PerimeterX (HUMAN) vs WebDecoy

HUMAN Security vs WebDecoy. Behavioral biometrics and fraud detection vs multi-signal bot detection with honeypots and vision AI.

PerimeterX merged with White Ops in 2021 and rebranded to HUMAN Security. HUMAN offers comprehensive fraud detection with behavioral biometrics. WebDecoy provides multi-signal bot detection with honeypots, TLS fingerprinting, and vision AI detection.

This comparison explains the technical differences and when each makes sense.

Detection Architecture

HUMAN: Behavioral Biometrics

User Request
    ↓
HUMAN JavaScript (client-side)
    ├── Behavioral Biometrics
    │   ├── Mouse movement patterns
    │   ├── Keystroke dynamics
    │   ├── Touch gestures (mobile)
    │   └── Scroll patterns
    ├── Device Fingerprinting
    │   ├── Canvas/WebGL/Audio
    │   └── Browser characteristics
    ├── JavaScript Challenges
    └── ML Bot Score
    ↓
Allow / Challenge / Block

HUMAN’s focus: Behavioral biometrics to distinguish humans from bots based on how they interact, plus comprehensive fraud detection.

WebDecoy: Multi-Signal Detection

User Request
    ↓
WebDecoy Detection Stack
    ├── TLS Fingerprinting (JA3/JA4)
    │   └── User-Agent mismatch detection
    ├── IP Enrichment
    │   ├── AbuseIPDB reputation plus VPN, proxy and datacenter detection
    │   └── Datacenter/VPN/Tor detection
    ├── Geographic Consistency
    │   └── Timezone/IP/Language correlation
    ├── Honeypot Detection
    │   ├── Decoy Links (hidden spider traps)
    │   └── Endpoint Decoys (fake API routes)
    ├── Behavioral Analysis (Bot Scanner)
    │   └── Mouse entropy, keystrokes, forms
    └── Vision AI Detection (FCaptcha)
        └── Signals designed for screenshot-driven agents
    ↓
Threat Score (0-100) → Allow / Challenge / Block

WebDecoy’s focus: Multiple independent detection signals that catch threats the others miss.

Detection Method Comparison

CapabilityHUMAN SecurityWebDecoy
Behavioral BiometricsPrimary method (deep analysis)Included (Bot Scanner)
Device FingerprintingExtensive (100+ signals)TLS fingerprinting only (JA3/JA4)
HoneypotsNoDecoy Links + Endpoint Decoys
IP IntelligenceHUMAN networkAbuseIPDB reputation plus VPN, proxy and datacenter detection
Geographic ChecksBasicTimezone/IP/Language consistency
Vision AI DetectionNoFCaptcha signals designed for screenshot-driven agents
AI Crawler DetectionVia bot rulesRegistry of 186 known bots and AI agents
Account Takeover FocusStrong (primary use case)Included (credential stuffing)
Ad Fraud PreventionYes (White Ops heritage)No
Mobile SDKYesNo
SIEM IntegrationEnterpriseEvery paid plan (Splunk, CrowdStrike Falcon LogScale, Datadog)

Key Differences

HUMAN’s Strengths

Behavioral Biometrics Depth

HUMAN has deep behavioral analysis from years of focus:

  • Mouse movement entropy and velocity curves
  • Keystroke timing patterns and rhythm
  • Touch pressure and gesture analysis (mobile)
  • Session-long behavioral profiling

Account Takeover Prevention

HUMAN excels at ATO with:

  • Device trust across sessions
  • Behavioral consistency scoring
  • Risk-based authentication integration

Ad Fraud Prevention

From the White Ops heritage:

  • Invalid traffic detection
  • Ad verification
  • Publisher fraud prevention

WebDecoy’s Strengths

Honeypot Detection (HUMAN doesn’t have this)

The snippets below are illustrative examples, simplified for readability; they are not WebDecoy’s API output format.

// Illustrative example: Endpoint Decoy detection
{
  "endpoint_decoy": {
    "path": "/api/admin/users",
    "method": "POST",
    "attack_patterns": [
      { "type": "sql_injection", "severity": "critical" },
      { "type": "path_traversal", "severity": "high" }
    ],
    "score_impact": +50
  }
}

No legitimate user accesses honeypots, only bots and attackers.

Vision AI Detection (HUMAN doesn’t have this)

// Illustrative example: FCaptcha vision-agent signals
{
  "vision_ai": {
    "screenshot_loop_timing": true,  // 2-3s intervals
    "pixel_perfect_clicks": true,    // Center of element
    "movement_entropy": 0.01,        // Near-zero
    "classification": "vision_ai_agent"
  }
}

FCaptcha has signals designed to detect screenshot-driven agents such as GPT-4V, Claude Computer Use and OpenAI Operator, which can pass traditional behavioral analysis.

IP Intelligence

// Illustrative example: IP enrichment
{
  "abuseipdb": { "score": 85, "reports": 200 },
  "datacenter": true,
  "vpn": false
}

TLS Fingerprinting

// Illustrative example: TLS mismatch detection
{
  "ja4": "t13d1516h2_8daaf6152771_e5627efa2ab1",
  "claimed": "Chrome/121",
  "actual": "Playwright",
  "mismatch": true
}

Even when behavioral analysis passes, TLS fingerprints reveal the true client.

Real-World Scenarios

Scenario 1: Sophisticated Credential Stuffing

Threat: Stealth browser with human-like timing, residential proxies.

HUMAN’s Detection:

  • Behavioral biometrics: May detect anomalies over time
  • Device fingerprint: Real browser (may pass)
  • Result: Depends on behavioral deviation from baseline

WebDecoy’s Detection:

  • TLS fingerprint: Playwright signature ✅
  • Honeypot form field: Filled by bot ✅
  • IP enrichment: Datacenter IP flagged ✅
  • Result: Flagged (blocked if you turn on enforcement)

Scenario 2: Vision AI Agent (Claude Computer Use)

Threat: AI agent using screenshots and vision models.

