AI-assisted fraud & geo-compliance investigations
A day’s worth of investigations, answered in minutes.
Connect your AI tools to the GeoComply signals already firing in your stack, and your team investigates with the reach of a whole data team behind them. Then, just ask. Get a verdict, the evidence behind it, and the method that got there.
Map the network around this device, two hops deep.
One ring, not two clusters.
Network mapped8 accounts across 2 devices. USER-1 bridges both, which is what joins them into a single network.
Investigate device 20003 over the last 90 days. Is it shared, and is it blocked?
Critical risk, high confidence.
BlockedThe device is blocked, shared across 6 accounts, and all 165 checks in the window failed.
Here are 9 flagged accounts. Check each for device sharing and flag anything blocked.
All 9 came back in one pass.
2 surfacedSix share a single blocked device, and two accounts you did not submit were pulled in because they share a device with the set. The ring is bigger than your list.
What can you ask it?
From one question to a decision you can defend.
Close a case with one question.
tools: investigate_device, investigate_user, multi_level_search
Investigate this user over the last 90 days.
High risk, high confidence. The account isn't blocked itself, but its device is shared with 7 others and one device in its history is already blocked. Every one of its 30 checks failed.
- high 0.65
- device shared x7
- 1 blocked device
- 30 of 30 failed
Are these accounts one ring, or a coincidence?
Three separate devices, each on its own account, all three currently blocked. No shared device between them in 90 days, so this reads as three flagged accounts, not one ring.
- 3 devices
- 3 blocked
- no shared device
Pull the numbers without opening a dashboard.
tools: compliance_pass_rates, compliance_error_breakdown
Show me pass rates by region for the last 90 days.
55,090 checks. Pennsylvania passes at 96% on 54K checks. Four regions sit below 95% and are flagged.
- 94.7% overall
- 4 flagged
- by region
Break down why checks failed this quarter.
3,919 failures. Device integrity leads at 26%, then out-of-boundary and missing location data. Ordered by how often each fired.
- 3,919 failures
- device integrity 26%
- ranked
Answer "why did this fail" without raising a ticket.
tools: diagnose_failed_rules, search_client_docs, get_playbook
Why did this check fail? It fired proxy, boundary, and mocked location.
Three rules fired, all user-fixable, none need escalation. Each comes back with the cause and the exact fix.
- 3 rules
- all user-fixable
- no escalation
A customer is stuck at verification. What happened on their identity checks?
Four checks ran. Document, identity proofing, and knowledge-based questions all passed. The credit-file step returned no match, and that is where it stopped. That is the step to action.
- 3 of 4 passed
- stopped at credit file
- no ticket
Not every question is a fraud question.
tools: edge_market_data_overview, stadium_insights_games, edge_poi_coordinates
How does game day change activity across our venues?
A big jump from preseason to regular season: checks per game rose about 8x, active accounts about 5x, new accounts about 7x. Top venues by game-day checks below.
- ~8x checks
- ~5x active accounts
- game day
Ready to see one of these run on a case?
Book a demoWhat teams are asking
Every desk gets an answer.
Analysts, support reps, and leadership just ask.
- Investigate this user and show me everything connected to them.
- Is this device on a VPN, or is the location actually being spoofed?
- Has this device been blocked before, and why?
- Give me a daily fraud briefing.
- What are the top failure reasons our users hit in the last two weeks?
- Pass rates by operator for the last 7 days.
- Why did this check fail?
- What does this error code mean?
- Show me every account that touched this device in the last 60 days.
- Which users were active inside this geohash last month?
- Map the network around this device, two hops deep.
- Here are 50 usernames. Check each for device sharing and flag anything blocked.
- What happened on this customer's identity checks?
- How many checks landed inside our exclusion zones last week?
- Compare these two users. Do they share anything?
- Which playbooks do I have access to?
- Break down our compliance failures for this month.
- Summarize this investigation into a report I can hand off.
- Walk me through an account takeover investigation on this user.
- Pull the full transaction profile for this transaction ID.
- Investigate this user and show me everything connected to them.
- Why did this check fail?
What does one connection reach?
Fewer places to look, not more things to check.
36 tools on one connection, grouped by how an investigation actually runs. Playbooks map to how your team already investigates.
Is AI fraud investigation explainable?
The decision always stays yours.
What your analyst can defend
-
Signals in, decisions yours
The MCP reports state, it does not change it.
-
Same baseline every time
The same scoring runs every time.
-
Shows its working and its limits
Each verdict arrives with the signals behind it.
What stays separate
-
Your own credentials, enforced twice
Every call is signed with your organization's own credential.
-
Permissions you already set
Analysts inherit the grant they already hold, through single sign-on.
-
Nothing new without your sign-off
Per-organization tool allowlists cap the set any caller can reach.
FAQ
-
The GeoComply MCP is a remote server that connects an AI assistant to your GeoComply location, device, and identity data, so your team can run fraud and compliance investigations by asking in plain language. MCP, or Model Context Protocol, is an open standard from Anthropic that lets an assistant use an outside system as a tool. Ask a question, and the investigation comes back assembled: linked accounts, failed checks, and a scored verdict with the evidence behind it.
-
Claude, ChatGPT, Copilot, and other AI assistants your team already uses. It is built on an open standard, so any assistant that speaks MCP can connect, and your own agent can reach the same endpoint machine to machine. Bring the AI you already have.
-
Yes, and it is enforced in two places, not one. Every call is scoped to the operators your organization is entitled to, and the platform underneath enforces that scope again using your organization's own credential. An organization without a credential record gets nothing rather than borrowing another organization's access.
-
Every call is attributed to the analyst or agent that made it, and an agent's activity is distinguishable from a person's. Requests are scoped to your existing permissions on the way in, so the record shows who asked, what they asked, and which operators they were entitled to see.
-
No. The verdicts and the spoofing analysis come from GeoComply's own models, not the assistant's reasoning. The assistant calls a tool and returns what came back, with the evidence attached, and it says when a verdict is resting on thin evidence rather than filling the gap.
-
Neither. It reads and reports, it does not act. A verdict is evidence for your analyst, and case actions still happen wherever you manage cases today.
-
Location, device, and behavioural signals, the account's own check history, and the accounts and devices connected to it. No single input decides a verdict on its own, and a low-risk result means nothing was found in what was examined, which is not the same as nothing being there.
-
Point your agent at the endpoint and it authenticates as itself, machine to machine. It can also run as a named analyst, scoped to that person's own permissions rather than your organization's full reach. Either way the call is scoped and attributed the same way an analyst session is.
-
Minutes on your side, once we have provisioned your organization. Your org admin adds the connector in your AI platform and signs in once with single sign-on, with no software to deploy. Moving your own data between platform providers, if that is part of your setup, is separate work and usually the longer part.
-
The API gives you the data. What the MCP adds is the scored verdicts, the investigation methods that assemble a case, and the permission and audit layer already enforced on every request. You would be rebuilding the interpretation and the governance, not just the access.
-
Start narrow. Two of the three connection paths exist for this: a scheduled machine-to-machine job with no user-facing surface, or the named-analyst mode where each person's own permissions apply. Use of AI features is covered by GeoComply's published AI Features Addendum, so for most operators this is a pointer to existing terms, not a new contract.