Dual-Phase Detection Engine

The Most Advanced Bot Detection for Media Buyers

Purpose-built for pop, push, and native traffic. Dual-phase detection: server-side analysis plus client-side browser verification. Every visitor classified into Gold, Silver, or Filtered quality tiers — in under 15 milliseconds.

18+
Detection Layers
<15ms
Decision Speed
99.3%
Accept Precision

Why We’re Different

Built from the ground up for media buyers. Not adapted from enterprise IT security.

Evidence-Based Verdicts

PureGuard never blocks on a single signal. Our proprietary scoring engine requires multiple pieces of converging evidence before making a decision. Real humans pass. Bots get caught.

Continuous Trust Scoring

Every click receives a proprietary trust score built from dozens of weighted signals. The scoring algorithm adapts to each traffic source, with tunable sensitivity per campaign.

Zone Intelligence (Only We Do This)

Bot detection is the means — zone intelligence is the end. Know exactly which zones send real humans and which send bots. No competitor offers this at any price.

Server-First, Client-Verified

Phase 1 runs server-side before the redirect — invisible to bots. Phase 2 verifies browser integrity client-side with 10 hardware and runtime checks. Two phases. Zero evasion surface.

Enterprise Power, Media Buyer Price

Competitors charge $3,000–$50,000/month and still don’t support pop/push traffic. PureGuard delivers superior detection for a fraction of the cost.

Self-Learning Engine

The detection engine continuously learns from your traffic patterns. Zone quality scores update every 10 minutes. The longer it runs, the more accurate it becomes.

What We Detect

18 proprietary detection layers organized into four defense tiers. Each click is analyzed across all tiers simultaneously.

Instant Block

Global Threat Intelligence

Real-time cross-referencing against multiple threat intelligence feeds and community-driven blocklists covering millions of known malicious IPs. Continuously updated from global sensor networks. Sub-millisecond kernel-level lookups.

Instant Block

Bot Signature Engine

200+ bot and automation framework signatures covering headless browsers, scraping tools, ad fraud crawlers, and verification bots. Pattern library updated weekly. Zero false positive rate on known signatures.

Instant Block

Browser Authenticity Validation

W3C-spec aware validation of browser version claims, build signatures, and privacy feature behavior. Catches fake versions, impossible combinations, and spoofed user-agents with 100% certainty.

Instant Block

Rate & Velocity Analysis

In-memory behavioral analysis detects abnormal click patterns, rapid-fire attacks, fingerprint rotation, and coordinated bot farm activity across multiple time windows.

Trust Analysis

Browser Enforcement Signals

Validates unforgeable browser-enforced security headers and protocol-level signals that simple HTTP clients cannot replicate. One of the strongest server-side bot indicators available today.

Trust Analysis

Network Origin Intelligence

Proprietary database of 13,200+ hosting ASNs and known proxy networks. Distinguishes genuine residential users from datacenter-originated traffic, VPNs, and residential proxy services used by sophisticated bot farms.

Trust Analysis

Multi-Signal Correlation

Cross-validates dozens of signals across HTTP headers, protocol metadata, Client Hints, TLS characteristics, and geo-consistency markers. Real browsers leave a consistent fingerprint across every dimension. Bots leave contradictions.

Trust Analysis

Behavioral Fingerprinting

Proprietary algorithms detect UA switching, coordinated multi-IP bot farm patterns, and sophisticated evasion techniques. Catches bots that evade all other single-signal detection methods.

Phase 2: Client-Side Browser Verification

After server-side analysis, borderline visitors undergo real-time browser verification — 10 integrity checks executed in under 10ms.

Browser Check

360-Degree Browser Fingerprint

WebDriver detection, Chrome object validation, automation framework globals, navigator.userAgentData consistency, and function integrity checks. Catches Selenium, Puppeteer, Playwright, and PhantomJS.

Browser Check

Hardware & Rendering Validation

WebGL renderer analysis (SwiftShader/Mesa/llvmpipe detection), screen dimension validation, viewport-to-screen ratio checks, and plugin/language enumeration. Virtual machines and headless browsers exposed.

Browser Check

Environment Consistency

Timezone verification against geo location, engagement tracking (scroll depth, click interaction, time-on-page), and visibility state monitoring. Bots that pass server checks fail behavioral verification.

Plus additional proprietary layers: TLS fingerprinting, geo-behavioral correlation, header order analysis, device authenticity validation, and more. Our detection engine is continuously expanded with new layers as bot techniques evolve.

Proprietary Trust Scoring

Every click receives a continuous trust score from 0 to 10, built from dozens of weighted positive and negative signals.

PROPRIETARY TRUST SCORE 0 — 10 ——— Positive Evidence ——————————————— + Browser enforcement signals validated + Genuine residential network detected + Protocol and header consistency confirmed + Device authenticity markers present + Geo-behavioral correlation matches ——— Negative Evidence ——————————————— - Datacenter / hosting / proxy network origin - Missing or inconsistent browser signals - Protocol version contradictions - Behavioral anomalies detected - Known threat intelligence matches ——— Verdict ——————————————————— GOLD (7.0+) → Best monetization path SILVER (5.0-6.9) → Alternate routing or secondary offers FILTERED (<5.0) → Bot detected, save budget

Why Trust Scoring Beats Binary Detection

Same User-Agent. Completely different evidence.
Chrome 131 on a mobile carrier in Thailand with full browser enforcement signals → HIGH TRUST — ACCEPT
Same Chrome 131 UA from a cloud server, missing browser signals, inconsistent protocol → LOW TRUST — BLOCK

The user-agent is identical. The surrounding evidence tells the whole story. That’s why multi-signal trust scoring catches bots that simple UA matching never will.

