Risk Scoring

Risk Scoring helps businesses identify and mitigate potential risks associated with bot traffic, spam, and other malicious activities. By leveraging advanced algorithms and real-time data analysis, it evaluates user behavior and interactions to generate accurate risk scores. These scores empower you to make informed decisions about granting access, delivering content, or flagging suspicious activity.

Whether you're protecting sensitive data, preventing fraud, or enhancing user trust, Risk Scoring provides the insights you need to stay ahead of evolving threats.

Risk Scoring

The benefits of choosing Prosopo Risk Scoring

Real-time risk assessment

Evaluate user behavior and interactions in real-time to identify potential threats.

Customizable scoring criteria

Tailor the risk scoring system to align with your specific security policies and business needs.

Enhanced user experience

Maintain a seamless user experience while effectively managing risks associated with bot traffic and spam.

GDPR compliance

Our privacy policy complies with the law and guidelines of GDPR.

How Prosopo Risk Scoring works

Every verification request is given a risk score between 0 and 1 — the closer to 1, the more likely it is the request came from a bot. The score is a composite signal drawn from the browser environment, interaction behaviour, network properties, and any policies you've layered on top.

You can use the score in two ways:

  1. Hands-off. Prosopo uses the score itself to decide whether the visitor passes silently, gets a Proof of Work challenge, or has to solve an image CAPTCHA. Your only knob is the Safety Threshold — raise it to challenge more visitors during an attack, lower it to reduce friction when things are calm.
  2. In your own decisions. On paid tiers, the score is also returned to your backend with every verification response. Use it to drive your own logic — flag high-score signups for manual review, require step-up authentication on borderline scores, or route the request through a slower fraud check.

The score isn't a black box

Prosopo's score isn't a single opaque number — it's the result of several measurable signals you can reason about:

  • Headless-browser detection. Tells normal Chrome from Playwright, Selenium and headless Chrome.
  • Behavioural signals. Mouse movements, touch gestures and keyboard cadence that distinguish a person from a script.
  • Network reputation. Whether the request comes from a residential connection, a VPN, a hosting datacenter, or a network with a history of abuse.
  • Browser-environment fingerprint. Hundreds of small browser quirks that are hard to forge in automation.
  • Site policy adjustments. Penalties applied for things like unverified origins or in-app webviews when you've configured Context Awareness.

You set a single number — the Safety Threshold — and the platform takes care of the rest. Or you take the score and use it however you want.

Decision Machines: bring your own logic

For teams that need more than a threshold, Prosopo supports Decision Machines — custom scoring logic you author yourself and run inside the verification pipeline. Use it to:

  • Combine Prosopo's score with your own first-party signals (account age, device history, purchase value).
  • Apply different policies for different parts of your site (checkout vs. comments vs. login).
  • Express business rules that don't fit a single number — "if score > 0.7 and the user is signing in from a new country, require email re-verification".

Decision Machines run on Prosopo's infrastructure with no code deployed on your servers, and you can change them live without an integration update.

Hard blocks for the obvious bots

For the most extreme scores there's no point in even issuing a challenge — a sufficiently bad signal means the request should just fail. The Autoban score threshold lets you set a cutoff above which Prosopo skips the challenge step entirely and rejects the request outright. Useful during sustained automated attacks, when you'd rather burn no compute on visitors that are unambiguously bots.

How Prosopo Risk Scoring compares

Prosopo Risk ScoringreCAPTCHA v3 scoreCloudflare Bot Score
Score returned to your backend✓ (paid tiers)Limited
Custom decision logic (Decision Machines)Limited
Tunable strictness without code changesLimited
Auto-ban above configurable threshold
GDPR-compliant data handlingVaries
No third-party tracking cookies

Common use cases

Configuration reference

Request a Demo of Prosopo Risk Scoring

Risk Scoring is part of our Enterprise product. Please contact our sales team who will be happy to provide you with a quote.

Tell us about your bot problem

We'll get back to you straight away

By submitting this form, you agree to our Privacy Policy and Terms of Service

Trusted by companies of all sizes

1000+
active websites
1B+
monthly secure verifications
100M+
bots stopped per month

Our customers love us

Hundreds of businesses have made the switch from reCAPTCHA and hCaptcha to us. Here's what they have to say.

Frequently Asked Questions

What is Risk Scoring?

Risk Scoring is a feature that evaluates user behavior and interactions to generate real-time risk scores. These scores help identify potential threats, such as bots or spammers, allowing you to make informed decisions about granting access or delivering content.

How does Risk Scoring work?

Risk Scoring uses advanced algorithms and data analysis to assess user behavior patterns. By analyzing various factors, it generates accurate risk scores that indicate the likelihood of a user being a bot or spammer.

Can I customize the risk scoring criteria?

Yes, you can customize the risk scoring criteria based on your specific needs and business requirements. This flexibility allows you to tailor the scoring system to align with your security policies.

What else can Prosopo protect for you?

No matter the threat, we have a solution to keep your business safe.
Access Control
Prosopo's Access Control dynamically generates rules to protect your website from bots and spam.
Access Control
API Protection
Stop automated abuse of your API endpoints with Prosopo's bot-aware verification and access control.
API Protection
Procaptcha - GDPR Compliant CAPTCHA
With Prosopo's GDPR friendly captcha, enjoy seamless website security. Protect users, prevent bots, and stay compliant - all while keeping it simple.
Procaptcha - GDPR Compliant CAPTCHA
Invisible CAPTCHA
Prosopo's Invisible CAPTCHA provides seamless bot protection without disrupting the user experience.
Invisible CAPTCHA
Risk Scoring
Prosopo's Risk Scoring provides real-time analysis of user behavior to identify potential threats.
Risk Scoring
Spam Filter
Prosopo's Spam Filter blocks fake signups, throwaway emails, and abusive networks before they reach your forms.
Spam Filter