Compare · Sep 1, 2026 · 6 min read

Netacea: server-side only, and why that is half the picture

Netacea is a Forrester Q2 2026 Strong Performer and the other UK vendor in this market. Server-side-only detection, model simulation, the most intricate pricing in the category, and where a client-side layer still earns its place.

Netacea: server-side only, and why that is half the picture

Netacea is the other UK vendor in this market, so the two come up together more often than relative size would suggest. Netacea is the larger company and takes a different technical approach, one worth explaining properly rather than dismissing.

What Netacea is

Netacea Bot Protection, based in England, built on a server-side-only detection model. There is no JavaScript running in the visitor's browser. Detection happens from request data and behavioural patterns observed at the server.

Where it leads

Forrester rates Netacea superior for web-scraping defence and transaction assurance. The standout feature is the ability to simulate the detection model in operation before deployment, which lets you see what would have been blocked against real historical traffic. Nobody else in the Wave has that, and if false positives on checkout are the thing keeping your team awake, it is the single most useful thing on this page.

Server-side-only also has a genuine architectural advantage. It reaches API endpoints, mobile clients and anything else a browser widget never touches.

Where Forrester identified gaps

Pricing is among the most intricate of any vendor in the evaluation: onboarding, platform, support and usage bands as separate components. Report customisation is limited, because Netacea prefers to handle reporting for you.

If you evaluate Netacea, model the three-year total rather than the year-one number.

The server-side question

The substantive technical difference between the two products sits here, and it is worth setting out in full.

Netacea's CTO, Andy Still, has said that 18% of LLM scraping traffic now mimics human click patterns to slip past client-side JavaScript and CAPTCHA checks. That is a fair observation, and it is why Prosopo runs server-side scoring in Decision Machines as well.

The disagreement is over the conclusion. A bot that has learned to fake clicks is a reason to look harder at the clicks, rather than to stop looking. Faked interaction falls apart under close inspection: cursor micro-jitter, scroll cadence, typing rhythm, and CPU timing signatures. Several of Prosopo's most reliable detectors work on exactly that, for example Inconsistent hardware readings for device and Synthetic interaction timings. Neither can fire without a client-side signal.

So Prosopo runs both layers: client-side behavioural collection through Catcher, server-side scoring through Decision Machines, and one verdict from the combination.

What it costs

Quoted, in several components.

Where data is processed

United Kingdom. Netacea and Prosopo are the two UK-based vendors on this list, so neither carries the US-hosting question. Prosopo can additionally restrict processing entirely to the EU on the Enterprise plan, and a dedicated database can be arranged so visitors' data is never held alongside another site's.

How a block gets explained

Through Netacea's reporting, which they largely run for you. Forrester flagged report customisation as limited.

Who authors the rules

Netacea, on the customer's behalf.

Which buyers Netacea suits

Netacea is the stronger fit if pre-deployment model simulation is what you need to get sign-off, if you want a UK vendor with SOC 2 and ISO 27001 already attested, if you would rather somebody else ran the reporting, or if everything you protect is server-side and a browser layer would add nothing.

How Prosopo compares

Where Prosopo is the stronger choice:

You want both detection layers rather than one, particularly against solver services and real-device farms where the client-side signal is what breaks the disguise.

If you want to author your own Access Rules and customise your own reporting rather than requesting it.

If you want simple, published pricing you can model without a call.

Side by side

ProsopoNetacea
Forrester Q2 2026 tierNot evaluatedStrong Performer
Detection layersClient-side and server-sideServer-side only
Pre-deployment simulationNoYes
Block explanationPlain-language reasonVendor reporting
Rule authoringCustomer, self-serveVendor
Report customisationSelf-serve, exportableLimited by design
Client stackOpen sourceNo client stack
Data processingEU-only available on Enterprise. Points of presence in US, LATAM, APAC, EUUK
Data isolationDedicated database can be arranged (Enterprise)Not published
Published pricingFull ladder on pricingQuoted, multi-component
SOC 2 / ISO 27001ISO 27001 in progress, SOC 2 on the roadmapYes

More in the Forrester Wave breakdown.

Comparing Netacea?

Both of us are UK companies selling into the same market, so we get asked about this a lot. Tell us what you are protecting and we will give you a straight read.

Tell us about your bot problem

We'll get back to you straight away

By submitting this form, you agree to our Privacy Policy and Terms of Service

Frequently Asked Questions

What is Netacea?

Netacea Bot Protection is a UK-based bot management platform with a deliberately server-side-only detection model, meaning it analyses request and behaviour data at the server rather than running JavaScript in the visitor's browser. Forrester named Netacea a Strong Performer in The Forrester Wave: Bot And Agent Trust Management Software, Q2 2026.

What did Forrester praise Netacea for?

Superior web-scraping defence and transaction assurance, plus a feature that simulates the detection model in operation before you deploy it. That simulation step is unusual, and useful for estimating false-positive risk ahead of go-live.

What did Forrester criticise Netacea for?

Pricing is among the most intricate of any vendor in the evaluation, with separate fees for onboarding, platform, support and usage bands. Report customisation is limited because Netacea prefers to handle reporting on the customer's behalf.

Is server-side-only bot detection enough?

It reaches endpoints a widget cannot, so we run server-side scoring too. Netacea's own CTO, Andy Still, has noted that 18% of LLM scraping traffic now mimics human click patterns to slip past client-side checks. We read that as an argument for running both layers: once bots fake clicks, you want to see the clicks as well as the server-side intent, because faked interaction usually falls apart under cursor micro-jitter, scroll cadence and CPU timing analysis.

Is Netacea or Prosopo better for a UK buyer?

Both are UK companies, which removes the US-hosting objection for either. Netacea is larger, has SOC 2 and ISO 27001 already attested, and runs reporting for you. Prosopo's ISO 27001 certification is in progress, and Prosopo is the specialist: your team authors the rules, every block comes with a reason you can read, the client stack is open source, and Prosopo runs points of presence in the US, LATAM, APAC and the EU. Pick on operating model rather than jurisdiction.