COOLOSJ Shield is invisible, privacy-first human verification for websites and apps. Stop spam, fake signups and credential stuffing — without making real customers squint at traffic lights.
This is the real engine, not a mock — it runs on your browser's actual
behaviour.
See the full API log →
They frustrate real customers, leak data to ad networks, and modern AI solves them anyway.
Solver farms defeat mainstream CAPTCHAs for about a dollar per thousand. The lock costs attackers almost nothing.
Every puzzle is a checkout abandoned and a signup never finished. Friction is a tax paid only by humans.
Free CAPTCHAs aren't free. Your visitors' behaviour feeds someone else's advertising graph.
Difficulty scales with suspicion. Over 95% of genuine visitors never see anything.
On page load Shield reads device, behavioural and network signals — pointer kinematics, timing, automation traces, IP reputation. No cookies, no PII.
The engine returns a score in under 100 ms. Confident humans pass invisibly. Uncertain sessions get proof-of-work. Only real threats meet a hard challenge.
Shield issues a signed, single-use token bound to your domain. Your backend confirms it with one API call. Replays are rejected automatically.
Most visitors never see a widget, checkbox or puzzle. Verification finishes before the page settles.
Trivial for one browser, ruinous at a million solves a day. We make attacks uneconomic rather than merely annoying.
Human reaching accelerates and decelerates. Scripted paths move at constant speed — and jitter can't fake that.
Headless Chrome, Puppeteer, Playwright, Selenium and stealth-patched browsers all leave fingerprints.
Processed in-region, built for DPDP compliance. EU and US regions available per site.
No tracking cookies, no cross-site ad profiling, no consent banner triggered by us.
Full keyboard path, screen-reader labels, reduced-motion support. Verification shouldn't exclude anyone.
A reCAPTCHA-compatible verify endpoint. For most sites, switching is a URL swap.
See what was blocked, from where, and why. Every verdict comes with the signals behind it.
<!-- front end -->
<script src="/shield.js" async defer></script>
<div class="coolosj-shield" data-sitekey="cjp_…"></div>
// back end
const v = await (await fetch(API + "/v1/siteverify", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
secret: process.env.SHIELD_SECRET,
response: req.body["coolosj-shield-response"]
})
})).json();
// check the verdict, not just success
if (!v.success) return res.status(403).send("blocked");
if (v.verdict === "review") flagForReview(user);
No card to start. Limits are per day, not per month — so a bad day never bills you.
Paid plans are activated by UPI. Talk to us for anything larger.
Working. The widget on this page runs the real engine — it scores your actual pointer movement, timing and browser environment, then issues a signed token your server would verify. Try it, then open the full demo to watch every API call.
Three ways. We don't feed visitor behaviour into an advertising graph. We process in your chosen region, including India for DPDP. And success means human — reCAPTCHA v3 returns success for any well-formed token, so bots scoring 0.0 still pass if you only check that field. We return a verdict you can act on.
Any single defence can be beaten — anyone claiming otherwise is selling something. Shield layers proof-of-work, pointer kinematics, device fingerprinting and network reputation so defeating all of them at scale costs more than the attack earns. It's an economic filter, not an unbreakable puzzle. We attack it ourselves with real browser automation and publish what gets through.
By default Shield fails open — verification is skipped rather than blocking your users. Your login page will never go down because ours did. You can switch to fail-closed for high-security flows.
One successful verification your backend consumes. Blocked bots are free — so an attack can't exhaust your allowance and take your signup form offline.
Signals needed to tell humans from bots: coarse device characteristics, interaction timing, pointer kinematics, network reputation. No tracking cookies, no cross-site profiling, no selling data. IPs are hashed and raw telemetry expires.
COOLOSJ Studios — we build software, design systems and digital products. Shield came out of protecting our own clients' forms and deciding the existing options weren't good enough.
No card, no sales call. Create an account and your API key is ready in about ten seconds.
Create your free account →