Bot Protection and Agent Trust Management

Prosopo is the specialist entry in Forrester's Bot and Agent Trust Management category, delivered as one platform in two modes — a drop-in widget for form-level protection, and invisible enforcement at the edge for continuous protection across a whole site. Every verdict returns an explainable reason rather than a black-box model output.

Bot Protection and Agent Trust Management
How it works

How the stack works

Detect, decide, explain — running against the same rules engine, dashboard and event stream whether the request came through the widget on a form or the edge enforcement in front of origin.

Detect

Every request is scored against behavioural signals (cursor, scroll, typing rhythm, SIMD-CPU signatures), JA4 TLS fingerprinting, DNS resolver observation, iOS App Attest and Android Play Integrity, IP reputation and residential-proxy classification.

Decide

The Decision Machine applies Access Rules against the score. Real humans and authorised agents pass invisibly; suspicious sessions escalate to a proof-of-work computation or an image challenge; known-bad traffic never reaches origin.

Explain

Every block response includes the rule that fired, and the event itself is drillable in the operator portal — the same view Prosopo engineers use internally — and exportable to Datadog, Splunk, Elastic or Sentinel.
Why Prosopo

Why teams pick Prosopo over the incumbents

Blocks return an explainable reason

Every Prosopo block response includes the reason attached, human-readable in the portal rather than as a black-box model output. The Forrester Q2 2026 Wave keeps marking DataDome, Kasada, HUMAN and Arkose down on exactly this — drill-down that's opinionated and vendor-curated, rather than direct read-access to what actually fired.

The event stream is exportable

The same events Prosopo engineers use internally to build new detectors — request, JA4, timing signal, rule firing — are filterable by every dimension the platform scores on and exportable to Datadog, Splunk, Elastic or Sentinel. The raw data rather than a curated summary.

The client is open source

The widget, the collectors and the client-side integration are all on GitHub, which means a technical evaluator can `npm install` and read the code before committing to the platform. The server-side detector is proprietary; customers who need to run entirely self-hosted receive a periodic obfuscated bundle.

One platform, two delivery modes

Widget for form-level protection, edge enforcement for continuous protection across a whole site. Same detection, same rules, same dashboard — the delivery mode is a deployment decision rather than a separate product.

Detection that keeps up with the attackers

JA4 fingerprinting, DNS resolver observation, iOS App Attest, Android Play Integrity, stealth-headless detection (Puppeteer Stealth, Playwright Stealth, undetected-chromedriver, nodriver), residential-proxy classification. The full detection surface the leaders ship, without the wall around it.

UK-incorporated, EU-processed

GDPR-native by design. The widget is cookieless by default (edge-mode deployments may set first-party session cookies for continuity). Human users aren't profiled cross-site — bot toolkits are, and that's how a scraper caught on one customer's site is recognised on the next. EU-only verification endpoints available on request. Enterprise support routes straight to the engineers who wrote the detection rather than through a tiered support queue.

What bot protection actually means in 2026

Bot protection — the discipline Forrester renamed to Bot and Agent Trust Management in its Q2 2026 Wave — covers most of what modern security teams need to keep automated attackers out of applications: credential stuffing, scraping (including the AI-training crawlers that ignore robots.txt), inventory hoarding, account takeover, ticket scalping, spam bot submissions, and the newer wave of authorised AI shopping agents that sit somewhere between real humans and the unwanted automation Prosopo is designed to stop.

Ten years ago, bot protection was mostly a CAPTCHA plus an IP blocklist, and in 2026 that combination catches almost nothing worth the name. Stealth headless browsers running on rotating residential proxies pass a CAPTCHA image check in milliseconds, at a fraction of a cent per solve via the various CAPTCHA-solving farms that operate at scale. Serious bot protection needs the whole stack — detection, decision, and (the part every incumbent still keeps behind a wall) the ability to explain why a specific request was blocked in the first place.

Bot detection as a service

If you've been searching for a bot detection service, bot detection website solution or web bot detection provider — those all describe the detection layer of what this page covers. Prosopo runs bot detection continuously against every request that hits a protected endpoint, with the score exposed both to the built-in Decision Machine (which acts on it via Access Rules) and to the customer's own backend (which can act on it however it likes). The detection layer is delivered as a managed service against a proprietary detector, with the client-side collectors open source on GitHub so a technical evaluator can read the code before committing.

Where Prosopo is deployed

Prosopo runs in production against several classes of adversarial-bot workload:

  • Ticketing platforms — full-traffic edge deployment against professional ticket-touting bots, including VM-iOS and real-device bot nets.
  • Subscription SaaS with free-tier scraping — the copycat-competitor pattern common in face-search, reverse-image, people-search and small-API businesses.
  • Crypto-wallet login endpoints — defending against CAPTCHA-solver services attempting account takeover.

