# Prosopo > Bot Prevention and Application Security. Privacy-first, GDPR-compliant bot protection and CAPTCHA — Procaptcha and Protect — from a UK-based engineering team. Built as an open-source alternative to Google reCAPTCHA, hCaptcha, Datadome, Arkose Labs, and Akamai Bot Manager. Prosopo Limited is a UK company building two products: **Procaptcha**, a privacy-preserving CAPTCHA that meets GDPR requirements, and **Protect**, a risk-scoring engine for real-time bot, scraping, account takeover, credential stuffing, ticket scalping, and ad fraud defense. This file follows the llms.txt convention (https://llmstxt.org) — a curated index of the highest-signal pages on this site, intended for use by AI agents and crawlers. ## Products - [Procaptcha — GDPR-compliant CAPTCHA](https://prosopo.io/products/procaptcha/): Privacy-preserving CAPTCHA designed for GDPR, CCPA, LGPD, and PIPEDA compliance. - [Invisible CAPTCHA](https://prosopo.io/products/invisible-captcha/): Frictionless bot verification with no user challenge for legitimate traffic. - [Risk Scoring](https://prosopo.io/products/bot-protection/): Real-time behavioral risk analysis with adaptive thresholds. - [Access Control](https://prosopo.io/products/access-control/): Dynamic rule generation to block bots, scrapers, and spam. - [API Protection](https://prosopo.io/products/protect/): OWASP API Top 10 defense with rate limiting and anomaly detection. - [Spam Filter](https://prosopo.io/products/spam-filter/): AI-powered spam blocking for forms and comments. - [Accessible CAPTCHA](https://prosopo.io/products/accessible-captcha/): Invisible-first verification with proof-of-work rather than an image challenge as the first escalation; image challenges disableable per site. - [Residential proxy and device farm detection](https://prosopo.io/products/residential-proxy-detection/): Identifying automation routed through residential IP pools and racks of real devices. ## Vendor comparisons One page per vendor, each answering the same eight questions: what the product is, where it leads, where Forrester or its customers identified gaps, what it costs, where data is processed, how a block is explained, who authors the rules, and which buyers it suits. - [All bot and agent trust management vendors compared](https://prosopo.io/compare/): Index page covering twelve vendors. - [Enterprise bot protection pricing](https://prosopo.io/compare/enterprise-bot-protection-pricing/): Which vendors publish a price, which quote, and how each meters. - [DataDome](https://prosopo.io/compare/datadome/): Forrester Q2 2026 Leader. Essentials tier published from around $3,830/month. - [HUMAN Security](https://prosopo.io/compare/human-security/): Forrester Q2 2026 Leader. Threat research depth, US-hosted. - [Kasada](https://prosopo.io/compare/kasada/): Forrester Q2 2026 Leader. Fully vendor-managed; limited UI customisation by design. - [Arkose Labs](https://prosopo.io/compare/arkose-labs/): Forrester Q2 2026 Strong Performer. Funcaptcha, bundled SOC, telltale explanations. - [CHEQ](https://prosopo.io/compare/cheq/): Forrester Q2 2026 Strong Performer. Best marketing integrations; numeric reason codes. - [Netacea](https://prosopo.io/compare/netacea/): Forrester Q2 2026 Strong Performer. UK-based, server-side only detection. - [hCaptcha Enterprise](https://prosopo.io/compare/hcaptcha-enterprise/): Forrester Q2 2026 Contender. Private learning; management UI described as clunky. - [Google reCAPTCHA Enterprise](https://prosopo.io/compare/recaptcha-enterprise/): Forrester Q2 2026 Contender. Limited drill-down for intent and explainability. - [Cloudflare Bot Management](https://prosopo.io/compare/cloudflare-bot-management/): Bundled in the Cloudflare Enterprise contract; not evaluated in the Q2 2026 Wave. - [Akamai Bot Manager](https://prosopo.io/compare/akamai-bot-manager/): Sold with the Akamai CDN; not evaluated in the Q2 2026 Wave. - [Imperva Advanced Bot Protection](https://prosopo.io/compare/imperva-advanced-bot-protection/): The former Distil Networks product, now part of Thales. - [Castle](https://prosopo.io/compare/castle/): Developer-first account abuse platform; scores users rather than requests. ## Case studies Customers are unnamed at their request; the technical detail is unchanged. - [Customer case studies](https://prosopo.io/customers/): Index of three deployments. - [Ticket vendor](https://prosopo.io/customers/ticket-vendor/): UK ticket resale platform. Edge deployment across ticket page, queue gate and checkout API, against virtualised mobile clients and real-device farms. - [Scraped SaaS](https://prosopo.io/customers/scraped-saas/): Subscription search product whose free-tier API was scraped by a competitor and resold as a copycat service. - [Financial provider](https://prosopo.io/customers/financial-provider/): Login