Agent · /llms.txt SHA-256
← News
25 June 2026 Launch · Octet is live

Octet is live.

Octet is a new primitive for proving location: a hardware-signed proof that a known device is where it claims to be. Live now for iOS and Android.

Trusted time is a solved problem. Atomic clocks and signed timestamps let networks, markets, and machines agree on when, down to the nanosecond. There has been no equivalent for location. The place attached to an event is whatever the device claims, and the device can claim anything. There is a gap between physical reality and how it is represented digitally, and until now nothing could close it. Octet is live today. It proves where.

When you log in, send money, or hit buy, your phone attaches a location to the action. It reports what it was told, not what is true. Every signal it exposes can be faked: GPS, IP, the location services your apps rely on. $300 of hardware spoofs GPS. A five-dollar VPN moves your IP across the world. One free spoofing app has more than 50 million installs. There is no way for systems to prove whether you logged in from Tokyo or Manhattan.

Location is not the only thing that can be faked. Every credential a system checks is something someone else can learn or copy: a password, a document, a face. This is the mechanism behind account takeover, business email compromise, and synthetic identity. The system verifies what is known about you, and everything known gets stolen.

One thing cannot be copied: where your body is. You are here. You cannot also be there. The attacker wearing your identity is somewhere else, and the attacks are multiplying. Cybercrime is among the largest economies on earth, by many estimates larger than the GDP of Japan. The fastest-growing part is impersonation.

Generative AI can copy every signal a system trusts: faces, voices, documents, credentials. The copy is no longer detectable. Fraud succeeds when the victim ties the action to the wrong actor, and the actor is now either a machine impersonating a person or a person using AI to impersonate someone else.

The defender has two jobs: protect the user, and not destroy their experience. The attacker has one. The asymmetry will not resolve on its own. The defense against perfect copies is a signal that cannot be copied: where you physically are. Octet makes that signal provable.

Octet learns location from inertial motion, RF geometry, GPS, and signals most systems ignore, then signs it into a single proof. Generated on the device. Signed in the Secure Enclave. The private key bound to the hardware. What leaves the device is a predicate: a hardware-signed yes or no against a policy. Inside this jurisdiction. Outside that one. At this venue.

The inertial-fusion stack was developed with US Air Force funding. The same signals civilian platforms rely on cannot be trusted when lives are at risk. The Octet SDK does not receive location. It builds location, datum by datum, until your trajectory forms the proof.

Presence is a primitive. When location determines what is real or legal, developers can build on ground truth, from fintech to logistics to social apps to AI agents that must prove where they act. And it opens products that could not exist before: markets that open only where they are legal, payments that clear only from the right place, functionality that triggers only when the user is actually there. We are starting with two use cases: jurisdictional compliance and stopping fraud.

  • Jurisdictional compliance and geofencing. A sanctions screen trusts the country an IP address claims to be in. Whoever leases the address block declares that country from a dropdown, and the claim goes unverified. An operator in a sanctioned territory can hold IP addresses that resolve to Frankfurt. VPNs are the easy attack on top of a system that never measured location to begin with. Without active manipulation, the signal is still imprecise: geolocation databases disagree on the location of the same IP address by 620 kilometers on average. By our analysis, 68 million people live in sanctioned jurisdictions within 100km of a non-sanctioned border. That imprecision cuts both ways, blocking legitimate users and wasting the screening budget on the wrong people. The largest sanctions fine in banking history was $8.9 billion. A recent settlement included nearly $1 billion for OFAC violations, and the CEO served time. Octet replaces guesswork with a hardware-signed predicate. Add one check to your trade, swap, or transfer endpoint.
  • Stopping fraud. Microsoft sees 7,000 password attacks every second, and the majority use credentials that are real. When an attacker logs in with a stolen password, there is nothing to detect. The credential is genuine, so every check passes. It confirms the account is in use, not that the right person is using it. The legitimate customer and their device are in one place. The attacker is in another. With Octet in the flow, the attacker cannot prove otherwise. Drop the SDK into the high-value action: withdrawal, transfer, trade. The proof is generated at the moment of action and bound to the device in hand. Any attempt from somewhere else fails the check.

When a system cannot prove where someone is, it asks for everything: more documents, more steps, more friction. Provable presence removes the reason to ask. Doors open because you are there. Payments clear without challenge.

Every era trades trust for proof. HTTP became HTTPS. The magnetic stripe became the EMV chip. The paper passport became the cryptographic chip. In each case, as the cost of fraud rose, friction disappeared. Location is next. Because you can only be in one place at a time.

The ground is where the truth has been all along. Octet · Launch, June 2026

The SDK is live. One line in the stack you already have. Do not take our word for it: the verifier is open source and runs anywhere, so anyone can check a proof without asking us. Start here.

Get a license key Quickstart ↗︎ Read the docs ↗︎ Verify it yourself ↗︎