How Prosopo compares to the Forrester-named vendors

CapabilityProsopoDataDomeHUMANArkose Labs
Behavioural analysis
Residential-proxy detection
Invisible-first UX (no default challenge) game challenges
EU-hosted processing enterprise
Widget cookieless by default
Blocks trace to a human-readable rule Named Access Rule GenAI summary Sightline view "Telltales"
Raw event stream exportable to your SIEM Datadog / Splunk / Elastic / Sentinel Vendor dashboard Vendor dashboard Vendor dashboard
Agent-aware policy (AI agents)

For the full Forrester picture see the 2026 Wave for Bot and Agent Trust Management — DataDome, HUMAN and Kasada were named Leaders. For a CAPTCHA-focused comparison of the whole market, read Cloudflare Turnstile alternatives.

Alternatives evaluations

Teams end up on this page from a few different directions. If you searched for Imperva advanced bot protection, PerimeterX (PX) bot protection, AWS WAF bot management or Cloudflare bot management alternatives, Prosopo covers the same category — Forrester's Bot and Agent Trust Management — with three differences the incumbents don't offer: an open-source client stack that a technical evaluator can npm install and read before committing; a proprietary detector whose Access Rules are human-readable rather than a black-box model output; and the option to run entirely self-hosted via a periodic obfuscated bundle of the detector. UK-incorporated, EU-processed.

For a full-market comparison see Cloudflare Turnstile alternatives at the CAPTCHA layer and the Forrester Wave 2026 breakdown at the platform layer.

Bot protection use cases

Prosopo scores every layer of the attack surface:

Deploy wherever your traffic lives

One platform, two delivery modes, running the same detection, the same rules and the same dashboard whether the request comes through the widget or the edge enforcement.

  • Widget. Drop-in for any login, signup, checkout, contact form or comment box. The client stack is open source and available on GitHub for a technical review before it goes into production.
  • Edge enforcement. Cloudflare Workers, Lambda@Edge and Fastly Compute@Edge, running verification before requests reach origin.
  • Backend SDK. Node, PHP, Python, Go, Java, Ruby and .NET.
  • API gateway. Verification in front of API endpoints, with a risk score returned on every request for the backend to make its own decisions on.
  • WordPress and CMS plugins. 16 WordPress plugin integrations, including Contact Form 7, Gravity Forms and WPForms.

The privacy posture is a design decision

  • Widget is cookieless by default. No third-party tracking cookies from the widget — nothing to disclose in a customer's cookie banner or privacy notice under the ePrivacy Directive. Edge-mode (Protect) deployments may set first-party session cookies for continuity.
  • Bots profiled cross-site, humans not. The platform catalogues bot toolkits across every customer site so a scraper caught in one place is recognised in another. Human users aren't cross-site profiled, and customer data isn't resold to ad networks or used as a cross-tenant training signal without explicit opt-in.
  • EU-only verification endpoints on request. European customers typically pin to the EU endpoint; US customers can pin verification stateside.
  • UK-incorporated, EU-processed. Full details in the privacy policy.

Talk to the engineers who built the detection

Buyers evaluating vendors are welcome to put Prosopo on the shortlist. A real threat model or an attack log makes the first conversation more concrete than a scripted demo, and the first call is a 30-minute session with an engineer rather than a sales representative.

You will never receive a block you can't explain to your team. — the Prosopo brand promise, and the point of the platform.

Getting started

How to deploy it

Proof-of-concept to production in days rather than months.

1

Step 1: Talk to the engineers

A 30-minute call with a Prosopo engineer, rather than a sales SE or a support-tier handler. Bringing a real threat model or an attack log makes the demo concrete — Prosopo will show what the detector catches on the customer's actual traffic before the pricing conversation begins.

2

Step 2: Integrate

Drop-in widget for forms. Edge deployment on Cloudflare Workers, Lambda@Edge or Fastly Compute@Edge for full-traffic protection. Backend SDKs for Node, PHP, Python, Go, Java, Ruby and .NET.

3

Step 3: Baseline, go live, drill in

Behavioural models baseline the customer's legitimate traffic before enforcement mode is turned on, at which point real users see nothing while every block fires against a rule that can be read in the portal or over the API.

By the numbers

Trusted by companies of all sizes.

Active websites
0+
Monthly verifications
0+
Bots stopped per month
0+
Reviews

Our customers love us.

Hundreds of businesses have made the switch from reCAPTCHA and hCaptcha to Prosopo. Here's what they have to say.

