Skip to content
How it works

Switch Centinel on. Shut the scrapers out. Leave your visitors alone.

Most bot tools hand you a rules engine and wish you luck. Centinel validates the request in under 2 ms, before your page is ever sent.

Request a site audit
What changes

Clear rules for crawler traffic.

You decide which bots can reach your site, page by page. Your CDN or WAF stays where it is.

We know this trade

Scrapers retooled. So did we.

We built the crawlers we now stop. We know the tools, the forums and the economics behind them, so we know what the next version will try before it ships. Detection that cannot move at that speed is already behind.

How scrapers retool
The difference

No single check catches a modern scraper

It takes layers that move faster than the people working around them, and a decision your team never has to make by hand.

  • Protection that holds

    The client-side checks change shape on every build. Getting past them once buys an attacker nothing, because the next request asks a different question.

  • Nothing to manage

    No rules to write, no thresholds to tune, no queue to triage on Monday. The decision arrives already made.

  • Visitors never notice

    The check runs inside the page and finishes in under a second. No CAPTCHA, no puzzle, and it does not run again for the rest of the visit.

The architecture

One call, from the stack you already run

Invisible checks inside the browser, signal analysis at the edge, and nothing new in front of your site. Your own servers never see a blocked request.

Where Centinel plugs into your stack
  1. Your edge

    Sends the request it already has

    A Cloudflare Worker, Lambda@Edge or reverse proxy passes Centinel the headers and connection details it already has. Your own servers are still untouched.

  2. Centinel

    Decides

    Signals from the request and from the browser are scored together, and the request is validated in under 2 ms.

  3. Your edge

    Acts on the answer

    Serve the page, send the visitor to a check, or refuse. Centinel only returns the answer. Your own infrastructure is what talks to the visitor.

Dynamic detection

What the platform is doing while nobody looks at it

  • Invisible signal collection

    467 properties are measured inside the page, before any protected content is sent.

    Catches automation on the first request, without a challenge your visitors can see.

    Read more
  • Client validation

    Everything the client reports is checked for tampering and for the contradictions automation leaves behind.

    Decisions rest on data that has been verified rather than trusted.

    Read more
  • Proof of execution

    The checks run inside an obfuscated virtual machine whose code paths change on every build.

    To answer at all, an attacker has to drive a real browser. That is the expensive part.

    Read more
  • Crawler identity

    More than 1,500 known crawlers are matched by identity, and the ones that declare themselves are checked against the IP ranges their operators publish.

    Googlebot keeps its access. Anything wearing its name does not.

    Read more
Backed by rapid feedback
  • Live analysis

    Every decision feeds an analysis pipeline where bypass attempts surface while they are still being attempted.

    A new evasion is visible to us long before it is profitable to the person running it.

  • Threat intelligence

    We track the scraping tools and the communities that build them, because we used to be in them.

    New sensors ship to every customer at once, not one integration at a time.

    Read more
Start with what matters

Protect the pages scraping costs you most

Usually that is paid content and the pages your customers sign in to.

  • Paid content and downloads
  • Account and signup flows
  • Search and archive pages
  • Comments and community areas
  • Checkout and subscription paths
Start with your site

Want to see what reaches your site?

A site audit shows the crawler families reaching your domain and the pages where you may need more control.