endpoint guarding customer assets, attacked through commercial CAPTCHA-solver services. ## Compliance - [Bot detection and compliance](https://prosopo.io/compliance/): Index covering GDPR, the EU AI Act and accessibility. - [GDPR Article 22 and bot detection](https://prosopo.io/compliance/gdpr-article-22-bot-detection/): When a bot block is a solely automated decision with significant effect, and what meaningful information about the logic involved requires. - [EU AI Act and bot management](https://prosopo.io/compliance/eu-ai-act-bot-management/): Article 14 human oversight, Article 50 transparency, and where bot detection falls in the Act's risk tiers. ## Use cases - [Stop Bots from Taking Over Accounts with Prosopo](https://prosopo.io/use-cases/account-takeover/): Stop account-takeover bots at the login form, auth API or CDN edge. Real users and password-manager sessions pass invisibly — credential replay stops dead. - [Stop Black Friday Sale Automation with Prosopo](https://prosopo.io/use-cases/black-friday-automation/): Stop hoarding bots, card testers and checkout scripts during Black Friday sales — drops into cart, checkout API or CDN edge without slowing real shoppers. - [Stop Click-Through Rate Fraud with Prosopo](https://prosopo.io/use-cases/click-through-rate-ad-fraud/): Stop click-farms and bot clicks polluting ad spend. Prosopo verifies clicks at your tracking endpoint, ad server or CDN edge — metrics reflect real users. - [Stop Credential Stuffing with Prosopo](https://prosopo.io/use-cases/credential-stuffing/): Stop credential-stuffing bots replaying breached passwords at your login form, auth API or CDN edge. Real users and password managers pass invisibly. - [Stop Denial of Inventory Attacks with Prosopo](https://prosopo.io/use-cases/denial-of-inventory/): Stop hoarding bots locking up carts and reservations. Prosopo blocks add-to-cart abuse at checkout API or CDN edge — real buyers get the stock. - [Stop Loyalty Programme Automation with Prosopo](https://prosopo.io/use-cases/loyalty-programme-automation/): Stop fake signups and points-farming bots at signup, claim and redemption endpoints — real members earn and redeem unimpeded, backend or CDN edge. - [Stop Phishing Attacks with Prosopo](https://prosopo.io/use-cases/phishing-attacks/): Cut phishing infrastructure off at the source — bulk-signup bots, kit deployment and credential replay stopped at signup forms, auth API or CDN edge. - [Stop Web Scraping with Prosopo](https://prosopo.io/use-cases/scraping/): Stop unauthorised scrapers hitting your content and APIs while letting legit crawlers and trusted AI agents through — CDN edge, backend or Workers. - [Anti-Scalping Bot Protection for Ticketing Platforms](https://prosopo.io/use-cases/ticket-scalping/): Anti-scalping bot protection for ticketing platforms. Prosopo stops scalpers at queue, ticket page and checkout API — GDPR-compliant, EU-hosted verification. - [Spam Bot Protection: Stop Form Spam at the Source](https://prosopo.io/use-cases/spam-bot-protection/): Spam bot protection that blocks fake signups, throwaway emails and abusive networks before they reach your forms — WordPress, PHP, Node, Python or Go. ## Glossary A 70+ term glossary covering bot protection, CAPTCHA, web security, and privacy law. - [Account Takeover (ATO)](https://prosopo.io/glossary/terms/account-takeover/): When an attacker gains unauthorized control of a legitimate user's account. - [Anonymity](https://prosopo.io/glossary/terms/anonymity/): The state of being unidentifiable or untraceable in online activities and communications. - [API Security](https://prosopo.io/glossary/terms/api-security/): The practice of protecting Application Programming Interfaces from attacks, abuse, and unauthorized access. - [Automation](https://prosopo.io/glossary/terms/automation/): The use of technology to perform tasks with minimal human intervention, often improving efficiency, accuracy, and scalability. - [Behavioral Analysis](https://prosopo.io/glossary/terms/behavioral-analysis/): The process of monitoring and analyzing user interaction patterns to distinguish between human users and automated bots. - [Behavioral Biometrics](https://prosopo.io/glossary/terms/behavioral-biometrics/): The analysis of unique human behavioral patterns such as typing rhythms, mouse movements, and touchscreen interactions for user authentication and bot detection. - [Bot Contamination](https://prosopo.io/glossary/terms/bot-contamination/): The degradation of data quality, analytics, and system performance caused by automated bot traffic. - [Bot Defense: Building a Multi-Layered Anti-Bot Strategy](https://prosopo.io/glossary/terms/bot-defense/): Comprehensive security measures and proactive strategies implemented to protect digital