# Prosopo > Bot Prevention and Application Security. Privacy-first, GDPR-compliant bot protection and CAPTCHA — Procaptcha and Protect — from a UK-based engineering team. Built as an open-source alternative to Google reCAPTCHA, hCaptcha, Datadome, Arkose Labs, and Akamai Bot Manager. Prosopo Limited is a UK company building two products: **Procaptcha**, a privacy-preserving CAPTCHA that meets GDPR requirements, and **Protect**, a risk-scoring engine for real-time bot, scraping, account takeover, credential stuffing, ticket scalping, and ad fraud defense. This file follows the llms.txt convention (https://llmstxt.org) — a curated index of the highest-signal pages on this site, intended for use by AI agents and crawlers. ## Products - [Procaptcha — GDPR-compliant CAPTCHA](https://prosopo.io/products/procaptcha/): Privacy-preserving CAPTCHA designed for GDPR, CCPA, LGPD, and PIPEDA compliance. - [Invisible CAPTCHA](https://prosopo.io/products/invisible-captcha/): Frictionless bot verification with no user challenge for legitimate traffic. - [Risk Scoring](https://prosopo.io/products/bot-protection/): Real-time behavioral risk analysis with adaptive thresholds. - [Access Control](https://prosopo.io/products/access-control/): Dynamic rule generation to block bots, scrapers, and spam. - [API Protection](https://prosopo.io/products/protect/): OWASP API Top 10 defense with rate limiting and anomaly detection. - [Spam Filter](https://prosopo.io/products/spam-filter/): AI-powered spam blocking for forms and comments. ## Use cases - [Stop Bots from Taking Over Accounts with Prosopo](https://prosopo.io/use-cases/account-takeover/): Stop account-takeover bots at the login form, auth API or CDN edge. Real users and password-manager sessions pass invisibly — credential replay stops dead. - [Stop Black Friday Sale Automation with Prosopo](https://prosopo.io/use-cases/black-friday-automation/): Stop hoarding bots, card testers and checkout scripts during Black Friday sales — drops into cart, checkout API or CDN edge without slowing real shoppers. - [Stop Click-Through Rate Fraud with Prosopo](https://prosopo.io/use-cases/click-through-rate-ad-fraud/): Stop click-farms and bot clicks polluting ad spend. Prosopo verifies clicks at your tracking endpoint, ad server or CDN edge — metrics reflect real users. - [Stop Credential Stuffing with Prosopo](https://prosopo.io/use-cases/credential-stuffing/): Stop credential-stuffing bots replaying breached passwords at your login form, auth API or CDN edge. Real users and password managers pass invisibly. - [Stop Denial of Inventory Attacks with Prosopo](https://prosopo.io/use-cases/denial-of-inventory/): Stop hoarding bots locking up carts and reservations. Prosopo blocks add-to-cart abuse at checkout API or CDN edge — real buyers get the stock. - [Stop Loyalty Programme Automation with Prosopo](https://prosopo.io/use-cases/loyalty-programme-automation/): Stop fake signups and points-farming bots at signup, claim and redemption endpoints — real members earn and redeem unimpeded, backend or CDN edge. - [Stop Phishing Attacks with Prosopo](https://prosopo.io/use-cases/phishing-attacks/): Cut phishing infrastructure off at the source — bulk-signup bots, kit deployment and credential replay stopped at signup forms, auth API or CDN edge. - [Stop Web Scraping with Prosopo](https://prosopo.io/use-cases/scraping/): Stop unauthorised scrapers hitting your content and APIs while letting legit crawlers and trusted AI agents through — CDN edge, backend or Workers. - [Anti-Scalping Bot Protection for Ticketing Platforms](https://prosopo.io/use-cases/ticket-scalping/): Anti-scalping bot protection for ticketing platforms. Prosopo stops scalpers at queue, ticket page and checkout API — GDPR-compliant, EU-hosted verification. - [Spam Bot Protection: Stop Form Spam at the Source](https://prosopo.io/use-cases/spam-bot-protection/): Spam bot protection that blocks fake signups, throwaway emails and abusive networks before they reach your forms — WordPress, PHP, Node, Python or Go. ## Glossary A 70+ term glossary covering bot protection, CAPTCHA, web security, and privacy law. - [Account Takeover (ATO)](https://prosopo.io/glossary/terms/account-takeover/): When an attacker gains unauthorized control of a legitimate user's account. - [Captcha Solver](https://prosopo.io/glossary/terms/captcha-solver/): A tool, service, or algorithm designed to solve CAPTCHAs, either manually or automatically. - [Proxy — Types, Uses & How Bots Exploit Them](https://prosopo.io/glossary/terms/proxy/): An