Switch Centinel on. Shut the scrapers out. Leave your visitors alone.
Most bot tools hand you a rules engine and wish you luck. Centinel validates the request in under 2 ms, before your page is ever sent.
Request a site auditClear rules for crawler traffic.
You decide which bots can reach your site, page by page. Your CDN or WAF stays where it is.
Scrapers retooled. So did we.
We built the crawlers we now stop. We know the tools, the forums and the economics behind them, so we know what the next version will try before it ships. Detection that cannot move at that speed is already behind.
How scrapers retoolNo single check catches a modern scraper
It takes layers that move faster than the people working around them, and a decision your team never has to make by hand.
Protection that holds
The client-side checks change shape on every build. Getting past them once buys an attacker nothing, because the next request asks a different question.
Nothing to manage
No rules to write, no thresholds to tune, no queue to triage on Monday. The decision arrives already made.
Visitors never notice
The check runs inside the page and finishes in under a second. No CAPTCHA, no puzzle, and it does not run again for the rest of the visit.
One call, from the stack you already run
Invisible checks inside the browser, signal analysis at the edge, and nothing new in front of your site. Your own servers never see a blocked request.
Where Centinel plugs into your stackYour edge
Sends the request it already has
A Cloudflare Worker, Lambda@Edge or reverse proxy passes Centinel the headers and connection details it already has. Your own servers are still untouched.
Centinel
Decides
Signals from the request and from the browser are scored together, and the request is validated in under 2 ms.
Your edge
Acts on the answer
Serve the page, send the visitor to a check, or refuse. Centinel only returns the answer. Your own infrastructure is what talks to the visitor.
What the platform is doing while nobody looks at it
Invisible signal collection
467 properties are measured inside the page, before any protected content is sent.
Catches automation on the first request, without a challenge your visitors can see.
Read moreClient validation
Everything the client reports is checked for tampering and for the contradictions automation leaves behind.
Decisions rest on data that has been verified rather than trusted.
Read moreProof of execution
The checks run inside an obfuscated virtual machine whose code paths change on every build.
To answer at all, an attacker has to drive a real browser. That is the expensive part.
Read moreCrawler identity
More than 1,500 known crawlers are matched by identity, and the ones that declare themselves are checked against the IP ranges their operators publish.
Googlebot keeps its access. Anything wearing its name does not.
Read more
Live analysis
Every decision feeds an analysis pipeline where bypass attempts surface while they are still being attempted.
A new evasion is visible to us long before it is profitable to the person running it.
Threat intelligence
We track the scraping tools and the communities that build them, because we used to be in them.
New sensors ship to every customer at once, not one integration at a time.
Read more
Protect the pages scraping costs you most
Usually that is paid content and the pages your customers sign in to.
- Paid content and downloads
- Account and signup flows
- Search and archive pages
- Comments and community areas
- Checkout and subscription paths
Want to see what reaches your site?
A site audit shows the crawler families reaching your domain and the pages where you may need more control.