Zone Intelligence Engine

Bot detection is the means. Zone intelligence is the end.

Finding Gold in Trash

Every traffic source has hundreds or thousands of zones (publisher IDs). Some zones deliver 95% real humans. Others deliver 95% bots. The difference between profit and loss is knowing which is which.

PureGuard aggregates Guard verdicts per zone — accept rate, average trust score, hit volume, bot evidence patterns, device fingerprint diversity, conversion data — and produces a quality verdict for every zone, updated every 10 minutes.

CONFIRMED_BOT
Multiple hard kill signals. Strong bot evidence. Zero human indicators. Auto-blocked.
DEAD_ZONE
Zero accepts out of 3+ hits. Every click failed Guard checks. Wasting budget.
SUSPECT
Mixed signals. Some bot evidence but not conclusive. Monitored, not blocked.
CLEAN
High accept rate, strong trust scores, real device diversity. Proven human traffic.

Result: A ready-to-paste blocklist and whitelist for every traffic source you run. Export as CSV, flat text, or use the API. Updated every 10 minutes. No manual analysis needed.

Traffic Flow

Where PureGuard sits in your traffic chain.

Traffic Source
PopAds, RollerAds, HilltopAds...
Phase 1: Server
18 layers, <15ms
Phase 2: Browser
10 integrity checks
Gold
High trust — best monetization
Silver
Passed — alternate routing
Filtered
Bot detected — blocked

Shadow Mode

Log all Guard decisions without blocking anything. See exactly what PureGuard would block before you flip the switch. Perfect for validating detection accuracy on your specific traffic sources.

  • Full event logging with trust scores
  • Zone intelligence builds in background
  • Zero impact on live traffic flow

Protect Mode

Active blocking. Bots get redirected to dump URLs. Clean traffic reaches your money URLs. Zone blocklists auto-generate and update every 10 minutes.

  • Real-time bot blocking (<15ms)
  • Auto-generated zone blocklists
  • Configurable trust threshold per source

RTB Pre-Bid Filtering

Score traffic before you pay for it. Not after.

Without PureGuard

The traditional RTB flow burns money on bots:

  • Bid request arrives → you bid
  • You win the auction → you pay
  • Click arrives → it’s a bot
  • Money gone. No conversion. No recourse.

With PureGuard RTB

Guard scores the bid request before you commit:

  • Bid request arrives → scored in 3ms
  • Dozens of signals analyzed (UA, geo, network, domain, device)
  • Bot detected → NOBID (you pay nothing)
  • Clean traffic → BID (money well spent)
36+ Scoring Signals per Bid:
Threat intelligence matching · Bot signature detection · Network origin analysis · Geo verification · Device type validation · Domain quality scoring · Browser authenticity · Rate limiting · OS consistency checks · Bid floor analysis · Hosting ASN detection · And 25+ more proprietary signals

Competitor Comparison

Built different. Built for media buyers, not enterprise marketing teams.

Capability PureGuard PPC fraud tools
$150/mo
PPC fraud tools
$500/mo
HUMAN
$50K/mo
Pop/push traffic support
Zone-level intelligence
RTB pre-bid filtering
Server-side (no JS tags)
Auto zone blocklist
Auto zone whitelist
Detection layers 18+ 3–5 5–8 20+
Decision latency <15ms 100ms+ 50ms+ <10ms
Threat intelligence feeds
Behavioral bot farm detection
Traffic quality tiers
Client-side verification
Free tier 100K checks

Why competitors don’t work for media buyers: PPC fraud tools and PPC fraud tools are built for Google/Facebook advertisers — they use JS tags and client-side detection that doesn’t work with pop/push traffic. HUMAN (formerly White Ops) is enterprise-only at $50K+/month and doesn’t offer zone-level intelligence. None of them understand the media buying workflow: zones, blocklists, source-specific tuning, or cheap traffic economics.

Production Results

Real performance data from live traffic across pop, push, and RTB sources.

99.3%
Accept Precision
15-30%
Avg Waste Detected
<15ms
Median Decision Speed
10 min
Zone Quality Updates
Threat Intelligence Blocks Millions of IPs
Hosting/Datacenter Detection 13,200+ ASNs
Bot Signature Database 200+ patterns
Zones Analyzed 22,000+
Events Processed 600,000+
Ad Networks Supported 23+

Continuous Innovation

Our detection engine evolves faster than bot techniques.

See It Work on Your Traffic

Connect your traffic source, enable Shadow Mode, and watch PureGuard score every click in real time. No code changes. No JS tags. Takes 2 minutes.

Start Free Read the Docs
100,000 free checks · Full dashboard · Zone intelligence included