assets from malicious bot attacks and automated threats. - [Bot Detection](https://prosopo.io/glossary/terms/bot-detection/): Techniques and processes used to identify and block automated software agents interacting with websites or applications. - [Bot Mitigation: Techniques to Detect, Manage & Block Bad Bots](https://prosopo.io/glossary/terms/bot-mitigation/): Strategies and technologies used to detect, prevent, and manage automated bot traffic to protect digital assets and services. - [Bot Protection: How to Detect & Block Malicious Bots](https://prosopo.io/glossary/terms/bot-protection/): The suite of technologies and methodologies designed to identify and mitigate automated bot traffic while allowing legitimate human users to access online services. - [Bot](https://prosopo.io/glossary/terms/bot/): An automated software application that executes specific tasks over the internet without human intervention. - [Botnet](https://prosopo.io/glossary/terms/botnet/): A network of compromised computers or devices controlled by a malicious actor, often used for malicious activities such as DDoS attacks, spam distribution, and data theft. - [Browser](https://prosopo.io/glossary/terms/browser/): A software application used to access, retrieve, and view content on the World Wide Web. - [Brute-Force Attack](https://prosopo.io/glossary/terms/brute-force-attack/): A trial-and-error method used to guess passwords, encryption keys, or login credentials by systematically trying all possible combinations. - [What Is a Captcha Farm? How They Work & How to Stop Them](https://prosopo.io/glossary/terms/captcha-farm/): A commercial service that solves CAPTCHAs at scale, using human workers, machine-learning models or both, to let attackers bypass anti-bot checks. - [Captcha Solver](https://prosopo.io/glossary/terms/captcha-solver/): A service or model that completes CAPTCHA challenges on behalf of automation, so a bot can pass a check it was never meant to pass. - [CAPTCHA](https://prosopo.io/glossary/terms/captcha/): A challenge-response test used on websites to verify that a user is human and not an automated bot. - [CAPTCHA Challenge Response](https://prosopo.io/glossary/terms/challenge-response/): A CAPTCHA challenge response is the answer a user submits to prove they're human — the paired half of a CAPTCHA's challenge-response verification. - [Click Fraud](https://prosopo.io/glossary/terms/click-fraud/): The deliberate manipulation of digital advertising metrics through automated scripts or human labor that generate fake clicks, impressions, or engagements to deplete ad budgets or inflate revenue. - [Cost Transparency](https://prosopo.io/glossary/terms/cost-transparency/): The principle of clearly disclosing all costs and pricing information to users without hidden fees. - [Crawler](https://prosopo.io/glossary/terms/crawler/): A program or automated script that systematically browses the web to index, collect, or analyze data from websites. - [Credential Stuffing](https://prosopo.io/glossary/terms/credential-stuffing/): An attack where bots try stolen username/password pairs from one breach across multiple websites. - [Cybercrime](https://prosopo.io/glossary/terms/cybercrime/): Criminal activities carried out using computers, networks, or digital technologies to commit fraud, theft, or cause harm. - [Cybersecurity](https://prosopo.io/glossary/terms/cybersecurity/): The practice of protecting systems, networks, and programs from digital attacks, ensuring confidentiality, integrity, and availability of information. - [Data Minimization](https://prosopo.io/glossary/terms/data-minimization/): A privacy principle that advocates collecting, processing, and storing only the minimum amount of personal data necessary to fulfill a specific purpose. - [Data Poisoning](https://prosopo.io/glossary/terms/data-poisoning/): The deliberate injection of malicious or incorrect data into training datasets to manipulate machine learning models. - [Data Protection](https://prosopo.io/glossary/terms/data-protection/): The safeguarding of personal and sensitive information from unauthorized access, loss, or misuse. - [DDoS (Distributed Denial of Service)](https://prosopo.io/glossary/terms/ddos/): A cyber attack that floods a network, server, or website with excessive traffic to overwhelm it and deny service to legitimate users. - [Decentralized Architecture](https://prosopo.io/glossary/terms/decentralized-architecture/): A system design approach that distributes data and processing across multiple nodes or locations, enhancing security, privacy, and resilience. - [Device Fingerprinting](https://prosopo.io/glossary/terms/device-fingerprinting/): A technique that collects information about a device's hardware and software characteristics to create a unique