Block the bots your WAF can't see
Centinel detects real-browser automation, residential proxies, and AI scraper APIs so you can see who is accessing your content and decide what to allow.

Tell real visitors from scrapers that look like them
Your CDN and WAF are built for DDoS and known crawlers. A sophisticated crawler that runs a real browser and behaves like a visitor slips past them. Centinel closes that gap.
How the layers fit together
- Your CDN and WAF absorb DDoS attacks
- Your CDN and WAF block known crawlers and bots
- Your CDN and WAF filter high-volume abuse
- Centinel catches stealth crawlers, not just bots
- Centinel reads behavior across the session
- Centinel allows or blocks per crawler
It runs in the stack you already have.
Centinel is a call your edge makes before it serves a page. Cloudflare, CloudFront, Akamai and Fastly each hook it in their own way, and none of them needs anything new in front of your site.

- Install the Centinel package for your platform.
- Set your Centinel secret key.
- Deploy. Centinel decides on the next request.
Not running one of those four?
It is the same one call from a reverse proxy, an application, or a CMS.
All 15 integration guides- Apache HTTP Server guide (opens in a new tab)
- HAProxy guide (opens in a new tab)
- Nginx / OpenResty guide (opens in a new tab)
- Varnish guide (opens in a new tab)
- ASP.NET Core guide (opens in a new tab)
- Azure Functions guide (opens in a new tab)
- Next.js guide (opens in a new tab)
- Drupal 7 guide (opens in a new tab)
- Drupal 8+ guide (opens in a new tab)
- WordPress guide (opens in a new tab)
Every shape automated traffic takes
Same platform, same sub-2 ms decision, a different question asked of the request for each one.
Scraping & AI crawlers
Bots read your pages, copy your pricing and archives, and feed AI models, all before a human visitor ever shows up in your analytics.
Learn moreAccount takeover
Attackers replay usernames and passwords stolen from other breaches against your login form, hoping a few pairs still work.
Learn moreCheckout & carding fraud
Attackers run stolen card numbers through your checkout to see which ones still work, then use the ones that clear.
Learn morePromo abuse & multi-accounting
Free trials, referral bonuses and promo codes all assume one person equals one account. Bots create as many accounts as it takes to break that assumption.
Learn moreAPI abuse
Mobile apps, partner integrations and backend services call your API directly. None of them load a page, so a browser-only check never runs.
Learn moreDDoS & traffic floods
A flood of automated requests can do the same damage as a DDoS attack, whether or not anyone meant it as one. Every request still has to be served, scored, and paid for.
Learn more
Detection across the crawler spectrum
One decision covers the whole range, from a crawler that declares who it is to a managed browser service built to look like a visitor.

- Declared crawlers: verify known identities and set policy per crawler.
- Basic scripted clients: identify request automation that does not behave like a browser.
- Spoofed and headless automation: detect automation that copies browser fingerprints and runtime traits.
- Browser-like scraping services: separate managed browser scraping from genuine visitor sessions.
Security and privacy, documented
Detection reads request and session signals, not visitor profiles. Data is stored in the EU, and our information security is certified to the ISO/IEC 27001 standard.
Trust Center
- ISO/IEC 27001 certified: our information security is certified to the ISO/IEC 27001 standard.
- GDPR-compliant: we minimize the data used for detection in line with the GDPR.
- No visitor profiling: detection classifies automated traffic; it does not build visitor profiles.
- EU data storage: data is stored in the EU.
See who's crawling your site
No card. No login. No code to change.
Understand the crawlers hitting your site
Common questions
What site owners ask before deployment.



