Summary
| HUMAN Security | Centinel | |
|---|---|---|
| September 2026 test (8 tools) | 2 of 8 detected | 8 of 8 detected |
| Where it runs | JavaScript sensor, cloud detector, and an enforcer on the app, load balancer, or CDN | Edge, CDN, reverse-proxy, server, and CMS integrations with browser-side checks |
| Buying model | Application Protection licensed by requests per month | Quote from the team after scoping; the site audit is free |
| Data location | Confirm with HUMAN | Data stored in the EU |
HUMAN Security merged with PerimeterX in July 2022, and its bot product is Bot Defender.
The benchmark
In September 2026 we ran eight scraping and browser-automation tools against Centinel and against HUMAN Security: Browser-use, Firecrawl, Browserbase, kernel.sh, Playwright Stealth, Camoufox, Zyte, and Ulixee Hero.
Centinel detected all eight. HUMAN Security detected 2 of 8.
Per-tool detection results
| Scraping tool | Centinel | HUMAN Security |
|---|---|---|
| Browser-use | Detected | Not detected |
| Firecrawl | Detected | Not detected |
| Browserbase | Detected | Detected |
| kernel.sh | Detected | Not detected |
| Playwright Stealth | Detected | Detected |
| Camoufox | Detected | Not detected |
| Zyte | Detected | Not detected |
| Ulixee Hero | Detected | Not detected |
| Detected | 8 / 8 | 2 / 8 |
The table reports detection in the September 2026 test. See the benchmark scope for the tools and products compared. Download the published per-tool results (CSV).
When HUMAN fits better
- You need a prebuilt enforcer for an uncommon platform. HUMAN documents over forty pre-built integrations for its enforcer. Check whether your platform is on that list and on Centinel's.
- You want to license by request volume. HUMAN licenses Application Protection by requests per month. Centinel quotes after a scoping call.
- Your team already runs it well. If Bot Defender covers the routes and automation that cost you, keep it. Add a second layer only where a test shows a gap.
Where Centinel fits
Centinel fits when browser-like automation still reaches a route that matters. In the September test, Centinel detected all eight tools, including Browser-use, Firecrawl, kernel.sh, Camoufox, Zyte, and Ulixee Hero, which HUMAN did not detect.
It also fits teams that need to tell declared crawlers apart. Centinel separates declared and verified crawlers from spoofed or hidden automation, so search engines and approved partners can get a different policy than a scraper using their name. You can check one address with the crawler verification tool.
Feature comparison
| Area | HUMAN Bot Defender (from its documentation) | Centinel |
|---|---|---|
| Architecture | Sensor (JavaScript snippet), Detector (cloud machine-learning risk score), Enforcer (module) | Integration module plus browser-side checks where browser collection is supported |
| Integrations | Over forty pre-built enforcer integrations | 15 documented guides across edge and CDN, reverse proxy and server, application and CMS |
| Challenge | HUMAN Challenge | Challenge where the integration and policy support it |
| Crawler identity | Documents handling of known bots and crawlers | Separates declared and verified crawlers from spoofed ones |
| Responses | Confirm the responses available on your plan | Identify, observe, rate-limit, challenge, allow, or block, depending on the integration |
| Pricing model | Requests per month | Quote after scoping |
| EU and GDPR | Confirm data location with HUMAN | Data stored in the EU; ISO/IEC 27001 certified; assessed against SOC 2 Type 1 |
Sources: HUMAN's Bot Defender overview and pricing documentation. Centinel's guides are on the integrations page; its security posture is in the trust center.
Setup effort and pricing model
Both products install the same way in outline: browser-side collection plus a module on the app, proxy, or CDN that enforces the decision. The effort depends on your stack more than on the vendor. Plan for one engineer who can change that configuration, the owner of the protected workflow, and a rollback path.
HUMAN licenses by requests per month. Centinel quotes per deployment: bring your domain, typical and peak traffic, and current stack. The site audit is free and needs no card.
Migrating from HUMAN
- Pick the routes. List where automation costs the most and which automation you want to keep, such as search crawlers and monitoring.
- Run side by side. Add Centinel in observe mode on those routes while HUMAN's enforcer keeps enforcing. Nothing changes for visitors yet.
- Compare decisions. Review where the two disagree, using the tools above and any workflow you can reproduce safely.
- Move enforcement route by route. Switch one route to Centinel's policy, check legitimate-user completion and error rates, then continue.
- Remove the old enforcer and sensor last. Keep HUMAN in place until each route has run on the new policy long enough to trust it.
The proof-of-concept scorecard turns these steps into a written evaluation plan.
FAQ
Is Centinel a HUMAN Security or PerimeterX alternative?
Yes. PerimeterX merged into HUMAN in 2022, and HUMAN's bot product is Bot Defender. In the September 2026 test, Centinel detected 8 of the 8 tools and HUMAN detected 2.
Can I run Centinel alongside HUMAN?
Yes. Centinel works alongside an existing stack. Run it in observe mode next to HUMAN, compare the decisions, and decide from your own traffic.
Does Centinel publish its prices?
No. Contact the team for current pricing, included usage, and contract terms. The site audit is free.
Where does Centinel store data?
Data is stored in the EU. Centinel is certified to ISO/IEC 27001 and assessed against SOC 2 Type 1.