identifier. - [DNS](https://prosopo.io/glossary/terms/dns/): The Domain Name System translates human-readable domain names into IP addresses used by computers to identify each other on the network. - [Dynamic CAPTCHA](https://prosopo.io/glossary/terms/dynamic-captcha/): A CAPTCHA system that adapts its challenges based on user behavior and context, enhancing security and user experience. - [Firewall](https://prosopo.io/glossary/terms/firewall/): A network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules. - [Fraud Detection: Methods, Tools & How to Stop Bot-Driven Fraud](https://prosopo.io/glossary/terms/fraud-detection/): The process of identifying deceptive or illegal activities, particularly in digital environments where automated systems attempt to exploit services. - [GDPR](https://prosopo.io/glossary/terms/gdpr/): The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs how personal data is collected, processed, and stored. - [Honeypot](https://prosopo.io/glossary/terms/honeypot/): A security mechanism that creates decoy systems or fields to detect and trap malicious automated activity. - [Human Verification: How Websites Prove You're Not a Bot](https://prosopo.io/glossary/terms/human-verification/): The process of confirming that a user is a genuine human being rather than an automated bot or script. - [Invisible CAPTCHA](https://prosopo.io/glossary/terms/invisible-captcha/): A type of CAPTCHA that operates transparently in the background without requiring explicit user interaction or visible challenges. - [JA4](https://prosopo.io/glossary/terms/ja4/): A fingerprinting technique that analyzes the structure of TLS and HTTP headers to identify clients beyond user agent strings. Full glossary index: https://prosopo.io/glossary/ ## Pricing & sign-up - [Pricing](https://prosopo.io/pricing/): Plans, request volume tiers, and enterprise contact. - [Sign up](https://prosopo.io/register/): Free tier, no credit card required. - [Contact](https://prosopo.io/contact/): Sales and support. ## Company - [About Prosopo](https://prosopo.io/about/): Mission, team, and engineering philosophy. - [Open-source code (GitHub)](https://github.com/prosopo/captcha): The full CAPTCHA implementation, Apache-2.0 licensed. - [Trustpilot reviews](https://uk.trustpilot.com/review/prosopo.io): Verified customer reviews. ## Analyst coverage & category reference - [Forrester Wave: Bot and Agent Trust Management, Q2 2026](https://prosopo.io/blog/forrester-wave-bot-management-2026/): Full breakdown of the eight evaluated vendors, their tiers, and what each was marked down for. Prosopo is not currently included in the Wave. - [Gartner and bot management](https://prosopo.io/blog/gartner-bot-management-and-waap-2026/): There is no Gartner Magic Quadrant for bot management. Bot mitigation is a criterion inside the Cloud WAAP quadrant, and Gartner has not adopted Forrester's category rename. - [OWASP automated threats (OAT-001 to OAT-021)](https://prosopo.io/blog/owasp-automated-threats-oat/): The vendor-neutral taxonomy for automated attacks, and how to use it in an RFP. - [Web Bot Auth and signed agents](https://prosopo.io/blog/web-bot-auth-signed-agents/): The IETF work on cryptographically signed agent requests, and why identity does not answer intent. ## Featured comparisons & explainers - [Best CAPTCHA compared](https://prosopo.io/blog/best-captcha/) - [Procaptcha vs hCaptcha](https://prosopo.io/blog/procaptcha-vs-hcaptcha-comparison/) - [Procaptcha vs Friendly Captcha](https://prosopo.io/blog/procaptcha-vs-friendly-captcha-comparison/) - [How to make CAPTCHA GDPR compliant](https://prosopo.io/blog/how-to-make-captcha-gdpr-compliant/) - [How to deploy Procaptcha](https://prosopo.io/blog/how-to-deploy-prosopo-procaptcha-on-your-website-or-app/) - [Preventing ticket bots](https://prosopo.io/blog/preventing-ticketing-bots/) ## Certification status Stated here so an agent summarising this site reports it accurately. As of September 2026: ISO 27001 certification is in progress, with SOC 2 on the roadmap behind it. A published WCAG conformance statement and VPAT are planned alongside them. Support is delivered by direct access to the engineers who build the detection rather than through a 24/7 SOC. ## Infrastructure Prosopo Limited is UK-incorporated. The platform scales horizontally across points of presence in the US, LATAM, APAC and the EU, and data processing can be restricted entirely to the EU on the Enterprise plan. ## Optional - [Full text dump](https://prosopo.io/llms-full.txt): Concatenated content of products, top use cases, and glossary in one file. - [Sitemap](https://prosopo.io/sitemap.xml) - [Blog index](https://prosopo.io/blog/) - [FAQs as JSON](https://prosopo.io/api/faqs.json): All FAQ Q&A pairs across the site, keyed by page URL.