Prosopo

Prosopo provides bot and AI agent trust detection so websites can block malicious automation while letting real users an

Cybersecurity · SaaS · AI / ML Live product
0
0
9/11/2026

The Problem

Websites face abuse from scraping, credential stuffing, account takeover, ticket scalping, inventory hoarding, click fraud, phishing and spam bots, but AI agents now also act on behalf of real customers to shop, research and book. Traditional CAPTCHA tools like reCAPTCHA and hCaptcha rely on binary block or allow decisions, data collection and cross-site tracking, which creates friction for legitimate users and privacy or compliance concerns. Blocking all automation indiscriminately means losing real customers who use AI agents, while allowing all automation invites abuse. Teams using black-box vendor scores also struggle to explain to a CFO or DPO exactly why a request was blocked.

The Solution

Prosopo runs a risk-based, trust-first detection engine that scores the intent of every request as human, AI agent or bot, applying verification only when risk thresholds are exceeded. It ships as Procaptcha (a CAPTCHA widget), Form Protect, Site App, and a Spam Filter and Residential Proxy Detection feature, integrating with WordPress, React, Vue, Angular, Cloudflare Workers and AWS Lambda@Edge. Detection uses behavioral analysis, JavaScript signals, proof-of-work challenges and machine learning across hundreds of signals, and every block includes a plain-language reason (e.g. inconsistent hardware readings, solver service detected, synthetic interaction timings). The platform supports agent whitelist rules and granular permissions to distinguish trusted AI agents and search crawlers from malicious automation, plus governance features like audit logs, access control and custom rules. It is designed to be privacy-first, avoiding cookies and cross-site tracking, and the base CAPTCHA is open source with self-hosting available.

Why Now?

Forrester adopted 'bot and agent trust management' as a category in late 2025 as AI agents like ChatGPT's shopping agent, Claude's computer-use agent and Perplexity's browser increasingly act on behalf of real users, making binary block/allow bot detection insufficient.

Prosopo