Just ask the GeoComply MCP V2 Skip to content
GeoComply MCP
Claude ChatGPT Slack Microsoft Copilot Google Gemini

AI-assisted fraud & geo-compliance investigations

A day’s worth of investigations, answered in minutes.

Connect your AI tools to the GeoComply signals already firing in your stack, and your team investigates with the reach of a whole data team behind them. Then, just ask. Get a verdict, the evidence behind it, and the method that got there.

Map the network around this device, two hops deep.

GeoComply

One ring, not two clusters.

Network mapped

8 accounts across 2 devices. USER-1 bridges both, which is what joins them into a single network.

Shared-device ringReal structure, identifiers masked
device account bridge link DEVICE-A 6 accounts DEVICE-B 3 accounts USER-1 1,847 checks USER-2 612 checks USER-3 288 checks USER-4 934 checks USER-5 156 checks USER-6 73 checks USER-7 2,104 checks USER-8 441 checks
8 accounts 2 devices USER-1 bridges both

Investigate device 20003 over the last 90 days. Is it shared, and is it blocked?

GeoComply

Critical risk, high confidence.

Blocked

The device is blocked, shared across 6 accounts, and all 165 checks in the window failed.

Device risk scorecardDEVICE-A · last 90 days
0.80 risk score CRITICAL RISK Confidence: high Device blocked · shared with 6 accounts · 100% of checks failed WHAT DROVE THE SCORE Device currently blocked source: block status +0.35 Shared with 6 accounts (multi-account pattern) source: device network +0.30 100% failure rate, 165 of 165 checks source: transactions +0.15
critical 0.80 6 linked accounts 100% fail blocked

Here are 9 flagged accounts. Check each for device sharing and flag anything blocked.

GeoComply

All 9 came back in one pass.

2 surfaced

Six share a single blocked device, and two accounts you did not submit were pulled in because they share a device with the set. The ring is bigger than your list.

Bulk device-sharing sweepActive within the last 365 days
SUBMITTED 9 IN THE NETWORK 11 SURFACED, NOT ASKED +2 ON 1 BLOCKED DEVICE 6 6 accounts share one device, and that device is blocked 2113 · 2116 · 2117 · 2118 · 2119 · 2120 → frauddevice20003 (blocked) 2 more accounts pulled in, one hop out 2111 and 2112 share a device with the submitted set. The ring is bigger than the list.
9 checked at once 6 on 1 blocked device +2 surfaced

What can you ask it?

From one question to a decision you can defend.

Close a case with one question.

tools: investigate_device, investigate_user, multi_level_search

Investigate this user over the last 90 days.

GeoComply

High risk, high confidence. The account isn't blocked itself, but its device is shared with 7 others and one device in its history is already blocked. Every one of its 30 checks failed.

User verdict scorecard USER-B, last 90 days. Account not blocked, the evidence around it is. 0.65 risk score HIGH RISK Confidence: high Account not blocked · device shared x7 · 100% of checks failed DEVICE SHARED WITH 7 accounts BLOCKED IN HISTORY 1 device CHECKS FAILED 30 of 30 [VERIFY] Rebuilt from the copy above — source scorecard SVG was not supplied with the set.
  • high 0.65
  • device shared x7
  • 1 blocked device
  • 30 of 30 failed

Are these accounts one ring, or a coincidence?

GeoComply

Three separate devices, each on its own account, all three currently blocked. No shared device between them in 90 days, so this reads as three flagged accounts, not one ring.

  • 3 devices
  • 3 blocked
  • no shared device

Pull the numbers without opening a dashboard.

tools: compliance_pass_rates, compliance_error_breakdown

Show me pass rates by region for the last 90 days.

GeoComply

55,090 checks. Pennsylvania passes at 96% on 54K checks. Four regions sit below 95% and are flagged.

