Skip to content
Use case

Keep bot floods from taking your site down

A flood of automated requests can do the same damage as a DDoS attack, whether or not anyone meant it as one. Every request still has to be served, scored, and paid for.

Request a site audit
Why it matters

57% of web requests

are now automated, per Cloudflare's own network data: bot traffic passed human traffic for the first time in mid-2026. A flood does not need to be labeled an attack to take a site down. Origin infrastructure sized for real visitors still has to answer every one of them, until it cannot.

Read the research (opens in a new tab)
How it works against you

What the traffic looks like

  • No coordination required

    A flood does not need a botnet commanding it. One scraper running too aggressively, or a dozen unrelated ones overlapping, produces the same spike.

  • Retries that make it worse

    A blocked or slow request often gets retried automatically, so the first sign of trouble multiplies the traffic instead of reducing it.

  • Volume built to look ordinary

    Spread across enough IPs and sessions, a flood can look like a normal traffic spike until the origin falls over.

How Centinel closes it

What runs against this traffic

  • Invisible signal collection

    467 properties are measured inside the page before any protected content is sent.

    Automated traffic is identified before it reaches your origin, not after your infrastructure notices the spike.

    Read more
  • Decisions made at the edge

    Each request is scored and answered in under 2 ms, at the edge, before it reaches your servers.

    A flood gets absorbed at the edge. Your origin only ever sees the traffic you decided to let through.

    Read more
Start with your site

Want to see what reaches your site?

A site audit shows the crawler families reaching your domain and the pages where you may need more control.