Bot protection — the discipline Forrester renamed to Bot and Agent Trust Management in its Q2 2026 Wave — covers most of what modern security teams need to keep automated attackers out of applications: credential stuffing, scraping (including the AI-training crawlers that ignore robots.txt), inventory hoarding, account takeover, ticket scalping, spam bot submissions, and the newer wave of authorised AI shopping agents that sit somewhere between real humans and the unwanted automation Prosopo is designed to stop.
Ten years ago, bot protection was mostly a CAPTCHA plus an IP blocklist, and in 2026 that combination catches almost nothing worth the name. Stealth headless browsers running on rotating residential proxies pass a CAPTCHA image check in milliseconds, at a fraction of a cent per solve via the various CAPTCHA-solving farms that operate at scale. Serious bot protection needs the whole stack — detection, decision, and (the part every incumbent still keeps behind a wall) the ability to explain why a specific request was blocked in the first place.
If you've been searching for a bot detection service, bot detection website solution or web bot detection provider — those all describe the detection layer of what this page covers. Prosopo runs bot detection continuously against every request that hits a protected endpoint, with the score exposed both to the built-in Decision Machine (which acts on it via Access Rules) and to the customer's own backend (which can act on it however it likes). The detection layer is delivered as a managed service against a proprietary detector, with the client-side collectors open source on GitHub so a technical evaluator can read the code before committing.
Prosopo runs in production against several classes of adversarial-bot workload:
- Ticketing platforms — full-traffic edge deployment against professional ticket-touting bots, including VM-iOS and real-device bot nets.
- Subscription SaaS with free-tier scraping — the copycat-competitor pattern common in face-search, reverse-image, people-search and small-API businesses.
- Crypto-wallet login endpoints — defending against CAPTCHA-solver services attempting account takeover.
| Capability | Prosopo | DataDome | HUMAN | Arkose Labs |
|---|
| Behavioural analysis | ● | ● | ● | ● |
|---|
| Residential-proxy detection | ● | ● | ● | ● |
|---|
| Invisible-first UX (no default challenge) | ● | ● | ● | ● game challenges |
|---|
| EU-hosted processing | ● | ● enterprise | ● | ● |
|---|
| Widget cookieless by default | ● | ● | ● | ● |
|---|
| Blocks trace to a human-readable rule | ● Named Access Rule | ● GenAI summary | ● Sightline view | ● "Telltales" |
|---|
| Raw event stream exportable to your SIEM | ● Datadog / Splunk / Elastic / Sentinel | ● Vendor dashboard | ● Vendor dashboard | ● Vendor dashboard |
|---|
| Agent-aware policy (AI agents) | ● | ● | ● | ● |
|---|
For the full Forrester picture see the 2026 Wave for Bot and Agent Trust Management — DataDome, HUMAN and Kasada were named Leaders. For a CAPTCHA-focused comparison of the whole market, read Cloudflare Turnstile alternatives.
Teams end up on this page from a few different directions. If you searched for Imperva advanced bot protection, PerimeterX (PX) bot protection, AWS WAF bot management or Cloudflare bot management alternatives, Prosopo covers the same category — Forrester's Bot and Agent Trust Management — with three differences the incumbents don't offer: an open-source client stack that a technical evaluator can npm install and read before committing; a proprietary detector whose Access Rules are human-readable rather than a black-box model output; and the option to run entirely self-hosted via a periodic obfuscated bundle of the detector. UK-incorporated, EU-processed.
For a full-market comparison see Cloudflare Turnstile alternatives at the CAPTCHA layer and the Forrester Wave 2026 breakdown at the platform layer.
Prosopo scores every layer of the attack surface:
One platform, two delivery modes, running the same detection, the same rules and the same dashboard whether the request comes through the widget or the edge enforcement.
- Widget. Drop-in for any login, signup, checkout, contact form or comment box. The client stack is open source and available on GitHub for a technical review before it goes into production.
- Edge enforcement. Cloudflare Workers, Lambda@Edge and Fastly Compute@Edge, running verification before requests reach origin.
- Backend SDK. Node, PHP, Python, Go, Java, Ruby and .NET.
- API gateway. Verification in front of API endpoints, with a risk score returned on every request for the backend to make its own decisions on.
- WordPress and CMS plugins. 16 WordPress plugin integrations, including Contact Form 7, Gravity Forms and WPForms.
- Widget is cookieless by default. No third-party tracking cookies from the widget — nothing to disclose in a customer's cookie banner or privacy notice under the ePrivacy Directive. Edge-mode (Protect) deployments may set first-party session cookies for continuity.
- Bots profiled cross-site, humans not. The platform catalogues bot toolkits across every customer site so a scraper caught in one place is recognised in another. Human users aren't cross-site profiled, and customer data isn't resold to ad networks or used as a cross-tenant training signal without explicit opt-in.
- EU-only verification endpoints on request. European customers typically pin to the EU endpoint; US customers can pin verification stateside.
- UK-incorporated, EU-processed. Full details in the privacy policy.
Buyers evaluating vendors are welcome to put Prosopo on the shortlist. A real threat model or an attack log makes the first conversation more concrete than a scripted demo, and the first call is a 30-minute session with an engineer rather than a sales representative.
You will never receive a block you can't explain to your team. — the Prosopo brand promise, and the point of the platform.