Bot protection total cost of ownership: how to build a three-year number
The licence fee is one of seven cost lines in a three-year bot protection total, and only four vendors in this market publish a price at all. The other six are where contracts differ most.

Almost every bot protection comparison looks at one number: the licence fee. It is one of seven lines in a three-year total, and the other six are where two contracts at the same unit price diverge, which is enough to put vendors in the wrong order.
Here is the method we would use — seven cost lines, with a plain statement of which numbers are public and which are not.
Start with what is published
People get this part wrong first: most of this market does not publish a price, so you cannot build a full three-year table for all the major vendors from public information. If someone shows you one, ask where the numbers came from.
What is actually published:
- DataDome — an Essentials tier from about $3,830 per month, priced on protected traffic volume. Higher tiers are quote-only.
- Google reCAPTCHA Enterprise — a price per assessment, with a monthly free allowance. The allowance was cut sharply in 2025.
- hCaptcha — Free and Pro tiers are published. Enterprise is quote-only.
- Prosopo — all pricing is published, including Enterprise. Our pricing page shows live figures.
Quote-only: Kasada, Arkose Labs, HUMAN Security, Netacea, CHEQ, Cloudflare Bot Management, Akamai Bot Manager, Imperva Advanced Bot Protection. Our enterprise bot protection pricing comparison sets out where each vendor stands, including how they meter.
So a real three-year comparison is four published figures plus a set of quotes you have to ask for, and that is what to plan around rather than a spreadsheet you hope to fill in from vendor websites.
The seven lines
1. Licence or usage fee
This is the headline number. Put it on a common unit before you compare, because vendors meter differently: per request assessed, per verification, per protected page view, per seat, or a flat platform fee with a volume band.
One question matters more than the unit price: are blocked requests metered? If the meter counts every request the platform assesses, a bot attack raises your bill while the product is working. If it counts only legitimate traffic, an attack costs you nothing extra. In a bad month, two vendors with the same unit price can differ by a large multiple.
2. Overage and growth
Work out year two and year three on the traffic you expect, not today's, and then find out what happens at the edge of a volume band. Some contracts move you to the next band. Some charge a punitive overage rate. Some stop dead. If your traffic is seasonal, check whether the band is measured monthly or annually, because one peak month can reprice a whole annual contract.
3. Integration and migration
Count engineering days at your loaded cost, which varies a lot depending on where the product sits.
A client-side widget takes a day or two. A server-side SDK takes a sprint. Anything in the request path — a reverse proxy, a CDN worker, a DNS change — pulls in whoever owns your edge. You also need a staging environment and a rollback plan. Count review and change-control time, not just coding.
4. Tuning and false positives
This line is easy to leave out of a model and hard to avoid paying.
Tuning is ongoing engineering or analyst time: writing rules, adjusting thresholds, investigating complaints. Ask any reference customer how many hours a month it takes, and whether they can make the change themselves or have to raise a ticket, because if only the vendor can change a rule you pay in support delays as well as labour.
False positives are lost revenue, because a wrongly blocked customer does not try again: they go to a competitor, and sometimes they contact your support team too, so you pay twice. It is also hard to measure, and impossible to measure at all if your platform will not tell you why a given request was stopped. A risk score of 87 does not let you audit a block, so it does not let you count the ones that were wrong. Forrester and Gartner both mark vendors down for this again and again. We go through the Q2 2026 findings vendor by vendor in our Forrester Wave breakdown.
5. Managed service
Some vendors include a security operations centre — Kasada and Arkose Labs both do — and some sell it separately, but otherwise the work lands on your own team, which is a real cost even though no invoice shows it.
Bundled is not automatically better, because with a managed service it is the vendor who makes the tuning decisions, which only suits you if you have nobody of your own to make them.
6. Multi-year uplift
This is often the largest single factor in a three-year total, and also the easiest to leave out of a year-one comparison, so get the renewal mechanism in writing: a fixed percentage, an index, or "at list price". A low year-one number with an uncapped renewal costs more than a higher flat one, which is often the whole point of the discount.