Pass rate by region, last 90 days TOTAL CHECKS 55,090 OVERALL PASS 94.7% FLAGGED BELOW 95% 4 regions Pennsylvania 96.0% 54,329 checks Ohio 0.8% 248 checks New York 0.0% 261 checks California 0.0% 192 checks Quebec 0.0% 60 checks
  • 94.7% overall
  • 4 flagged
  • by region

Break down why checks failed this quarter.

GeoComply

3,919 failures. Device integrity leads at 26%, then out-of-boundary and missing location data. Ordered by how often each fired.

Why checks failed, last 90 days 3,919 failures. Device integrity leads at 26%. Device integrity 1,026 Outside boundary 702 No location data 560 Close to border 329 Blocked software 291 Proxy / VPN 290 In exclusion zone 250 Android loc invalid 192 Mocked location 94
  • 3,919 failures
  • device integrity 26%
  • ranked

Answer "why did this fail" without raising a ticket.

tools: diagnose_failed_rules, search_client_docs, get_playbook

Why did this check fail? It fired proxy, boundary, and mocked location.

GeoComply

Three rules fired, all user-fixable, none need escalation. Each comes back with the cause and the exact fix.

Why did this check fail? Three rules fired. All user-fixable, none need escalation. Proxy server software Fix: Disable any VPN, proxy, or SmartDNS, or switch networks. RETRY NO ESC Outside state border boundary Fix: Confirm physical presence inside the licensed state. RETRY NO ESC Simulated location (iOS) software Fix: Close and uninstall the location-spoofing tool, then retry. RETRY NO ESC
  • 3 rules
  • all user-fixable
  • no escalation

A customer is stuck at verification. What happened on their identity checks?

GeoComply

Four checks ran. Document, identity proofing, and knowledge-based questions all passed. The credit-file step returned no match, and that is where it stopped. That is the step to action.

Identity verification history USER-C. Four checks ran. Three passed, one stopped, that's the one to action. Stopped at: credit-file check. No ticket needed, the answer is here. Document verification ID document read and validated PASSED Identity proofing Name, DOB, and address matched PASSED Knowledge-based questions Security questions answered correctly PASSED Credit-file check No matching credit record found STOPPED Check types are real (document, identity proofing, KBA, credit file). Results representative until confirmed against a live pull.
  • 3 of 4 passed
  • stopped at credit file
  • no ticket

Not every question is a fraud question.

tools: edge_market_data_overview, stadium_insights_games, edge_poi_coordinates

How does game day change activity across our venues?

GeoComply

A big jump from preseason to regular season: checks per game rose about 8x, active accounts about 5x, new accounts about 7x. Top venues by game-day checks below.

Game-day activity around venues Preseason to regular season, last month. Venue names masked. CHECKS / GAME 6.5K → 52K ~8x jump ACTIVE ACCOUNTS / GAME 1.4K → 6.7K ~4.9x jump NEW ACCOUNTS / GAME 24 → 163 ~6.8x jump TOP VENUES BY GAME-DAY CHECKS (regular season) Venue A (PA) 102,558Venue B (MI) 93,512Venue C (OH) 74,414Venue D (NJ) 74,024Venue E (NC) 38,584 Measured kickoff -2h to +4h. Single-client venues excluded. Real Edge data, names masked. Source: GeoComply Edge, stadium insights, Aug 18 to Sep 18 2026.
  • ~8x checks
  • ~5x active accounts
  • game day

Ready to see one of these run on a case?

Book a demo

What teams are asking

Every desk gets an answer.

Analysts, support reps, and leadership just ask.

