Sense
Sign inBook a demo
Bot Detection · web and API traffic

Tell a real customer from a script, in real time.

Sense scores every request at the edge on behaviour, browser fingerprinting, network and intent — credential stuffing, card testing, scraping and checkout bots are stopped before they cost you, and real customers never see a CAPTCHA.

Book a demo
63%of requests were automated last month
8 msadded at the edge, p99
1,412features scored per session
SENSE EDGE · yourshop.in42,800 req/min
12447193
BOT SCOREscored in 8ms
at the edge
POST /loginheadless chrome · 0ms mouse travel
BLOCK
POST /payments/authorise312 cards · ₹1 each · 4 ASNs
BLOCK
GET /catalogue?page=*residential proxy · 900 req/min
THROTTLE
POST /checkoutarjun · returning session · human cadence
ALLOW
GET /sitemap.xmlverified search crawler
ALLOW
AUTOMATED SHARE63%
TO YOUR STACK
Verdict on the request, not five minutes laterscore + reason codes on the header · 8ms p99
No CAPTCHA shown
01 Signals02 Decision03 Behavioural profiles04 Adaptive auth
Signals → score → action, in one round trip
HOW IT WORKS

Four signal families, one score.

Fingerprints alone are a rented answer — attackers buy real browsers, real IPs and real cookies. Sense combines what the client is with how it behaves and what it is trying to do, so a bot that looks perfect still fails on intent.

01BehaviourPointer travel, keystroke cadence, scroll physics, form dwell — human motion has noise, scripts do not.
02Browser environmentHeadless artefacts, patched APIs, canvas and font entropy, automation drivers and spoofed user agents.
03Network & reputationResidential and mobile proxy pools, datacentre ASNs, TLS and HTTP/2 fingerprints, IP rotation patterns.
04Intent & velocityWhat the session is reaching for: login attempts per identity, ₹1 card tests, cart holds, catalogue sweeps.
SIGNAL COLLECTOR1,412 features
CLIENTHeadless flagsPatched navigatorCanvas entropyTLS / JA4 hash
SESSIONPointer entropyKeystroke cadenceProxy pool matchIdentity fan-out
Automation driver present+38
Residential proxy rotation+27
No pointer entropy before submit+18
140 identities, one browser fingerprint+10
01 · SIGNALS

A bot can rent a browser. It cannot rent a habit.

Automation now ships with real Chrome, residential IPs and warmed cookies, so single-signal defences fold. Sense reasons across families — expensive bots still fail on behaviour.

Passive collection, no challenge
Nothing is shown to the user — no CAPTCHA, no interstitial, no added click on the happy path.
Web pages and raw API alike
A JS tag on your pages, and request-level signals for headless clients that never render one.
Reason codes, not a black box
Every score arrives with the signals that drove it, so your fraud team can defend the decision.
Adapts as the attacker retools
Models retrain on your traffic; new automation kits are covered without a release from you.
02 · DECISION

Block, throttle or challenge — your call, per route.

A scraper on your catalogue and a stuffing run on your login deserve different answers. Sense returns a score and reason codes; you set each route's action from the dashboard.

Enforce at the edge or in your app
Return a verdict at the CDN worker, or take the score in your own service and act on it.
Silent friction for the grey zone
Rate-limit, serve cached prices, hold the cart or step up — instead of a hard block on a maybe.
Good bots stay welcome
Verified search crawlers, partner integrations and your own monitors are allow-listed by identity, not user agent.
DECISION LOG · LAST 60 SECONDSlive
/login · credential stuffing runscore 93BLOCK
/payments · card testingscore 88BLOCK
/catalogue · price crawlerscore 71THROTTLE
/signup · grey-zone sessionscore 54STEP UP
/checkout · returning customerscore 12ALLOW
// what your edge worker sees
x-sense-score: 93
x-sense-reasons: automation_driver, proxy_pool, no_pointer_entropy
x-sense-action: block
Requests scored today812M
03 · BEHAVIOURAL PROFILES

Every session leaves a behavioural profile. Most of them are not human.

Sense does not start from a list of known attacks — it builds a profile of how the session moves, types, waits and navigates, then places it against the profiles it already knows. Five recur across Indian commerce, lending and BFSI traffic.

