About half of the traffic hitting a typical login endpoint is automated. Most of it is not an attack in the classical sense: it is credential stuffing with leaked password lists, price scraping, inventory hoarding, gift-card enumeration and fake account creation.
Deflecto classifies automated clients into verified good bots (search engines, uptime monitors, partners you allow-list), unverified automation and malicious automation. Good bots pass. Everything else pays a proof-of-work cost that scales with how suspicious it looks — and that cost is what breaks the economics of the attack.
No CAPTCHAs
Your customers never click on traffic lights. Challenges run in the background in a few hundred milliseconds on a mid-range phone.