CDNs and WAFs bundle useful bot controls with delivery and application-security products. Centinel is not a replacement for either layer. It adds behavioral classification when your crawler policy needs to depend on signals observed across a session.
Different signals, different decisions
CDN and WAF bot products use different combinations of identity, reputation, request, browser, and behavior signals. Review the controls enabled in your deployment before deciding whether you need an additional crawler-management layer.
Stealth crawlers use real browser sessions, residential or rotating networks, and ordinary-looking navigation to scrape content while posing as readers. The signals that separate them from a real audience are often distributed across the session rather than present in one request.
Centinel classifies those sessions by behavior. It evaluates how the connection, browser, request, and browsing signals fit together, then applies your access policy at the edge.
Where the approaches differ
| Decision point | Centinel | What to check in your CDN or WAF deployment |
|---|---|---|
| Primary decision signal | Behavioral consistency across each session. | Which signals and rules are enabled. |
| Stealth crawlers | Designed to classify browser-like crawler sessions that conceal their identity. | Whether browser-like sessions can be distinguished without blocking readers. |
| Declared crawlers | Policy can be set per crawler after verification. | Whether policy can be set per verified crawler. |
| Crawler visibility | Separates human, identified crawler, and stealth crawler activity for access decisions. | Which crawler classes appear in reporting. |
| Operations | Managed detection updates as crawler tactics change. | How detection updates and policy changes are maintained. |
| Deployment | Runs beside the CDN and WAF you already use. | How the controls fit the delivery and security stack. |
Fine-grained control starts with visibility
Known crawlers still need a decision. You may want a search crawler to index your pages while blocking a training bot, a commercial scraper, or an unverified agent that uses the same broad category.
Centinel keeps crawler identities and traffic visible at the individual-agent level. That lets commercial, editorial, and engineering teams decide from the same evidence instead of using a blanket allow or block policy.
Keep the security layer; add the access layer
Keep the CDN and WAF for delivery and application security. Use Centinel when crawler policy needs to depend on a session's classification.