  • Investigate this user and show me everything connected to them.
  • Is this device on a VPN, or is the location actually being spoofed?
  • Has this device been blocked before, and why?
  • Give me a daily fraud briefing.
  • What are the top failure reasons our users hit in the last two weeks?
  • Pass rates by operator for the last 7 days.
  • Why did this check fail?
  • What does this error code mean?
  • Show me every account that touched this device in the last 60 days.
  • Which users were active inside this geohash last month?
  • Map the network around this device, two hops deep.
  • Here are 50 usernames. Check each for device sharing and flag anything blocked.
  • What happened on this customer's identity checks?
  • How many checks landed inside our exclusion zones last week?
  • Compare these two users. Do they share anything?
  • Which playbooks do I have access to?
  • Break down our compliance failures for this month.
  • Summarize this investigation into a report I can hand off.
  • Walk me through an account takeover investigation on this user.
  • Pull the full transaction profile for this transaction ID.
  • Investigate this user and show me everything connected to them.
  • Why did this check fail?

What does one connection reach?

Fewer places to look, not more things to check.

36 tools on one connection, grouped by how an investigation actually runs. Playbooks map to how your team already investigates.

Is AI fraud investigation explainable?

The decision always stays yours.

What your analyst can defend

  • Signals in, decisions yours

    The MCP reports state, it does not change it.

  • Same baseline every time

    The same scoring runs every time.

  • Shows its working and its limits

    Each verdict arrives with the signals behind it.

What stays separate

  • Your own credentials, enforced twice

    Every call is signed with your organization's own credential.

  • Permissions you already set

    Analysts inherit the grant they already hold, through single sign-on.

  • Nothing new without your sign-off

    Per-organization tool allowlists cap the set any caller can reach.

FAQ

  • The GeoComply MCP is a remote server that connects an AI assistant to your GeoComply location, device, and identity data, so your team can run fraud and compliance investigations by asking in plain language. MCP, or Model Context Protocol, is an open standard from Anthropic that lets an assistant use an outside system as a tool. Ask a question, and the investigation comes back assembled: linked accounts, failed checks, and a scored verdict with the evidence behind it.

  • Claude, ChatGPT, Copilot, and other AI assistants your team already uses. It is built on an open standard, so any assistant that speaks MCP can connect, and your own agent can reach the same endpoint machine to machine. Bring the AI you already have.

  • Yes, and it is enforced in two places, not one. Every call is scoped to the operators your organization is entitled to, and the platform underneath enforces that scope again using your organization's own credential. An organization without a credential record gets nothing rather than borrowing another organization's access.

  • Every call is attributed to the analyst or agent that made it, and an agent's activity is distinguishable from a person's. Requests are scoped to your existing permissions on the way in, so the record shows who asked, what they asked, and which operators they were entitled to see.

  • No. The verdicts and the spoofing analysis come from GeoComply's own models, not the assistant's reasoning. The assistant calls a tool and returns what came back, with the evidence attached, and it says when a verdict is resting on thin evidence rather than filling the gap.

  • Neither. It reads and reports, it does not act. A verdict is evidence for your analyst, and case actions still happen wherever you manage cases today.

  • Location, device, and behavioural signals, the account's own check history, and the accounts and devices connected to it. No single input decides a verdict on its own, and a low-risk result means nothing was found in what was examined, which is not the same as nothing being there.

  • Point your agent at the endpoint and it authenticates as itself, machine to machine. It can also run as a named analyst, scoped to that person's own permissions rather than your organization's full reach. Either way the call is scoped and attributed the same way an analyst session is.

  • Minutes on your side, once we have provisioned your organization. Your org admin adds the connector in your AI platform and signs in once with single sign-on, with no software to deploy. Moving your own data between platform providers, if that is part of your setup, is separate work and usually the longer part.

  • The API gives you the data. What the MCP adds is the scored verdicts, the investigation methods that assemble a case, and the permission and audit layer already enforced on every request. You would be rebuilding the interpretation and the governance, not just the access.

  • Start narrow. Two of the three connection paths exist for this: a scheduled machine-to-machine job with no user-facing surface, or the named-analyst mode where each person's own permissions apply. Use of AI features is covered by GeoComply's published AI Features Addendum, so for most operators this is a pointer to existing terms, not a new contract.