Block the bots your WAF can't see
Centinel detects real-browser automation, residential proxies, and AI scraper APIs so you can see who is accessing your content and decide what to allow.

Tell real visitors from scrapers that look like them
Your CDN and WAF are built for DDoS and known crawlers. A sophisticated crawler that runs a real browser and behaves like a visitor slips past them. Centinel closes that gap.
How the layers fit together
- Your CDN and WAF absorb DDoS attacks
- Your CDN and WAF block known crawlers and bots
- Your CDN and WAF filter high-volume abuse
- Centinel catches stealth crawlers, not just bots
- Centinel reads behavior across the session
- Centinel allows or blocks per crawler
It runs in the stack you already have.
Centinel is a call your edge makes before it serves a page. Cloudflare, CloudFront, Akamai and Fastly each hook it in their own way, and none of them needs anything new in front of your site.

- Install the Centinel package for your platform.
- Set your Centinel secret key.
- Deploy. Centinel decides on the next request.
Not running one of those four?
It is the same one call from a reverse proxy, an application, or a CMS.
All 15 integration guides- Apache HTTP Server guide (opens in a new tab)
- HAProxy guide (opens in a new tab)
- Nginx / OpenResty guide (opens in a new tab)
- Varnish guide (opens in a new tab)
- ASP.NET Core guide (opens in a new tab)
- Azure Functions guide (opens in a new tab)
- Next.js guide (opens in a new tab)
- Drupal 7 guide (opens in a new tab)
- Drupal 8+ guide (opens in a new tab)
- WordPress guide (opens in a new tab)
Every shape automated traffic takes
The route and the client change what you need to inspect, what could go wrong, and which response makes sense.
Scraping & AI crawlers
Some crawlers identify themselves. Others use real browsers, residential networks, or copied identities to resemble ordinary visitors.
Learn moreAccount takeover
Credential-stuffing tools can replay exposed username and password pairs at scale. The login still needs its normal authentication and account-security controls.
Learn moreCheckout & carding fraud
Automated card testing can repeat payment attempts through a valid checkout flow. Bot evidence adds context before the payment provider makes its own fraud decision.
Learn morePromo abuse & multi-accounting
Automated sign-up flows can rotate submitted details and browser profiles. Bot evidence helps enforce an offer policy without claiming to resolve a person's identity.
Learn moreAPI abuse
Mobile apps, partner integrations, and backend services may call an API without loading a page. Those requests need a policy built from the evidence the server integration actually receives.
Learn moreDDoS & traffic floods
Aggressive crawlers and distributed automation can consume application capacity. Centinel complements rather than replaces volumetric DDoS protection.
Learn more
Detection across the crawler spectrum
One decision covers the whole range, from a crawler that declares who it is to a managed browser service built to look like a visitor.

- Declared crawlers: verify known identities and set policy per crawler.
- Basic scripted clients: identify request automation that does not behave like a browser.
- Spoofed and headless automation: detect automation that copies browser fingerprints and runtime traits.
- Browser-like scraping services: separate managed browser scraping from genuine visitor sessions.
Security and privacy, documented
Detection reads request and session signals, not visitor profiles. Data is stored in the EU, and our information security is certified to the ISO/IEC 27001 standard.
Trust Center
- ISO/IEC 27001 certified: our information security is certified to the ISO/IEC 27001 standard.
- GDPR-compliant: we minimize the data used for detection in line with the GDPR.
- No visitor profiling: detection classifies automated traffic; it does not build visitor profiles.
- EU data storage: data is stored in the EU.
See who's crawling your site
No card. No login. No code to change.
Common questions
What site owners ask before deployment.



