Home/Products/Transparency
01 · Transparency

See what bots are actually doing.

Deep behavioral classification across IP, TLS, HTTP, and JavaScript layers — surfaced in a clean, queryable dashboard. No black-box scores. Every decision is explainable.

Drops into any stack in under 10 minutes

~6
Bot classes detected, signal-by-signal
< 4ms
P95 classification latency
100%
Explainable decisions — no black box
Multilayer signal analysis, plus continuously recompiled JSVM to reduce programmatic bypass by 90%
What's inside

Classification you can actually inspect.

Most bot management is a single threat score. Transparency gives you the raw signals that score was built from — so you can decide what to allow, what to block, and what to investigate.

Real-time classification

Every request labeled in milliseconds: real_browser, simple_fake, seo_crawler, untrusted_ip, request_bot.

Signal-level inspection

Drill into IP reputation, TLS fingerprints, HTTP anomalies, and JS execution traces for any visit.

Queryable dashboard

Slice traffic by path, user agent, country, classification, or any custom signal — without writing SQL.

JSON-first API

Pull per-request signals into your data warehouse, SIEM, or BI tool. Clean, versioned, no surprises.

Raise the bar

Built on a custom Botguard/Shape-style runtime — recompiled frequently to defeat replay attacks.

Privacy by default

None of our signals are enough to track real users. Unique-fingerprint replay attacks don't work here.

How it works

From request to verdict, end-to-end.

Request lands

A visitor hits any page or endpoint instrumented with the Button SDK.

Signals collected

IP, TLS, HTTP, and JS layers each emit signals — passively, in under 4ms.

Verdict computed

Signals are combined into one of 5 transparent classifications, with a per-signal trail.

You decide

Pass, block, challenge, or just observe — based on your policies, not ours.

The signals

Four layers. One verdict.

Strong signals only. We won't block on a likelihood score — every classification has receipts.

LayerWhat we collectWhat it catches
IPASN reputation, datacenter / residential proxy detection, geo / TOR exits (via ipinfo.io)Untrusted infrastructure, scraping farms, anonymized abuse
TLSDeep version/OS fingerprints, cipher order, ALPN preferences, edge-case handlingHeadless browsers, custom HTTP clients masquerading as Chrome
HTTPHeader order & casing, claimed UA vs IP range consistency, known leaksStale automation libraries, mismatched UA / IP combinations
JSRecompiled VM challenges, runtime quirks, CreepJS-style entropy (no fingerprinting)Sophisticated bots running real browsers but missing real-world entropy
FAQ

Questions, answered.

Will this slow down my site?
No. Classification runs at the edge in under 4ms P95. Real users won't notice it; only bots ever see a challenge.
Do you fingerprint or track real users?
No. None of the individual signals we collect are sufficient to track a user across visits. Unique fingerprinting is inherently vulnerable to replay attacks — we deliberately don't rely on it.
How is this different from Cloudflare Bot Management?
We're transparent end-to-end. Every classification ships with the underlying signals, and you can run your own policies on top — instead of trusting a single black-box score.
What does setup look like?
Add our script to your html page, verify your domain, and start analyzing your traffic within a few minutes.
Ready to look

Stop guessing. Start seeing.

Try Transparency free for 14 days. Wire up your dashboard in under 10 minutes — no credit card required.