Live — free tier, no card

Bots pay in CPU.
Humans pay in nothing.

COOLOSJ Shield is invisible, privacy-first human verification for websites and apps. Stop spam, fake signups and credential stuffing — without making real customers squint at traffic lights.

✓ No tracking cookies ✓ 100 verifications/day free ✓ 2-line integration
Live demoReal engine

This is the real engine, not a mock — it runs on your browser's actual behaviour.
See the full API log →

The problem

Old CAPTCHAs punish the wrong people

They frustrate real customers, leak data to ad networks, and modern AI solves them anyway.

~$1.20

What bots actually pay

Solver farms defeat mainstream CAPTCHAs for about a dollar per thousand. The lock costs attackers almost nothing.

Up to 4%

Conversion you lose

Every puzzle is a checkout abandoned and a signup never finished. Friction is a tax paid only by humans.

Your data

Sent somewhere else

Free CAPTCHAs aren't free. Your visitors' behaviour feeds someone else's advertising graph.

How it works

Risk-adaptive, not one-size-punishes-all

Difficulty scales with suspicion. Over 95% of genuine visitors never see anything.

1

Silent signals

On page load Shield reads device, behavioural and network signals — pointer kinematics, timing, automation traces, IP reputation. No cookies, no PII.

2

Risk scoring

The engine returns a score in under 100 ms. Confident humans pass invisibly. Uncertain sessions get proof-of-work. Only real threats meet a hard challenge.

3

Verify server-side

Shield issues a signed, single-use token bound to your domain. Your backend confirms it with one API call. Replays are rejected automatically.

Features

Everything you need. Nothing you don't.

👻

Genuinely invisible

Most visitors never see a widget, checkbox or puzzle. Verification finishes before the page settles.

⚡

Proof-of-work engine

Trivial for one browser, ruinous at a million solves a day. We make attacks uneconomic rather than merely annoying.

🧠

Kinematic analysis

Human reaching accelerates and decelerates. Scripted paths move at constant speed — and jitter can't fake that.

🛡️

Automation detection

Headless Chrome, Puppeteer, Playwright, Selenium and stealth-patched browsers all leave fingerprints.

🇮🇳

India data residency

Processed in-region, built for DPDP compliance. EU and US regions available per site.

🍪

Cookieless by design

No tracking cookies, no cross-site ad profiling, no consent banner triggered by us.

♿

Accessible

Full keyboard path, screen-reader labels, reduced-motion support. Verification shouldn't exclude anyone.

🔌

Drop-in migration

A reCAPTCHA-compatible verify endpoint. For most sites, switching is a URL swap.

📊

Real analytics

See what was blocked, from where, and why. Every verdict comes with the signals behind it.

For developers

Two lines on the front. One call on the back.

  • ✓ Under 25 KB, async, never blocks render
  • ✓ Proof-of-work runs in a Web Worker — no UI jank
  • ✓ Works with any backend that can POST JSON
  • ✓ Fails open by default — we will never take down your login page
  • ✓ success means human, not "token parsed"
integration.js
<!-- front end -->
<script src="/shield.js" async defer></script>
<div class="coolosj-shield" data-sitekey="cjp_…"></div>

// back end
const v = await (await fetch(API + "/v1/siteverify", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    secret: process.env.SHIELD_SECRET,
    response: req.body["coolosj-shield-response"]
  })
})).json();

// check the verdict, not just success
if (!v.success) return res.status(403).send("blocked");
if (v.verdict === "review") flagForReview(user);
Pricing

Start free. Pay when you grow.

No card to start. Limits are per day, not per month — so a bad day never bills you.

Currency

Paid plans are activated by UPI. Talk to us for anything larger.

FAQ

Questions, answered

Is this actually working, or a landing page?

Working. The widget on this page runs the real engine — it scores your actual pointer movement, timing and browser environment, then issues a signed token your server would verify. Try it, then open the full demo to watch every API call.

How is this different from reCAPTCHA?

Three ways. We don't feed visitor behaviour into an advertising graph. We process in your chosen region, including India for DPDP. And success means human — reCAPTCHA v3 returns success for any well-formed token, so bots scoring 0.0 still pass if you only check that field. We return a verdict you can act on.

Can bots just solve it anyway?

Any single defence can be beaten — anyone claiming otherwise is selling something. Shield layers proof-of-work, pointer kinematics, device fingerprinting and network reputation so defeating all of them at scale costs more than the attack earns. It's an economic filter, not an unbreakable puzzle. We attack it ourselves with real browser automation and publish what gets through.

What happens if your service goes down?

By default Shield fails open — verification is skipped rather than blocking your users. Your login page will never go down because ours did. You can switch to fail-closed for high-security flows.

What counts against my daily limit?

One successful verification your backend consumes. Blocked bots are free — so an attack can't exhaust your allowance and take your signup form offline.

What data do you collect?

Signals needed to tell humans from bots: coarse device characteristics, interaction timing, pointer kinematics, network reputation. No tracking cookies, no cross-site profiling, no selling data. IPs are hashed and raw telemetry expires.

Who builds this?

COOLOSJ Studios — we build software, design systems and digital products. Shield came out of protecting our own clients' forms and deciding the existing options weren't good enough.

Get started

Your first 100 verifications a day are free

No card, no sales call. Create an account and your API key is ready in about ten seconds.

Create your free account →