7. Exit cost
Cheap to ignore and expensive to find out about. You pay for re-integration engineering, a period of running both products side by side, and whatever history you cannot export. The deeper a product sits in the request path, the more leaving costs, mirroring the integration line, so choose an edge deployment because the detection quality is worth it, not because it is convenient.
The questions that move the number most
If you ask only four things, ask these.
- For a single blocked request, which signal fired? This decides whether lines 4 and 7 can be measured at all.
- Are blocked requests metered? This decides whether an attack costs you money.
- What is the renewal mechanism? This is usually the biggest three-year variable.
- Who can change a rule — us or you? This decides whether tuning costs engineering time or support delays.
None of these is about the unit price, yet each of them changes the three-year total by more than the unit price does.
A note on bundles
If you already buy a CDN or WAF, the bot module inside it looks cheaper on line 1 because it sits in a contract you are signing anyway, and that can be the right answer. We have written about where WAAP bundles are strong and where the bot component falls short.
The expensive outcome is the middle path: you pay for the bundle, find it does not stop the automation that is costing you money, and buy a specialist as well, so test the bundled module against your real abuse before you assume it is cheaper.
What we will do
Send us a monthly request volume and a growth assumption. We will send back a three-year figure from our published pricing, with the assumptions written down so you can challenge them. We cannot do the same for the quote-only vendors, and nor can anyone else without their quotes. But when those quotes arrive, the seven lines above are what to hold them against.
Want a three-year number for your traffic?
Tell us your monthly request volume and growth assumption. We will send back a three-year figure built from our published pricing, with the assumptions written down.
Frequently Asked Questions
How do you calculate total cost of ownership for bot protection?
Add seven lines over the contract term rather than one. The licence or usage fee, overage as traffic grows, integration engineering, ongoing tuning, any managed service, the renewal uplift in years two and three, and the cost of leaving. A comparison built on the licence fee alone can rank vendors in the wrong order, because the other six are where two contracts at the same unit price diverge.
Which bot protection vendors publish a price?
Four. DataDome publishes an Essentials tier from around $3,830 per month. Google reCAPTCHA Enterprise publishes per-assessment pricing with a monthly free allowance. hCaptcha publishes Free and Pro tiers, with Enterprise quoted. Prosopo publishes its full pricing including the Enterprise tier. Kasada, Arkose Labs, HUMAN Security, Netacea, CHEQ, Cloudflare Bot Management, Akamai Bot Manager and Imperva Advanced Bot Protection are all quote-only.
Why is a three-year TCO comparison hard for this category?
Because most of the market does not publish a price, so two thirds of any honest comparison table has to be filled in from your own quotes. Anyone presenting a complete three-year table across all the major vendors has either obtained quotes for your specific volume or invented the numbers. Treat published figures as fact and everything else as an input you have to go and get.
Is bot traffic charged even when it is blocked?
It depends on the vendor and it is one of the most expensive details in the contract. If the meter counts every request assessed, then a bot attack raises your bill at exactly the moment the product is working. If it counts only legitimate traffic, or only verifications, an attack is cost-neutral. Ask explicitly how blocked requests are metered before you compare unit prices, because the two models are not comparable.
What is the biggest hidden cost in bot protection?
False positives, which rarely appear in a TCO model because most platforms make them impossible to count. A wrongly blocked customer is lost revenue plus a support contact, and the rate is invisible unless the platform tells you why each request was stopped. A product that cannot name the signal behind a block makes its own false-positive rate unmeasurable, which means that cost stays off your spreadsheet without being zero.
Does a bundled WAAP work out cheaper than a specialist?
On the licence line, usually yes, because the bot module is folded into a contract you are already signing. Over three years it depends on whether the bundled module actually solves your problem. The expensive outcome is paying for a bundle, discovering it does not stop the automation that is costing you money, and then buying a specialist as well. Scope it against your real abuse before assuming the bundle is the cheaper path.