intermediary server or service that forwards requests between clients and other servers, often used for privacy, security, or caching. - [Automation](https://prosopo.io/glossary/terms/automation/): The use of technology to perform tasks with minimal human intervention, often improving efficiency, accuracy, and scalability. - [Behavioral Analysis](https://prosopo.io/glossary/terms/behavioral-analysis/): The process of monitoring and analyzing user interaction patterns to distinguish between human users and automated bots. - [Behavioral Biometrics](https://prosopo.io/glossary/terms/behavioral-biometrics/): The analysis of unique human behavioral patterns such as typing rhythms, mouse movements, and touchscreen interactions for user authentication and bot detection. - [Bot Contamination](https://prosopo.io/glossary/terms/bot-contamination/): The degradation of data quality, analytics, and system performance caused by automated bot traffic. - [Bot Detection](https://prosopo.io/glossary/terms/bot-detection/): Techniques and processes used to identify and block automated software agents interacting with websites or applications. - [Botnet](https://prosopo.io/glossary/terms/botnet/): A network of compromised computers or devices controlled by a malicious actor, often used for malicious activities such as DDoS attacks, spam distribution, and data theft. - [Browser](https://prosopo.io/glossary/terms/browser/): A software application used to access, retrieve, and view content on the World Wide Web. - [Brute-Force Attack](https://prosopo.io/glossary/terms/brute-force-attack/): A trial-and-error method used to guess passwords, encryption keys, or login credentials by systematically trying all possible combinations. - [CAPTCHA Challenge Response](https://prosopo.io/glossary/terms/challenge-response/): A CAPTCHA challenge response is the answer a user submits to prove they're human — the paired half of a CAPTCHA's challenge-response verification. - [Click Fraud](https://prosopo.io/glossary/terms/click-fraud/): The deliberate manipulation of digital advertising metrics through automated scripts or human labor that generate fake clicks, impressions, or engagements to deplete ad budgets or inflate revenue. - [Cost Transparency](https://prosopo.io/glossary/terms/cost-transparency/): The principle of clearly disclosing all costs and pricing information to users without hidden fees. - [Crawler](https://prosopo.io/glossary/terms/crawler/): A program or automated script that systematically browses the web to index, collect, or analyze data from websites. - [Credential Stuffing](https://prosopo.io/glossary/terms/credential-stuffing/): An attack where bots try stolen username/password pairs from one breach across multiple websites. - [Cybercrime](https://prosopo.io/glossary/terms/cybercrime/): Criminal activities carried out using computers, networks, or digital technologies to commit fraud, theft, or cause harm. - [Cybersecurity](https://prosopo.io/glossary/terms/cybersecurity/): The practice of protecting systems, networks, and programs from digital attacks, ensuring confidentiality, integrity, and availability of information. - [Data Poisoning](https://prosopo.io/glossary/terms/data-poisoning/): The deliberate injection of malicious or incorrect data into training datasets to manipulate machine learning models. - [DDoS (Distributed Denial of Service)](https://prosopo.io/glossary/terms/ddos/): A cyber attack that floods a network, server, or website with excessive traffic to overwhelm it and deny service to legitimate users. - [Decentralized Architecture](https://prosopo.io/glossary/terms/decentralized-architecture/): A system design approach that distributes data and processing across multiple nodes or locations, enhancing security, privacy, and resilience. - [Device Fingerprinting](https://prosopo.io/glossary/terms/device-fingerprinting/): A technique that collects information about a device's hardware and software characteristics to create a unique identifier. - [DNS](https://prosopo.io/glossary/terms/dns/): The Domain Name System translates human-readable domain names into IP addresses used by computers to identify each other on the network. - [Dynamic CAPTCHA](https://prosopo.io/glossary/terms/dynamic-captcha/): A CAPTCHA system that adapts its challenges based on user behavior and context, enhancing security and user experience. - [Firewall](https://prosopo.io/glossary/terms/firewall/): A network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules. - [Fraud Detection: