Understand your traffic
Every fetch classified: humans, crawlers, scrapers, scanners, AI agents, forgeries. Observe first — nothing is blocked until you say so.
100,000 events a month. No card. DNS at the edge or a PHP agent on origin.
Botscope actively blocks malicious bots while giving you deep analytics into AI agents like GPTBot, ClaudeBot, and Gemini.
This is your visit on this page — not a mock-up.
Check your robots.txt
A plain GET against your domain — no account, no script. Every line of the answer is checkable.
Shows which AI crawlers your robots.txt allows, blocks, or never mentions.
02 · what you get
This is the screen you open on Monday
Everything above describes how it works. This is what it produces: one week of a mid-size storefront, every request classified, every verdict explained. Numbers below are from our own demo workspace — no customer is named and nothing here is presented as somebody else's result.
Which assistants fetched your pages, and how many readers each one sent back. No DNS migration. And through to conversion, not to a request counter.
Demo workspace data. Your own numbers appear within a day of connecting, in observe mode, before anything is ever blocked.
03 · under the hood
Four layers of defense
Every request runs the full stack before your application is reached — no redirect, no round trip, nothing for a real visitor to wait on.
Network & Crawlers
- ·IP reputation & threat feeds
- ·Verified crawler bypass (Googlebot, GPTBot…)
- ·Fake-crawler detection via rDNS mismatch
Session Validation
- ·HMAC-signed shield session cookie
- ·TLS / JA4 fingerprint continuity check
- ·Silent re-vouch on IP change (150 ms)
Challenge Barrier
- ·Invisible Proof-of-Work (browser-only)
- ·Adaptive difficulty by risk score 0–100
- ·Custom rule engine — block / challenge / observe
Behavioural Traps
- ·Invisible honeypot links in HTML
- ·Stateless pixel tracks static-asset loading
- ·Token-copier & HTML-only scraper detection
03 · under the hood, continued
What gets stopped?
Everything that shouldn't be there.
Headless browsers
Puppeteer, Playwright, Selenium — detected via JS environment probes.
Scrapers & parsers
HTML-only scrapers, API harvesters, price and content bots.
Fake crawlers
Bots spoofing Googlebot — exposed by rDNS / forward-DNS mismatch.
Datacenter & proxy
AWS, Azure, GCP ranges; residential proxies and Tor exit nodes.
AI training scrapers
Unverified or policy-violating LLM data harvesters.
Honeypot triggers
Any client clicking invisible trap links gets an instant permanent ban.
04 · you already have a WAF
Keep Cloudflare. This answers a different question.
A WAF decides whether a request is dangerous. Botscope decides who the client is and what it is doing with your content — including the AI assistants that are now a traffic source rather than a threat. Most customers run both.
If a WAF already covers what you need, that is a fine answer — say so on a call and we will tell you whether this adds anything for you. Book 30 minutes →
06 · pricing
Everything is free. You pay for volume.
Every feature, on every account, up to 100K events a month. Past that, buy capacity in blocks of 100K — change the number any month, or drop back to free.
No card. Start on the free 100K and add blocks when you outgrow it.
Rate by volume
Per 100K block. The further you go, the less each one costs.
Each band is charged at its own rate, so the bill only ever rises with the volume. Increases apply immediately; decreases at your next renewal, with nothing refunded and nothing owed.
Included free, and at every size
One billable event = one telemetry record stored (typically one protected HTTP request).