OCTOBER UPDATE: FASTER WEBSITES, SMOOTHER VERIFICATION AND PASSKEY SIGN-IN.Read the update Sign in

Bot Protection That Stops Scripts, Never People.

An invisible browser check that real visitors pass without noticing, a self-hosted CAPTCHA for traffic that needs a closer look, and verified search engines that always get through.

Invisiblebrowser check for real visitors, once per session.
Self-hostedCAPTCHA on Shieldify servers. No Google, no tracking.
VerifiedGooglebot, Bingbot and Applebot, checked by address.
No pluginnothing to install on your website or server.
Which bots

Most automated traffic is not a search engine

Bots do more than flood a website. They copy prices and content, try leaked passwords against your login page, create fake accounts, hammer search and filter pages, and probe for vulnerable plugins. Many of them now use real browser user agents and rotate through residential proxies, so a simple user-agent filter or IP block list no longer catches them.

  • Scrapers that copy product data, prices and content.
  • Credential stuffing against login pages with leaked passwords.
  • Attack bots behind HTTP floods and vulnerability scans.
  • Abusive automation on search, forms and checkout.
The browser check

A check real browsers pass on their own

When a website is under pressure, and for clients that go over their rate limit, Shieldify asks new visitors for a quick browser check. A real browser completes it automatically in a moment: it runs the check, stores a short-lived verification cookie and continues to the page. Scripts, simple HTTP clients and most automation tools cannot complete it, so they never reach your server.

Verified visitors are not asked again for hours, and people who share one address, such as an office or a mobile network, verify together instead of each seeing their own check.

Private CAPTCHA

A CAPTCHA that does not track your visitors

Traffic that still looks suspicious after the browser check meets a CAPTCHA instead of a hard block, so a real person always has a way through. The CAPTCHA runs on Shieldify's own servers. Visitor data is not sent to Google or any other captcha vendor, and no advertising cookies are set. The Trust Center lists the security cookies Shieldify uses.

Search engines

Good bots get through, fake ones do not

Blocking search engines during an attack would cost you rankings. Shieldify lets Googlebot, Bingbot and Applebot through, but only after checking that the request really comes from the address ranges each company publishes. A scraper that only copies Googlebot's user agent is treated like any other unverified client.

APIs and integrations

Let your own machines in

Payment providers, webhooks, uptime monitors and mobile apps cannot run a browser check. Add their exact paths, such as /api/payment/callback, or their fixed IP addresses as trusted rules under Access rules. Keep each rule as narrow as possible; trusted paths still have their own abuse limits.

What you see

Challenged traffic, separate from the rest

The traffic dashboard shows challenges as their own series next to allowed and mitigated requests, live and over up to 180 days. Security events and the request log show which clients were challenged or blocked and why.

FAQ

Questions, Answered.

Something else on your mind? Write to contact@shieldify.ee and a person will answer.

Will my visitors have to solve puzzles?

Usually not. Most visitors never see anything, and those who do see a short "checking your browser" page that completes by itself. The CAPTCHA is reserved for traffic that still looks suspicious.

Does bot protection hurt SEO?

No. Googlebot, Bingbot and Applebot are verified against their published address ranges and let through, including during an attack.

Is the CAPTCHA GDPR-friendly?

It is self-hosted on Shieldify servers, sends no visitor data to a third-party captcha vendor and sets only security cookies. See the Trust Center for details.

Can I use Shieldify in front of an API?

Yes. Add the API's paths or your clients' fixed addresses as trusted rules so machine clients are not asked for a browser check, and keep the rest of the website fully protected.

Do I need a plugin for WordPress or Shopify?

No. Shieldify works in front of your server after one DNS change. Hosted shop platforms that do not let you point your own domain to a proxy are not supported.

Stop Bad Bots.Keep Every Visitor.

Put an invisible browser check and a private CAPTCHA in front of your website today.