Skip to content

Block the bots your WAF can't see

Centinel detects real-browser automation, residential proxies, and AI scraper APIs so you can see who is accessing your content and decide what to allow.

Centinel dashboard showing human, crawler, unknown, and blocked traffic

Featured by publishers and industry bodies

The scraper gap

Tell real readers from scrapers that look like them

Your CDN and WAF are built for DDoS and known crawlers. A sophisticated crawler that runs a real browser and behaves like a reader slips past them. Centinel closes that gap.

How the layers fit together
A bundle of identical request lines, with one line lifting away from the rest.
  • Your CDN and WAF absorb DDoS attacks
  • Your CDN and WAF block known crawlers and bots
  • Your CDN and WAF filter high-volume abuse
  • Centinel catches stealth crawlers, not just bots
  • Centinel reads behavior across the session
  • Centinel allows or blocks per crawler
How it works

It runs in the stack you already have.

Centinel is a call your edge makes before it serves a page. Cloudflare, CloudFront, Akamai and Fastly each hook it in their own way, and none of them needs anything new in front of your site.

Three points on one line, the middle one live.
  • Install the Centinel package for your platform.
  • Set your Centinel secret key.
  • Deploy. Centinel decides on the next request.

Not running one of those four?

It is the same one call from a reverse proxy, an application, or a CMS.

All 15 integration guides
Detection breadth

Detection across the crawler spectrum

One decision covers the whole range, from a crawler that declares who it is to a managed browser service built to look like a reader.

A row of marks growing from faint to solid across the frame.
  • Declared crawlers: verify known identities and set policy per crawler.
  • Basic scripted clients: identify request automation that does not behave like a browser.
  • Spoofed and headless automation: detect automation that copies browser fingerprints and runtime traits.
  • Browser-like scraping services: separate managed browser scraping from genuine reader sessions.
Security & privacy

Security and privacy, documented

Detection reads request and session signals, not reader profiles. Data is stored in the EU, and our information security is certified to the ISO/IEC 27001 standard.

Trust Center
Concentric rings closing around a single point.
  • ISO/IEC 27001 certified: our information security is certified to the ISO/IEC 27001 standard.
  • GDPR-compliant: we minimize the data used for detection in line with the GDPR.
  • No reader profiling: detection classifies automated traffic; it does not build reader profiles.
  • EU data storage: data is stored in the EU.
Free site audit

See who's crawling your site

No card. No login. No code to change.

FAQ

Common questions

What publishers ask before deployment.

See what your current protection is missing

Request a site audit