Block the bots your WAF can't see
Centinel detects real-browser automation, residential proxies, and AI scraper APIs so you can see who is accessing your content and decide what to allow.

Tell real readers from scrapers that look like them
Your CDN and WAF are built for DDoS and known crawlers. A sophisticated crawler that runs a real browser and behaves like a reader slips past them. Centinel closes that gap.
How the layers fit together
- Your CDN and WAF absorb DDoS attacks
- Your CDN and WAF block known crawlers and bots
- Your CDN and WAF filter high-volume abuse
- Centinel catches stealth crawlers, not just bots
- Centinel reads behavior across the session
- Centinel allows or blocks per crawler
It runs in the stack you already have.
Centinel is a call your edge makes before it serves a page. Cloudflare, CloudFront, Akamai and Fastly each hook it in their own way, and none of them needs anything new in front of your site.

- Install the Centinel package for your platform.
- Set your Centinel secret key.
- Deploy. Centinel decides on the next request.
Not running one of those four?
It is the same one call from a reverse proxy, an application, or a CMS.
All 15 integration guides- Apache HTTP Server guide (opens in a new tab)
- HAProxy guide (opens in a new tab)
- Nginx / OpenResty guide (opens in a new tab)
- Varnish guide (opens in a new tab)
- ASP.NET Core guide (opens in a new tab)
- Azure Functions guide (opens in a new tab)
- Next.js guide (opens in a new tab)
- Drupal 7 guide (opens in a new tab)
- Drupal 8+ guide (opens in a new tab)
- WordPress guide (opens in a new tab)
Detection across the crawler spectrum
One decision covers the whole range, from a crawler that declares who it is to a managed browser service built to look like a reader.

- Declared crawlers: verify known identities and set policy per crawler.
- Basic scripted clients: identify request automation that does not behave like a browser.
- Spoofed and headless automation: detect automation that copies browser fingerprints and runtime traits.
- Browser-like scraping services: separate managed browser scraping from genuine reader sessions.
Security and privacy, documented
Detection reads request and session signals, not reader profiles. Data is stored in the EU, and our information security is certified to the ISO/IEC 27001 standard.
Trust Center
- ISO/IEC 27001 certified: our information security is certified to the ISO/IEC 27001 standard.
- GDPR-compliant: we minimize the data used for detection in line with the GDPR.
- No reader profiling: detection classifies automated traffic; it does not build reader profiles.
- EU data storage: data is stored in the EU.
See who's crawling your site
No card. No login. No code to change.
Understand the crawlers hitting your site
Common questions
What publishers ask before deployment.



