What stops everyone else02 / 10
Six defences, six answers.
A modern protected site is not one wall — it is six independent systems, each of which fails a scraper differently. Most projects die because one of them was never engineered for. Here is all six, and what we do about each.
01 — EdgeWAF
Managed bot rules at the CDN
Cloudflare, Akamai and Imperva score a request before the origin ever sees it — on network reputation, header order, protocol quirks and a hundred signals you don't get to read.
What we doCoherent clients rather than patched ones: transport, TLS and HTTP behaviour that is internally consistent, over routing chosen per source and per region.
02 — BehaviourScoring
Bot management that watches sessions
DataDome, HUMAN and Kasada don't judge a request, they judge a session: timing, navigation order, what a real user would have loaded on the way here.
What we doSession strategies modelled on real journeys, with pacing, warm-up and abandonment tuned per source instead of one global delay.
03 — IdentityFingerprint
Fingerprints across the whole stack
TLS handshakes, HTTP/2 frame settings, canvas and font enumeration, sensor entropy. A headless browser with a spoofed user-agent is identified instantly and quietly.
What we doFingerprint control end to end, so what the network layer claims and what the runtime does are the same story — and a drift monitor that tells us when the story stops working.
04 — ChallengeInterstitial
Proofs, interstitials and waiting rooms
JavaScript proof-of-work, invisible challenges, queue systems that hold a session for twenty minutes and expire it if it looks synthetic.
What we doA challenge pipeline that resolves in-session and keeps state through the wait, so throughput survives a queue instead of collapsing at it.
05 — StructureObfuscation
Markup engineered to be unparsable
Machine-generated class names that rotate on deploy, values assembled client-side, decoy nodes, content split across lazy fragments.
What we doWe work from the interfaces underneath the page wherever they exist, so a cosmetic redesign is a non-event rather than an outage.
06 — LimitsCaps
Ceilings that hide the catalogue
200 results per query over a catalogue of millions, pagination that stops at page 50, indexes that are deliberately partial. A naive crawl reports success and silently misses a third of the market.
What we doQuery-space decomposition — the catalogue is partitioned until every partition fits under the cap, then reconciled against control totals.