Methods, Tools & How to Stop Bot-Driven Fraud](https://prosopo.io/glossary/terms/fraud-detection/): The process of identifying deceptive or illegal activities, particularly in digital environments where automated systems attempt to exploit services. - [GDPR](https://prosopo.io/glossary/terms/gdpr/): The General Data Protection Regulation (GDPR) is a comprehensive data protection law in the European Union that governs how personal data is collected, processed, and stored. - [Honeypot](https://prosopo.io/glossary/terms/honeypot/): A security mechanism that creates decoy systems or fields to detect and trap malicious automated activity. - [Invisible CAPTCHA](https://prosopo.io/glossary/terms/invisible-captcha/): A type of CAPTCHA that operates transparently in the background without requiring explicit user interaction or visible challenges. - [JA4](https://prosopo.io/glossary/terms/ja4/): A fingerprinting technique that analyzes the structure of TLS and HTTP headers to identify clients beyond user agent strings. - [Machine Learning](https://prosopo.io/glossary/terms/machine-learning/): A branch of artificial intelligence that enables computers to learn and make decisions from data without explicit programming. - [Malware](https://prosopo.io/glossary/terms/malware/): Malicious software designed to harm, exploit, or gain unauthorized access to computer systems and networks. - [Man-in-the-Middle Attack](https://prosopo.io/glossary/terms/man-in-the-middle-attack/): A cyberattack where an attacker secretly intercepts and potentially alters communications between two parties who believe they are directly communicating with each other. - [Multi-Factor Authentication](https://prosopo.io/glossary/terms/multi-factor-authentication/): A security method requiring users to provide two or more verification factors to gain access to accounts or systems. - [Network Security](https://prosopo.io/glossary/terms/network-security/): The practice of protecting computer networks from unauthorized access, misuse, or theft, ensuring the confidentiality, integrity, and availability of data. - [OWASP](https://prosopo.io/glossary/terms/owasp/): The Open Web Application Security Project, a nonprofit organization focused on improving software security through community-driven open-source projects and resources. - [Personally Identifiable Information](https://prosopo.io/glossary/terms/personally-identifiable-information/): Any data that can be used to identify an individual, either directly or indirectly. - [Phishing](https://prosopo.io/glossary/terms/phishing/): A cyberattack that uses deceptive emails, messages, or websites to trick users into revealing sensitive information or installing malware. - [Procaptcha](https://prosopo.io/glossary/terms/procaptcha/): A privacy-first CAPTCHA solution that uses advanced machine learning techniques to provide secure and user-friendly verification. - [Ransomware](https://prosopo.io/glossary/terms/ransomware/): Malicious software that encrypts victims' files or locks their systems, demanding payment for restoration of access. Full glossary index: https://prosopo.io/glossary/ ## Pricing & sign-up - [Pricing](https://prosopo.io/pricing/): Plans, request volume tiers, and enterprise contact. - [Sign up](https://prosopo.io/register/): Free tier, no credit card required. - [Contact](https://prosopo.io/contact/): Sales and support. ## Company - [About Prosopo](https://prosopo.io/about/): Mission, team, and engineering philosophy. - [Open-source code (GitHub)](https://github.com/prosopo/captcha): The full CAPTCHA implementation, Apache-2.0 licensed. - [Trustpilot reviews](https://uk.trustpilot.com/review/prosopo.io): Verified customer reviews. ## Featured comparisons & explainers - [Procaptcha vs hCaptcha](https://prosopo.io/blog/procaptcha-vs-hcaptcha-comparison/) - [Procaptcha vs Friendly Captcha](https://prosopo.io/blog/procaptcha-vs-friendly-captcha-comparison/) - [How to make CAPTCHA GDPR compliant](https://prosopo.io/blog/how-to-make-captcha-gdpr-compliant/) - [How to deploy Procaptcha](https://prosopo.io/blog/how-to-deploy-prosopo-procaptcha-on-your-website-or-app/) - [Preventing ticket bots](https://prosopo.io/blog/preventing-ticketing-bots/) ## Optional - [Full text dump](https://prosopo.io/llms-full.txt): Concatenated content of products, top use cases, and glossary in one file. - [Sitemap](https://prosopo.io/sitemap.xml) - [Blog index](https://prosopo.io/blog/) - [FAQs as JSON](https://prosopo.io/api/faqs.json): All FAQ Q&A pairs across the site, keyed by page URL.