For security teams
Stop the bots. Keep the humans.
Free forever: unlimited widgets and verifications, no card.
- Humanity score on every check
- 1–100
- Cookies and trackers
- 0
- JavaScript bundle
- <15KB
- Unlimited widgets, forever
- Free
The abuse you’re paged about
Same targets, every site
- 01
Credential stuffing against the login page.
Scripted traffic floors the humanity score. Step up or block on your thresholds before a request reaches your authentication layer.
- 02
Fake accounts arriving faster than you can clean them out.
Protect registration invisibly. Genuine new users see nothing; farms of throwaway signups don’t get a token.
- 03
Scrapers lifting your content and pricing.
Tell humans, declared AI agents and undeclared automation apart — and give each its own policy instead of a blanket block.
- 04
Spam in contact forms, comments and reviews.
Tokens are single-use and expire after five minutes, so replayed and farmed tokens fail by design.
Edge Shield
Built for how security teams actually work
A score, not a verdict
Your thresholds, not ours
- Invisible to humans: proof-of-work and environment signals, no image puzzles
- The score refines as the visitor types and moves, before the form is sent
- Shadow mode trials enforcement on live traffic without blocking anyone
- Auto-approved
- 573
- Step-up
- 67
- Blocked
- 360
// your server, after siteverify if (!success) reject() else if (agent?.verified) routeToApi() else if (score >= 70) allow() else if (score >= 40) stepUp() else block()
Privacy by construction
Nothing to consent to, because nothing is collected
- No cookies, local storage or fingerprint database
- GDPR and CCPA friendly by default, not by configuration
- No visual puzzles to fail an accessibility audit — WCAG 2.2 AA
Verified AI agents
Route good agents instead of blocking customers
- Web Bot Auth signatures and reverse-DNS checks for known crawlers
- The score stays honest; the agent field tells you who it is
- Anonymous automation is always treated aggressively
Drop-in migration
Leave reCAPTCHA or Turnstile without a rewrite
- Compatibility mode fills the cf-turnstile-response field during the switch
- Familiar error codes such as timeout-or-duplicate
- Fixed test secrets so CI exercises every branch
Expert services
Migrate without a protection gap
We’ll also analyse your traffic and recommend humanity-score thresholds for auto-approve, step-up and block that fit your risk profile.
What usually brings teams to us
- An accessibility audit flagged the CAPTCHA.
- Legal wants to know what the CAPTCHA provider does with visitor data.
- Bots sign up faster than anyone can clean them out.
- AI agents are real customers now, and they need routing, not blocking.
Security across the whole platform
Shield guards the front door. The platform guards the rest.
DDoS absorption
Malicious traffic is absorbed and filtered across the global network before it reaches your origin.
Full audit trail
Every action on the account — by a person, a pipeline or an agent — is logged with who, when and from where.
Scoped credentials
API keys with expiry; agent access codes with per-product permissions, budget caps and instant revocation.
Encryption everywhere
TLS 1.3 in transit and AES-256 at rest, with regularly rotated keys as standard.
Recommended products
Where to start
Shield
Humanity scores, verified agents and zero puzzles. Free, with no verification caps.
CDN
Attacks absorbed at the edge, TLS 1.3 by default, and password protection for staging.
DNS
Managed DNS with an audit trail for every record change. Free.
In production: Peri Happy runs Shield to keep bots off its signup and AI-planner endpoints — with no dedicated ops team.
Read the case studyProtect your first form in five minutes
Two snippets on the page, one call on your server, free forever. See what your traffic really looks like.
Unlimited widgets and verifications. No card, no plans, no caps.