Prosopo blocks the automated attacks that most directly impact revenue, security and user trust:
- Credential stuffing and account takeover on login and password-reset flows.
- Scraping by AI-training crawlers, price aggregators and look-alike competitors.
- Ticket scalping toolkits on high-demand on-sales.
- Denial of inventory that reserves stock across sneaker drops and limited releases.
- Spam form submissions and disposable-email signups.
- Unwanted AI shopping agents that sit between real humans and the automation you don't want.
A decade ago, a CAPTCHA and an IP blocklist were sufficient. Today they are not. Stealth headless browsers on rotating residential proxies pass an image CAPTCHA in milliseconds, at fractions of a cent, via CAPTCHA-solving farms that operate at industrial scale. Effective bot protection now requires continuous silent detection, adaptive challenges applied only when the risk score demands it, and a clear, auditable reason for every request that is blocked.
Three inspectable layers, in order.
First, a library of named detectors that fires against pattern-matches in the traffic. Signals combined include JA4 TLS fingerprinting, DNS resolver observation, iOS App Attest, Android Play Integrity, stealth-headless-browser detection, residential-proxy classification, cursor and scroll behaviour, and SIMD-CPU signatures. When a detector fires, the block response names it. A few real examples of what the platform catches, with the underlying technical string in each case:
| What it catches | Underlying detector string |
|---|
| Apple hardware spoofing — a bot claims Safari-on-macOS in the User-Agent but the CPU behaves like Android or Linux | SIMD timings inconsistent with claimed Apple hardware |
| Known CAPTCHA-solver service — request pattern matches the fingerprint of a commercial solving service | 2Captcha solver detected |
| Synthetic mouse-event timings — mouse-move rhythm no human keyboard-and-mouse produces | Synthetic mouse-event timing pattern |
| HTTP header fingerprint mismatch — client-hints headers don't agree with the claimed User-Agent | User-Agent and sec-ch-ua-platform mismatch |
| Malformed HTTP header signature — request headers no real browser would emit | accept-language contains duplicate q-parameter |
Second, your own Access Rules layer on top for policy the default detectors don't yet cover — block a specific ASN pattern, gate a country on a checkout endpoint, whitelist a partner IP range. Third, in Prosopo Protect, an ML model scores request intent across the human / agent / bot boundary — the layer that decides whether an agentic browser is acting on behalf of a real customer or automating abuse.
Every layer surfaces a readable trigger on a block. Real users pass invisibly. Suspicious sessions get a proof-of-work, puzzle or image challenge. Known-bad traffic never reaches your servers.
Live examples of what Prosopo is protecting in production today:
- Ticketing platforms. Full-traffic edge deployment against professional ticket-touting bots, including VM-iOS and real-device botnets.
- Subscription SaaS with free-tier scraping. The look-alike competitor pattern common in face-search, reverse-image, people-search and small-API businesses.
- Crypto-wallet login endpoints. Blocking CAPTCHA-solver services attempting account takeover.
| Capability | Prosopo | DataDome | HUMAN | Arkose Labs |
|---|
| Behavioural analysis | ● | ● | ● | ● |
|---|
| Residential-proxy detection | ● | ● | ● | ● |
|---|
| Invisible-first UX (no default challenge) | ● | ● | ● | ● game challenges |
|---|
| EU-hosted processing | ● | ● enterprise | ● | ● |
|---|
| Widget cookieless by default | ● | ● | ● | ● |
|---|
| Named detector reason on every block | ● Technical string | ● GenAI summary | ● Sightline view | ● "Telltales" |
|---|
| Raw event stream exportable to your SIEM | ● Datadog / Splunk / Elastic / Sentinel | ● Vendor dashboard | ● Vendor dashboard | ● Vendor dashboard |
|---|
| Agent-aware policy (AI agents) | ● | ● | ● | ● |
|---|
For a CAPTCHA-layer comparison across the wider market, see Cloudflare Turnstile alternatives.
Evaluating Cloudflare Bot Management, Imperva Advanced Bot Protection, AWS WAF Bot Control or HUMAN Bot Defender (formerly PerimeterX)? Three reasons teams pick Prosopo instead:
- Open source you can inspect. The base captcha is published on GitHub, so your security team can review the client-side code before adoption.
- Rules you can name. Every block traces back to a human-readable Access Rule in your dashboard, not to a black-box model score you cannot audit.
- A self-hosted option. If you need to run the platform fully on your own infrastructure, an obfuscated bundle of the advanced detection layers is available so no data has to leave your network.
All UK-incorporated, EU-processed, and available on a free tier so the fundamentals are not restricted to enterprise contracts.
Same detection stack, same rules, same dashboard, wherever it runs:
- Edge enforcement. The primary mode for whole-site coverage. Verifies on Cloudflare Workers, AWS Lambda@Edge or Fastly Compute@Edge before requests reach your origin.
- Backend SDK. For stacks without an edge worker. Node, PHP, Python, Go, Java, Ruby and .NET.
- API gateway. In front of your APIs, returning a risk score on every request so your backend can decide what to do.
- Drop-in widget. For form-level protection: login, signup, checkout, contact, comment. Open source on GitHub for a code review before it goes live.
- WordPress and CMS plugins. 16 WordPress integrations, including Contact Form 7, Gravity Forms and WPForms.
- Cookieless widget by default. Nothing to add to your cookie banner under the ePrivacy Directive. Edge-mode deployments may set first-party session cookies for session continuity only.
- Fits GDPR, CCPA and HIPAA programmes. A Data Processing Agreement is available for enterprise customers, and your data is never resold to ad networks or used as a cross-tenant training signal without your opt-in.
- Bots profiled cross-site, real users are not. A scraper we spot on one customer's site is blocked when it shows up on yours; real users are never cross-site tracked.
- EU-only or US-only verification endpoints on request. Pick the region your verification data is processed in.
- UK-incorporated, EU-processed. Full details in the privacy policy.
Ready to evaluate? Bring an attack log or your threat model to the first call. The demonstration is far more useful when it runs against your own traffic than against a scripted one, and the first call is 30 minutes with a Prosopo engineer, not a sales representative.