Crawlers and click farms inflate what your analytics shows. Ad blockers hide real people from it. Both happen at once, so the total looks about right and every decision underneath it is off.
Setup takes about five minutes and needs no changes to your pages. Finish it and $100 lands in your wallet. 30 day money back guarantee.
Analytics that runs in the browser overcounts, because a headless browser executes JavaScript exactly like a person does. And it undercounts, because a fifth to a third of real people block the script entirely.
Either error alone would be survivable. Together they cancel out just enough to look plausible, which is why the number goes unquestioned for years. The total is roughly right and the composition is completely wrong.
“My top cities were Prineville, Boardman and Council Bluffs. Those aren't cities. They're datacenter towns. Once you see it you can't unsee it.”
Indie founder, on discovering what his analytics was counting. Read the threadIt undercounts in the other direction, hiding low volume queries behind a privacy threshold. Two tools, two wrong numbers, neither of them the truth. Your server log is the only place a request cannot hide.
A person browsing is about four requests. An AI agent doing the same task is closer to four hundred. Any dashboard leading with request counts shows a single agent outweighing a hundred real people, and the chart just looks like growth.
Real browsers, real residential addresses, plausible referrers, and nobody home. By every measure a bot filter takes, they are browsers. Telling them apart needs behaviour, not identity.
Your server or edge tells us about each request, and we classify it. That part is unblockable, because it never touches the visitor's browser. An optional snippet adds behaviour, which is the only thing that separates a person who read the page from a browser that rendered it and left.
If the snippet is blocked, the visit is still counted. You lose the behavioural detail, never the visitor. That is the whole difference from a JavaScript tag, where a blocked script means the visit never happened.
Every verdict decomposes into the individual signals that produced it. The classification engine is open source so anyone can audit the method.
A verified search crawler and a competitor's price monitor land in the same tier. They are the same kind of thing and they deserve opposite decisions, so we read two more properties off every agent.
Function is what kind of thing it is: search engine, AI crawler, AI assistant, AI search, SEO tool, social media, and the rest of the taxonomy. Intent is what it is doing to you, and it is never declared. It is worked out from what the agent actually did on your site: which paths it went to, how evenly spaced the requests were, whether it read robots.txt first, whether real people ever arrived from that surface afterwards.
The same crawler genuinely behaves differently on different sites, so intent is measured per site rather than stamped globally. Googlebot indexing your articles and a scraper copying them can be the same tier. The doing is the difference, and the doing is what we measure.
Edge middleware, a log agent, or two lines in your application. No DNS change, no proxy in front of your site, nothing that can take you down.
Put a protected link between your advert and your landing page. A real person sails through in about 40 milliseconds. A rented server gets stopped, with the reason attached, and you get a timestamped record of every click that was turned away and exactly which check it failed.
That record is the point. Telling an ad network your traffic was fake is an accusation. Showing them four hundred clicks that arrived from rented servers with no browser headers is evidence, and evidence is what gets a refund.
It fails open: if the check times out or we have a bad day, the visitor goes through. And the link runs on our domain, so if we go down your site keeps serving and only the link stops.
Available on a plan or not. We will not meter this, because metering it would mean earning more from the fraudulent clicks it exists to stop.
Tell us what a click costs and we show what blocking them kept in your budget. Leave it blank and we show the blocks with no figure rather than inventing one.
Most tools will hand you a block button and let you find out what it cost you. We think a rule that turns away paying visitors silently is worse than no rule at all, because the people it blocks do not complain. They see an error and go somewhere else, and you see a traffic dip with nothing attached to it.
So every rule is checked against your own traffic first. If the pattern would also have blocked real people, we say how many before you can add it. If the number is large, we refuse to generate the rule at all. There are networks we will not help you block whoever asks: mobile carriers, consumer ISPs, the ranges that feed your search traffic. A tool that lets you lock out four thousand customers with one comfortable click is worse than no tool.
And we never do the blocking ourselves. Everything here produces configuration for infrastructure you already run, and you review it before it goes anywhere near your server. Every rule expires, because a permanent block is a decision about a network that may belong to somebody completely different next year.
A dashboard that only totals bandwidth talks you into blocking the crawler that feeds you. So every cost figure sits beside its counterweight: what came back through that same agent, in people and in confirmed conversions.
Googlebot costs cents and sends thousands. A scraper costs the same cents and sends nothing. Same byte count, opposite decisions. Only the return leg tells you which is which.
Attribution lags honestly: content indexed today can surface in an answer engine months later, so AI crawlers get judged over quarters, not fortnights. The numbers say when they are estimates, and the method is on the page.
You know which campaign you suspect. Paste its dates and source into the audit and watch the system agree with you or surprise you, for reasons you can check: how many of those clicks were real people, how many did anything, and which named signal flagged the rest.
A verdict is an accusation; a verdict with named signals is evidence. The audit never reports a number without the reasons underneath it, because the output is meant to be shown to whoever sold you the traffic.
Your own server tells us when somebody signs up, buys, or finishes anything real, signed with a key that never touches a browser. That one assertion overrides every heuristic we run. A visitor running every privacy tool on earth looks like a bot, until your server says they created an account.
Then the arithmetic fixes itself. The naive rate divides by everyone, machines included. The true rate divides by people. The gap between those two numbers is the size of the lie your old dashboard was telling you.
Bots reach checkout now. They click email links, submit forms and traverse four stages, and every conventional funnel folds them into the conversion rate. That is how somebody concludes their checkout is broken when in fact half of what reached it was never a person.
Both numbers are shown side by side, always. The inflated one is what you have been looking at elsewhere, and hiding it would make this look like a different tool with worse figures rather than the same figures told honestly. The gap between the two is the finding.
Stages must happen in order to count, visits are stitched across days, and the loose "ever visited" number other tools would show sits beside the ordered one, because the gap between them is how much every other tool was overstating.
A notification in an app you open twice a week is a record of something you missed. So alerts go to Slack, Discord, Teams, Zapier or your own signed endpoint, with thresholds you set: machine share, traffic jumps against the baseline you pick, funnel leaks, or a site that stopped reporting entirely.
A failing endpoint is shown as failing, loudly. The worst version of this feature is one that quietly stops delivering while you believe you are covered. Ours pauses and tells you why.
The click farm signature is a shape: everything plausible, nothing home, and a session window under one second. One chip isolates every sub second visit on your site. A slider up to a minute isolates the readers. Zombies that lingered half a minute and machines that vanished in under a second were always different populations wearing the same tier. Now they are two clicks apart.
No plan has a traffic limit. Bot traffic is the thing you are paying us to find, so billing you more for having more of it would put us on the wrong side of your own interests. Every other tool in this category meters exactly the traffic it promises to eliminate.
Full comparisonYour traffic is a puzzle with thousands of pieces. The picture only needs how each piece moved and when. It never needs whose piece it was, so that is the part we never keep.
Visitor addresses are hashed with a salt that changes every night, so the same person looks different tomorrow. Nobody can follow them through the data, including us. Raw logs are classified and discarded in the same pass, never stored.
The behaviour snippet measures pointer movement, scroll and typing rhythm as timing and geometry only. It cannot tell an A from a Z. No canvas fingerprinting, no device identity, and by default no cookie, which is why your visitors need no banner on our account.
The picture assembles. The box the pieces came in is thrown away.
Five minutes to set up. Nothing to install on your pages.
Get started