Bot detection & web fraud · Castle
Castle
Usage-priced fraud and bot API that scores every login, registration, and transaction using device, behavioral, IP, and email signals.
Castle is an API-first fraud and bot detection platform aimed at registration, login, and in-app transaction abuse rather than general web-traffic filtering. It combines device fingerprinting (including detection of headless browsers, emulators, and rooted devices), behavioral signals such as velocity and custom rate limits, IP reputation (proxy, VPN, Tor, and datacenter detection), and email risk checks (disposable domains, enumeration) into three real-time scores: Bot, Account Takeover, and Account Abuse. A rules engine and dynamic block/trust/review lists let teams act on those scores, with webhooks and Slack alerts for automation, and up to 18 months of historical data for backtesting new rules. Unlike most competitors in this category, Castle publishes transparent self-serve pricing on its site, including a free usage tier and metered per-request rates above it.
At a glance
| Vendor | Castle |
|---|---|
| Pricing model | Usage-based |
| Free tier | Yes |
| Deployment | Cloud |
| Open source | No |
| Best for | Product and fraud teams who want a metered, self-serve API for login and account-abuse risk scoring. |
Pricing
Published self-serve pricing: a free tier with a monthly usage credit, a Pro tier, and custom Enterprise, all metered per Risk/Filter and IP Intelligence API call.
| Plan | Price | Notes |
|---|---|---|
| Free | $0/month | Includes $5 of API usage: 5,000 IP lookups or 1,000 Risk API calls, 3-day data retention, 3 seats |
| Pro | $200/month | Includes $200 of API usage: 200,000 IP lookups or 40,000 Risk API calls, 7-day retention, 5 seats |
| Enterprise | from $4,000/month | Custom, no rate limits, up to 18 months retention, unlimited seats |
Prices read from the vendor's own page on September 21, 2026. Vendors change prices; check the source before you budget.
Features
- Real-time Bot, Account Takeover, and Account Abuse risk scores
- Device fingerprinting including headless-browser and emulator detection
- IP reputation: proxy, VPN, Tor, and datacenter detection
- Email risk scoring: disposable domains, enumeration
- Custom rules engine and velocity/rate limiting
- Dynamic block/trust/review lists
- Webhook and Slack alert automation
- Up to 18 months of historical data for rule backtesting
Profile last reviewed September 21, 2026