Home/Products/Button Defender (coming soon)
04 · Button Defender

Full-site bot defense, end to end.

One layer of protection across every endpoint — login, checkout, search, content, APIs. Adaptive policies with no false positives on real users.

No false positives on real users.


(Coming soon.)

99.7%
Bot traffic blocked across instrumented routes
< 6ms
Edge decision latency, P95
0.02%
False-positive rate on real users
Routes covered — site-wide, not just login
What's inside

One layer for every endpoint.

Most bot tools defend a single page. Button Defender sits at your edge and applies adaptive policies to every route on your site — APIs, content, auth, payment — without breaking real users.

Site-wide policies

Pass, challenge, or block — per route, per visitor class. One policy engine for your entire surface.

Edge-deployed

Runs on Cloudflare Workers, Fastly Compute, Vercel, or your own reverse proxy. No origin round-trips.

ATO & credential stuffing

Blocks distributed login attempts before they touch your auth service — no rate-limit tuning needed.

Scraper & inventory defense

Stop content scraping, price aggregators, and inventory hoarding without breaking SEO or partner crawlers.

Adaptive thresholds

Models retrain continuously on your traffic. Defender gets sharper the longer it watches your site.

Zero false positives

Every block is explainable. Real users — including assistive tech — never see a challenge.

How it works

From request to verdict, end-to-end.

Deploy at the edge

One worker, one config. Defender installs in front of every route — auth, API, content, payment.

Classify in flight

Every request gets a verdict before it reaches your origin — no extra latency from your perspective.

Apply policy

Pass real users, challenge edge cases, block known automation. All per-route, all configurable.

Adapt continuously

Models retrain on your traffic. Block lists, allow lists, and thresholds tune themselves.

Coverage

Every route, every threat class.

One deployment covers the full surface — not just the login form. Below: what Defender catches, by route family.

Route familyWhat Defender doesWhat it stops
Auth Per-IP and per-credential rate shaping, distributed pattern detection across login & signup Credential stuffing, account takeover, brute-force enumeration
PaymentVerifies real-browser execution before checkout submission, blocks card-testing scriptsCarding, BIN attacks, fake order spam
ContentThrottles aggressive crawlers, allows verified search engines, fingerprints scrapersPrice scraping, content theft, inventory hoarding
APIsToken-bound JS challenges for unauthenticated APIs; adaptive limits per consumerReverse-engineered mobile API abuse, public-endpoint scraping
FAQ

Questions, answered.

Will Defender break real users?
No. Real users — including those on assistive tech, low-bandwidth connections, or with privacy extensions — never see a challenge. False-positive rate stays under 0.02% in production.
Where will Defender run?
At the edge: Cloudflare Workers, Fastly Compute@Edge, Vercel Edge Functions, or your own reverse proxy. No origin round-trip needed.
Does it work for APIs and mobile?
Yes. Public APIs get token-bound JS challenges; mobile API consumers get adaptive per-token budgets. SDK shims are available for native apps.
How is this different from a WAF?
A WAF blocks known-bad requests via signatures. Defender classifies behavior — so it catches sophisticated bots running real Chrome that no WAF rule would flag.
Can I run it in observe-only mode first?
Yes. Set mode: analytics on any route to see what would be blocked without acting. Most teams run this for 1–2 weeks before going live.
Ready to defend

One layer. Whole site.

Try Button Defender free for 14 days. Deploy at the edge in under 30 minutes — no credit card required.