Spam and bot protection for your forms and logins. No puzzles for real visitors, nothing handed to advertisers, and nothing kept that can be turned back into a person.
Every other CAPTCHA makes your visitors do unpaid labor and hands their behavior to an advertising company. Unbotable does neither — and tells you exactly what it does instead.
Real visitors sail through and are never asked to prove anything. A session we're unsure about is quietly asked to wait a moment and come back — no images, no puzzles, nothing to click.
Your browser's characteristics are hashed with a secret before anything is written down. What's left is a 64-character string and a few counters. There is no way back from it to a device, an address, or a person.
Nothing is shipped to Google or Cloudflare. Decisions are made on Unbotable's own servers, and the data never leaves them — it isn't sold, shared, or used for anything but blocking bots.
Records fade on their own. Stop showing up and you're forgotten entirely. Even a flagged bot is forgiven on a fixed schedule it can't extend by trying again.
A live, random sample from our database, pulled the moment you loaded this page. Try to identify a single person from it. You can't — and neither can we. That's the entire point.
Alongside each of these we keep a handful of counters — how often it's been seen, how many sites, whether it ever tripped a trap. That's the part that actually catches bots, and it's spelled out below.
Bot protection that remembers nothing catches nothing. So we do keep a record — here is the whole of it, and what we deliberately don't do with it.
Your browser's characteristics — screen, language, graphics, and so on — hashed together with a secret key. We store the result, never the ingredients. It identifies a browser to us only as a meaningless string, and only for as long as that browser keeps showing up.
How long we've seen it around, how often it submits, how many sites it turns up on, and whether it has ever filled in a hidden field no human can see. Numbers, not history — we don't keep what you did, only how much.
We look at the network a request came from to spot one machine pretending to be hundreds. It's cut down to a neighborhood of up to 254 addresses, hashed, held for ten minutes, and never written down whole.
What you wrote never reaches us. The site you're on counts the links, notes which domains they point at, and takes a fingerprint of the text — on its own server. We receive those numbers. The words stay where you typed them.
And the other half, stated plainly: this is a cross-site record. A browser seen on two Unbotable-protected sites is recognizable as the same browser to us — that's how a bot caught on one site gets stopped on the next. It doesn't follow you anywhere else, it isn't linked to a name, an account, or an email address, no advertiser ever touches it, and there's nothing in it we could hand over that would mean anything to anyone.
Four layers, each free for a person and expensive for a bot.
Silent checks first. A hidden field no human can see, and a check that the form wasn't filled faster than anyone could read it. These catch the easy majority and need no JavaScript at all.
Does the browser contradict itself? What a browser says over the wire and what it says in JavaScript come from the same place, so they agree. Something claiming to be Chrome on a Mac while sending a Python request is not one browser.
A record, not a profile. We ask whether this fingerprint has done something a person can't — turning up on forty sites in ten minutes, submitting hundreds of times an hour, reproducing its own keystroke timings exactly. Doing the same thing every day is not one of them. Consistency is what people are like.
A pause, only when unsure. No images, no puzzle, nothing to solve. The browser is asked to wait a couple of seconds and come back. You won't notice; a spam operation firing and forgetting thousands of submissions can't afford to wait for any of them.
No account, no billing, no secret keys to guard — just a name for your site so a bot's reach across the network can be counted. No analytics on this page either. Expect a little wiring to point things at your forms; not much.
Middleware, Blade directives and a Vue/Inertia helper. Install it, add the middleware to a route, drop a directive in your form.
Hooks into the forms you already use — Elementor, WPBakery, comments and login. A short setup, then it runs itself.
We're not collecting your email to tell you when they're ready — that wouldn't be very us. They'll show up right here.