HUMAN’s Detection:

  • Sees real browser with real mouse movements
  • Behavioral: Designed for traditional automation
  • Result: Likely passes as human

WebDecoy’s Detection: FCaptcha has signals designed for this pattern:

  • Pixel-perfect clicks
  • Screenshot loop timing (regular multi-second intervals)
  • Zero movement during “thinking”
  • Possible result: classified as a vision AI agent (no published recorded test yet)

Scenario 3: AI Content Crawler

Threat: GPTBot-style crawler scraping content.

HUMAN’s Detection:

  • Server-side crawler, no JavaScript
  • Detection: Based on User-Agent rules
  • Result: Dependent on blocklist maintenance

WebDecoy’s Detection:

  • AI crawler signature: Immediate match ✅
  • Decoy Link: Sitemap honeypot followed ✅
  • Options: monitor, allow, or block according to your policy
  • Result: Automatic detection with a response you choose

Block the Actor, Not the IP

HUMAN (formerly PerimeterX) enforces through its own sensor and API, so the block lives in HUMAN’s platform rather than infrastructure you own.

WebDecoy treats a rotating adversary as a single actor. It correlates every request into a persistent identity built from composite fingerprints: JA4 (the TLS handshake, which a proxy can’t rewrite), device signals, and cryptographic agent identity. So one scraper cycling through thousands of residential IPs collapses into one actor instead of thousands of anonymous hits.

Then enforcement follows the actor. WebDecoy is not an inline proxy: your traffic never routes through us. When an actor is a confirmed rotator with a non-browser JA4, a Block actor at WAF response action can push a JA4-based rule into your own AWS WAF, or into Cloudflare if your zone has Bot Management (Cloudflare’s Enterprise add-on), so the block follows the actor across the IPs it rotates to. The rule lives in your account where you can inspect it, and it is never built from a browser-like fingerprint real users could share. Automatic blocking from detections is held off until scores are calibrated, so today you review and apply blocks yourself.

Deep dive: Defeat IP Rotation: Block Bots by JA4 at the WAF

Pricing Comparison

HUMAN Security

  • Enterprise pricing with custom quotes
  • Typically thousands to tens of thousands per year
  • Includes enterprise support and SLAs
  • Contact sales for pricing

WebDecoy

PlanPricePropertiesStored eventsFeatures
Free$01 property5,000 stored events/moContinuous detection, seven days of detail
Starter$20/mo3 properties50,000 stored events/mo90-day history, webhooks, basic response actions
Pro$99/mo10 properties500,000 stored events/moFull enrichment, persistent actor identity, integrations, enforcement
Agency$299/mo25 properties2,000,000 pooled stored events/moClient reporting and everything in Pro

WebDecoy keeps detection running on every tier. See the current pricing page for the source of truth.

When to Choose Each

Choose HUMAN If:

  • Account takeover is your primary concern
  • You need comprehensive fraud detection (not just bots)
  • Ad fraud prevention is important
  • You need mobile SDK support
  • You have enterprise budget

Choose WebDecoy If:

  • Bot detection is your primary concern
  • You need to detect vision AI agents
  • You want honeypot-based detection
  • You prefer transparent, explainable detection
  • You have budget constraints
  • You need SIEM integration without enterprise pricing

Use Both Together

For maximum coverage:

  • HUMAN: Behavioral biometrics, ATO prevention, ad fraud
  • WebDecoy: Honeypots, vision AI detection, TLS fingerprinting

What WebDecoy Provides

  1. Multi-Signal Detection - TLS + IP + Geo + Behavioral + Honeypots
  2. Vision AI Detection - FCaptcha has signals designed to detect screenshot-driven agents such as GPT-4V, Claude Computer Use and Operator
  3. Honeypot Technology - Decoy Links and Endpoint Decoys
  4. IP Enrichment - AbuseIPDB reputation plus VPN, proxy and datacenter detection
  5. Geographic Consistency - Timezone/language/IP correlation
  6. Transparent Detection - See exactly which signals triggered
  7. SIEM Integration - Splunk, CrowdStrike Falcon LogScale and Datadog on every paid plan
  8. Accessible Pricing - A free plan, then $20 to $299/month vs enterprise quotes

Get Started

Try WebDecoy: Start Your Free Trial and see multi-signal detection in action.

Questions? Contact us to discuss your threat model.

Frequently Asked Questions

Is PerimeterX the same as HUMAN Security?

Yes. PerimeterX merged with White Ops in 2021 and rebranded to HUMAN Security. The bot detection product is now HUMAN Bot Defender.

What's the main difference between HUMAN and WebDecoy?

HUMAN specializes in behavioral biometrics and comprehensive fraud detection. WebDecoy uses multi-signal detection including honeypots, TLS fingerprinting, vision AI detection, and IP enrichment. Different approaches with different strengths.

Can WebDecoy detect vision AI agents like GPT-4V?

WebDecoy's FCaptcha has signals designed to detect vision AI agents (GPT-4V, Claude Computer Use, OpenAI Operator), such as screenshot loop timing, pixel-perfect clicks, and movement entropy. We have not yet published a recorded test against these agents.

Which is more expensive, HUMAN or WebDecoy?

HUMAN is enterprise-priced (typically thousands to tens of thousands per year). WebDecoy has transparent pricing: a free plan, then $20 to $299/month depending on tier.

Need help choosing a bot protection solution?

Our team can help you compare options and find the right fit for your needs.

Talk to an Expert