Skip to content

For security teams

Stop the bots. Keep the humans.

Edge Shield returns a 1–100 humanity score on every check, so you can write real policy instead of guessing. No puzzles for your users, no tracking for legal to worry about, and no invoice.

Free forever: unlimited widgets and verifications, no card.

Humanity score on every check
1–100
Cookies and trackers
0
JavaScript bundle
<15KB
Unlimited widgets, forever
Free

The abuse you’re paged about

Same targets, every site

Automated abuse goes after logins, signups, forms and content. Shield sits in front of all four — invisibly for the people you want to keep.
  1. 01

    Credential stuffing against the login page.

    Scripted traffic floors the humanity score. Step up or block on your thresholds before a request reaches your authentication layer.

  2. 02

    Fake accounts arriving faster than you can clean them out.

    Protect registration invisibly. Genuine new users see nothing; farms of throwaway signups don’t get a token.

  3. 03

    Scrapers lifting your content and pricing.

    Tell humans, declared AI agents and undeclared automation apart — and give each its own policy instead of a blanket block.

  4. 04

    Spam in contact forms, comments and reviews.

    Tokens are single-use and expire after five minutes, so replayed and farmed tokens fail by design.

Edge Shield

Built for how security teams actually work

A signal you can build policy on — not a black box that silently drops your traffic.

A score, not a verdict

Your thresholds, not ours

Every verification returns a humanity score from 1 (confirmed automation) to 100 (confirmed human). Decide where auto-approve ends, where step-up starts and what you block — then tune it as your traffic changes. Try it.
  • Invisible to humans: proof-of-work and environment signals, no image puzzles
  • The score refines as the visitor types and moves, before the form is sent
  • Shadow mode trials enforcement on live traffic without blocking anyone
Your policy · signup formIllustrative day · 1,000 attempts
Auto-approved
573
Step-up
67
Blocked
360
// your server, after siteverify
if (!success) reject()
else if (agent?.verified) routeToApi()
else if (score >= 70) allow()
else if (score >= 40) stepUp()
else block()

Privacy by construction

Nothing to consent to, because nothing is collected

No cookies, no fingerprinting, no per-visitor data. Signals are scored in memory and discarded; the only thing kept is hourly counters. Your privacy policy doesn’t need a section about bot protection.
  • No cookies, local storage or fingerprint database
  • GDPR and CCPA friendly by default, not by configuration
  • No visual puzzles to fail an accessibility audit — WCAG 2.2 AA

Verified AI agents

Route good agents instead of blocking customers

Shopping, booking and research agents act for real people. Agents that sign their requests with Web Bot Auth are identified cryptographically — not guessed from a user-agent string — and each widget decides whether to allow, challenge or block them.
  • Web Bot Auth signatures and reverse-DNS checks for known crawlers
  • The score stays honest; the agent field tells you who it is
  • Anonymous automation is always treated aggressively

Drop-in migration

Leave reCAPTCHA or Turnstile without a rewrite

Same sitekey-and-secret model, Turnstile-compatible response fields and familiar siteverify semantics. Swap the widget, change one server-side call, and existing error handling carries over.
  • Compatibility mode fills the cf-turnstile-response field during the switch
  • Familiar error codes such as timeout-or-duplicate
  • Fixed test secrets so CI exercises every branch

Expert services

Migrate without a protection gap

Moving off reCAPTCHA, Turnstile or hCaptcha? Our engineers swap the widgets, update your server-side validation and verify every form — typically inside 48 hours, with no unprotected window.

We’ll also analyse your traffic and recommend humanity-score thresholds for auto-approve, step-up and block that fit your risk profile.

What usually brings teams to us

  • An accessibility audit flagged the CAPTCHA.
  • Legal wants to know what the CAPTCHA provider does with visitor data.
  • Bots sign up faster than anyone can clean them out.
  • AI agents are real customers now, and they need routing, not blocking.

Security across the whole platform

Shield guards the front door. The platform guards the rest.

Every Edge product ships with security defaults your team doesn’t have to bolt on afterwards.
Platform security overview
  • DDoS absorption

    Malicious traffic is absorbed and filtered across the global network before it reaches your origin.

  • Full audit trail

    Every action on the account — by a person, a pipeline or an agent — is logged with who, when and from where.

  • Scoped credentials

    API keys with expiry; agent access codes with per-product permissions, budget caps and instant revocation.

  • Encryption everywhere

    TLS 1.3 in transit and AES-256 at rest, with regularly rotated keys as standard.

Protect your first form in five minutes

Two snippets on the page, one call on your server, free forever. See what your traffic really looks like.

Unlimited widgets and verifications. No card, no plans, no caps.