Comprehensive security on demand
One integration, many use cases. The same widget, the same siteverify call and the same privacy guarantees, whether it sits on a checkout, a login or a public form.
Bot protection
Bad bots are a loop around an HTTP client, pointed at any public form you expose, submitting it faster than a person.
Credential stuffing
A combo list from someone else's breach, replayed one pair at a time against your login form.
Account takeover
Someone targeting one specific account, working password reset, resend-code and contact-change routes rather than the login box.
Fake signups
Someone runs your registration form in a loop to mint disposable accounts for trial credits, free tiers and referral bounties.
Spam comments
Comment spam is link placement at scale: one URL pushed into thousands of threads.
Card testing
Stolen card numbers validated in bulk against a live checkout: the checkout is not the target, it is the oracle.
Scraping
Scraping reads your catalogue at a rate and coverage no reader produces: every SKU, every price, once a day.
Giveaway abuse
One entrant taking hundreds of places in a draw or airdrop, each behind a throwaway email or wallet.
Ticket scalping
Bots are aimed at the seat-hold endpoint before the on-sale opens, then fire hundreds of holds in seconds.
Click fraud
Scripts and traffic farms drive paid clicks into your landing pages, so a campaign reports conversions that never happened.
Common questions about these use cases and PrivCaptcha
Straight answers on how the challenge works, what we keep, and what actually changes on your side when you switch.
The route that costs you money when it is abused - usually login, signup or checkout. Everything else can follow once you have seen what the numbers look like on the first one.
No. It is the same widget and the same verify call everywhere. What changes between these pages is which route you put it in front of and what the abuse looks like when it arrives.
Yes. A sitekey belongs to a site, not to a form, so login, signup and checkout can all share one - with a single domain allowlist governing the lot.
These are the ten we see most, not the boundary of what the widget does. If a route can be posted to by a script, it can be put behind a challenge.
Add PrivCaptcha now, in two lines of code
Drop in the script tag and sitekey and point your existing siteverify call at us. 10,000 verifications a month are free.