Stop bots.
Don't surveil people.

Spam and bot protection for your forms and logins. No puzzles for real visitors, nothing handed to advertisers, and nothing kept that can be turned back into a person.

verdict: human detected

Protection without the privacy tax

Every other CAPTCHA makes your visitors do unpaid labor and hands their behavior to an advertising company. Unbotable does neither — and tells you exactly what it does instead.

Invisible to humans

Real visitors sail through and are never asked to prove anything. A session we're unsure about is quietly asked to wait a moment and come back — no images, no puzzles, nothing to click.

Nothing reversible

Your browser's characteristics are hashed with a secret before anything is written down. What's left is a 64-character string and a few counters. There is no way back from it to a device, an address, or a person.

No advertising company involved

Nothing is shipped to Google or Cloudflare. Decisions are made on Unbotable's own servers, and the data never leaves them — it isn't sold, shared, or used for anything but blocking bots.

Everything expires

Records fade on their own. Stop showing up and you're forgotten entirely. Even a flagged bot is forgiven on a fixed schedule it can't extend by trying again.

Look at the data yourself

A live, random sample from our database, pulled the moment you loaded this page. Try to identify a single person from it. You can't — and neither can we. That's the entire point.

live from the database refreshes on load
  • 5c453ae14e37fe51b468f518f57cdba25cb74822c5960b4a3d3d62f9491b7eac 1 week old · flagged
  • ba4b417f09ea397070f90aa4794485fcf35fe4de51a5aaf86aa32e12e79dac21 2 weeks old · flagged
  • a07fef6852691aaea8d6a2f489fd16b45c460fb4e3882066c093dca2b6056f34 1 week old · flagged
  • 3f3d993383fdbde48c9368d3acdc790b93b47d5bd0ce345daf6abba49ed730e5 3 days old
  • da1b58b33f757f112ece8b1228447c5c547a9b73bfc1e95443699ed52aa9d725 15 hours old · flagged
  • 61e0cc5a9da1bc9fc625f07a5287dc70253e93f07ce4c2c5509a177bd74a4b65 2 weeks old · flagged
11 stored · 8 flagged auto-expires · nothing reversible

Alongside each of these we keep a handful of counters — how often it's been seen, how many sites, whether it ever tripped a trap. That's the part that actually catches bots, and it's spelled out below.

What we actually keep

Bot protection that remembers nothing catches nothing. So we do keep a record — here is the whole of it, and what we deliberately don't do with it.

An irreversible fingerprint

Your browser's characteristics — screen, language, graphics, and so on — hashed together with a secret key. We store the result, never the ingredients. It identifies a browser to us only as a meaningless string, and only for as long as that browser keeps showing up.

Counters against it

How long we've seen it around, how often it submits, how many sites it turns up on, and whether it has ever filled in a hidden field no human can see. Numbers, not history — we don't keep what you did, only how much.

Your address, for seconds

We look at the network a request came from to spot one machine pretending to be hundreds. It's cut down to a neighborhood of up to 254 addresses, hashed, held for ten minutes, and never written down whole.

On forms with a message box

What you wrote never reaches us. The site you're on counts the links, notes which domains they point at, and takes a fingerprint of the text — on its own server. We receive those numbers. The words stay where you typed them.

And the other half, stated plainly: this is a cross-site record. A browser seen on two Unbotable-protected sites is recognizable as the same browser to us — that's how a bot caught on one site gets stopped on the next. It doesn't follow you anywhere else, it isn't linked to a name, an account, or an email address, no advertiser ever touches it, and there's nothing in it we could hand over that would mean anything to anyone.

How it works

Four layers, each free for a person and expensive for a bot.

Silent checks first. A hidden field no human can see, and a check that the form wasn't filled faster than anyone could read it. These catch the easy majority and need no JavaScript at all.

Does the browser contradict itself? What a browser says over the wire and what it says in JavaScript come from the same place, so they agree. Something claiming to be Chrome on a Mac while sending a Python request is not one browser.

A record, not a profile. We ask whether this fingerprint has done something a person can't — turning up on forty sites in ten minutes, submitting hundreds of times an hour, reproducing its own keystroke timings exactly. Doing the same thing every day is not one of them. Consistency is what people are like.

A pause, only when unsure. No images, no puzzle, nothing to solve. The browser is asked to wait a couple of seconds and come back. You won't notice; a spam operation firing and forgetting thousands of submissions can't afford to wait for any of them.

Drop it into your stack

No account, no billing, no secret keys to guard — just a name for your site so a bot's reach across the network can be counted. No analytics on this page either. Expect a little wiring to point things at your forms; not much.

Coming soon

Laravel package

Middleware, Blade directives and a Vue/Inertia helper. Install it, add the middleware to a route, drop a directive in your form.

composer require unbotable/unbotable-laravel
Coming soon

WordPress plugin

Hooks into the forms you already use — Elementor, WPBakery, comments and login. A short setup, then it runs itself.

Install the plugin · point it at Unbotable

We're not collecting your email to tell you when they're ready — that wouldn't be very us. They'll show up right here.