing is sent until you hit send there.

Thanks. If your email client didn't open, write to us directly at our contact address.

Direct

Email [contact email]. We reply within one business day.

Good to know before we talk

  • Integration effortWeb is a script include and two middleware lines. Mobile needs the location permission and a small payload on your paid-entry calls, which means an app-store release.
  • Data handlingWe store device fixes and decisions for the audit trail. We don't sell or share location data, and you can set your own retention window.
  • PricingFlat monthly fee based on monthly active players, unlimited checks. We'll quote once we understand your volume.