PROFILEHOW THE SESSION BEHAVESWHAT SEPARATES IT FROM A HUMANTYPICAL VERDICT
Scripted credential replay
HOW IT BEHAVESA form filled in a single tick, submitted without a pause, repeated across thousands of identities from rotating residential IPs.
WHAT SEPARATES ITHumans hesitate, correct themselves and move a pointer. This profile has no dwell, no correction and no motion noise.
TYPICAL VERDICTBlocked at /login
Payment probing
HOW IT BEHAVESSmall authorisations in bursts across many BINs, fresh sessions with warmed cookies, high decline tolerance.
WHAT SEPARATES ITReal customers pay once and leave. This profile retries through failure at machine cadence and never browses.
TYPICAL VERDICTBlocked at /payments
Catalogue harvesting
HOW IT BEHAVESPages walked in strict order at even intervals, no scroll physics, traffic that swells whenever prices change.
WHAT SEPARATES ITReading is uneven. This profile requests at a metronome and never lingers on anything.
TYPICAL VERDICTThrottled or served cached
Release rushing
HOW IT BEHAVESCarts held on limited stock within a second of release, checkout completed faster than the page can be read.
WHAT SEPARATES ITA person cannot decide and pay in under two seconds. This profile is waiting on a timer, not on a page.
TYPICAL VERDICTCart held, queue enforced
Checkout replay and card testing
HOW IT BEHAVESPayment pages driven by a headless runtime with patched native functions, replaying checkout to find cards that still authorise.
WHAT SEPARATES ITA rendered page reports what a request header cannot: spoofed environments, patched DOM functions and automation driver artefacts.
TYPICAL VERDICTBlocked before the gateway is called
Account farming
HOW IT BEHAVESSignup after signup with disposable identities, identical form paths, one browser fingerprint behind hundreds of them.
WHAT SEPARATES ITGenuine signups vary in typing, order and pace. This profile repeats itself exactly.
TYPICAL VERDICTBlocked at /signup
PROFILES, NOT SIGNATURESA retooled kit changes its fingerprint overnight. It does not change the fact that it has no hesitation before submit.
HUMANS PROFILE TOOReturning customers build a profile of their own, so a familiar session clears without ever being asked anything.
READABLE BY YOUR TEAMEach profile arrives named, with the behaviours that placed the session in it — reviewable, not a bare number.
04 · ADAPTIVE AUTHENTICATION

The risk signal RBI's adaptive authentication rules assume you already have.

The Authentication Mechanisms for Digital Payment Transactions Directions, 2025 keep two factors as the floor and, from 1 April 2026, let issuers add risk-based checks on top, sized to the fraud risk of the transaction in front of them. Net banking journeys carry that risk before the payment does — at login, at payee addition, at reset. Sense supplies the session-level judgement those checks need.

WHAT THE DIRECTIONS EXPECTWHAT SENSE CONTRIBUTES
Two factors as the floor2FA remains mandatory for digital payment transactions.
Sense replaces nothing. Your existing factors keep running; the score decides whether anything more is asked.
Risk-based checks above the minimumIssuers may add checks sized to the fraud risk of the transaction.
A 0-100 session score with reason codes, returned before the journey continues, so the step-up rule has something to read.
Context, not a fixed ruleRisk assessed in real time from the circumstances of the request.
Behaviour, browser environment, network reputation and intent, scored on the request rather than reviewed afterwards.
Fraud risk management on suspicious activitySuspicious transactions must be identified and handled.
Automated and anomalous sessions are named by profile, at login, payee addition, limit change and reset — not only at payment.
Issuer accountabilityThe issuer answers for the integrity of the mechanism.
Every decision is logged with its inputs and its policy version, so the reasoning can be reconstructed months later.
Sense is a risk-signal layer, not an authentication factor. It tells your engine when a step-up is warranted and when a customer has already earned a quiet pass.
Proportionate, not uniformLow-risk sessions pass with the two factors you already run. Only the sessions that profile badly meet an extra check.
Evidence for the fileEvery verdict is stored with its score, its reason codes and the policy that applied — exportable when the decision is questioned.
DPDP-aligned handlingBehavioural features are derived and retained under your policy, with no message content and no browsing history leaving your domain.

Find out how much of your traffic is not human.

Two weeks of shadow-mode scoring on your real traffic, with the reason codes behind every verdict.