Edge-based abuse blocking
Run Castle at the edge to inspect requests before they reach your backend, helping you block credential stuffing and scripted abuse earlier in the flow.
Castle is a fraud and abuse prevention platform to block bots, monitor users, and stop in-app fraud with SDKs, APIs, and real-time policy actions.
Castle is a fraud and abuse prevention platform for blocking bots, account abuse, and in-app fraud. The site describes it as a complete suite of SDKs and APIs that can be deployed at the edge and inside the app to monitor users and stop abuse in real time.
Its workflow is designed to start in monitoring mode and then move to blocking when teams are ready. The platform supports edge analysis of requests, in-app session and device tracking, and policy actions such as allow, challenge, or deny for events like fake signups, account takeovers, credential stuffing, and multi-accounting.
Run Castle at the edge to inspect requests before they reach your backend, helping you block credential stuffing and scripted abuse earlier in the flow.
Add the SDK to track sessions, devices, and behavior inside the application, with the option to enrich decisions using your own business context.
Use built-in scores and signals such as Bot Score, Abuse Score, ATO Score, fingerprinting, IP geolocation, VPN detection, and device integrity checks to inform decisions.
Create real-time allow, challenge, and deny policies with rules, lists, webhooks, and Slack alerts, without needing code changes for every adjustment.
Query, visualize, and backtest historical data with pattern exploration, network analysis, and session monitoring to investigate abuse and refine rules.
Manage trusted, blocked, and review states for users, devices, emails, IPs, or custom attributes with case and state management tools.
Use Castle to detect and block automated requests before they reach the backend, especially for credential stuffing and scripted abuse patterns.
Track sessions, devices, and behavior inside the product to catch suspicious activity such as fake signups, account takeovers, and coordinated abuse.
Apply device, IP, email, and velocity rules to limit users who create multiple accounts from the same signals or shared infrastructure.
Query historical events, shared signals, and user paths to uncover fraud rings and decide which users, devices, or IPs should be blocked or reviewed.
Start in monitoring mode, then switch policies to challenge or deny when the risk signals are strong enough to act automatically.
Castle measures API usage in API calls. Each successful request to one of Castle’s APIs counts as one call, and the dashboard shows usage in real time.
Yes. Plans can be upgraded or downgraded at any time through billing settings.
Yes. Enterprise customers can receive SLAs, and the SLA terms can be customized to fit business requirements.
Yes. Dedicated setup and integration support is available on the Enterprise plan.
No. Unused API calls do not roll over; usage resets at the start of each billing cycle.