Frequently Asked Questions

What is bot protection?

Bot protection is the security discipline of detecting, scoring and mitigating automated attacks against web and mobile applications. Effective bot protection combines behavioural analysis, device and TLS fingerprinting (JA4), network reputation, adaptive challenges and rules — layered so that if one signal is spoofed, others still catch the attacker. Prosopo delivers this as one platform in two modes: a drop-in widget for form-level protection and invisible enforcement at the edge for full-traffic protection.

What is Bot and Agent Trust Management?

Bot and Agent Trust Management is the category name Forrester adopted in its Q2 2026 Wave, replacing the older 'bot management' term to reflect that AI agents now sit between real humans and unwanted bots. Rather than binary block-or-allow, the discipline is about establishing ongoing trust decisions — allowing authorised agents through, blocking unauthorised automation, and being able to explain the difference to your own team, your customers and your regulators. See the Prosopo comparison against all 8 named vendors on the Forrester Wave breakdown.

How is bot protection different from a CAPTCHA?

A CAPTCHA is a single detection layer — usually a challenge presented to the user. Bot protection is the whole system: silent detection (behavioural, device, network, JA4), adaptive escalation (bring out a challenge only when needed), and integrated response (block, throttle, step-up). Modern bots defeat single-layer CAPTCHAs cheaply through solving farms, so a CAPTCHA alone is no longer sufficient — the detection has to happen before the CAPTCHA fires.

Which vendors does Forrester name in Bot and Agent Trust Management Q2 2026?

The Q2 2026 Forrester Wave named DataDome, HUMAN and Kasada as Leaders; Arkose Labs, CHEQ and Netacea as Strong Performers; and hCaptcha and Google reCAPTCHA Enterprise as Contenders. Prosopo is the specialist entry in the same category — one platform delivered in two modes, with every verdict traceable to a human-readable Access Rule (rather than a black-box model output). See the full comparison in the Forrester Wave 2026 breakdown.

Can Prosopo stop credential stuffing and account takeover?

Yes. Credential stuffing and account takeover are two of the primary threats Prosopo scores. Every login and account-recovery request is scored against behavioural, device, JA4 and network signals — legitimate users pass invisibly, credential-replay infrastructure is throttled or blocked, and every block returns an explainable reason and the signals that fired. See the credential stuffing use case for the full pattern.

Is Prosopo GDPR compliant?

Yes. Prosopo is UK-incorporated and engineered in the UK. The widget is cookieless by default; edge-mode (Protect) deployments may set first-party session cookies for continuity. Human users are not profiled across sites — bot toolkits are catalogued platform-wide, which is how a scraper caught on one customer's site is recognised on another. EU-only verification endpoints available on request; European customers typically pin to the EU endpoint. See the GDPR-compliant CAPTCHA page for the specific data-handling posture.

Can Prosopo run self-hosted?

Yes. The widget stack — challenges, collectors, client-side integration — is open source; you can npm install and read the code before you deploy. The detector on the server side is proprietary; customers who need to run entirely self-hosted receive a periodic obfuscated bundle of the detector so the open-source side stays reproducible and the private side keeps up with the threat model.

More from Prosopo

What else can Prosopo protect for you?

No matter the threat, we have a solution to keep your business safe.

Product

Access Control

Prosopo's Access Control dynamically generates rules to protect your website from bots and spam.

Learn more
Access Control
Product

API Protection

Stop automated abuse of your API endpoints with Prosopo's bot-aware verification and access control.

Learn more
API Protection
Product

Risk Scoring

Prosopo's Risk Scoring provides real-time analysis of user behavior to identify potential threats.

Learn more
Risk Scoring
Product

Spam Bot Protection: Stop Form Spam Before It Lands

Spam bot protection that blocks fake signups, throwaway emails and abusive networks before they hit your forms — without breaking real users' experience.

Learn more
Spam Bot Protection: Stop Form Spam Before It Lands
Product

Bot Protection and Agent Trust Management

Bot protection and Bot and Agent Trust Management by Prosopo. One platform, two delivery modes — widget or edge. Blocks that trace to a human-readable rule.

Learn more
Bot Protection and Agent Trust Management
Product

GDPR-Compliant CAPTCHA

GDPR-compliant CAPTCHA that stores an IP and a short-lived session — no third-party cookies, no cross-site profile, EU processing on request.

Learn more
GDPR-Compliant CAPTCHA
Product

Invisible CAPTCHA

Prosopo's Invisible CAPTCHA provides seamless bot protection without disrupting the user experience.

Learn more
Invisible CAPTCHA