PerimeterX (HUMAN) vs WebDecoy
HUMAN Security vs WebDecoy. Behavioral biometrics and fraud detection vs multi-signal bot detection with honeypots and vision AI.
PerimeterX merged with White Ops in 2021 and rebranded to HUMAN Security. HUMAN offers comprehensive fraud detection with behavioral biometrics. WebDecoy provides multi-signal bot detection with honeypots, TLS fingerprinting, and vision AI detection.
This comparison explains the technical differences and when each makes sense.
Detection Architecture
HUMAN: Behavioral Biometrics
User Request
↓
HUMAN JavaScript (client-side)
├── Behavioral Biometrics
│ ├── Mouse movement patterns
│ ├── Keystroke dynamics
│ ├── Touch gestures (mobile)
│ └── Scroll patterns
├── Device Fingerprinting
│ ├── Canvas/WebGL/Audio
│ └── Browser characteristics
├── JavaScript Challenges
└── ML Bot Score
↓
Allow / Challenge / BlockHUMAN’s focus: Behavioral biometrics to distinguish humans from bots based on how they interact, plus comprehensive fraud detection.
WebDecoy: Multi-Signal Detection
User Request
↓
WebDecoy Detection Stack
├── TLS Fingerprinting (JA3/JA4)
│ └── User-Agent mismatch detection
├── IP Enrichment
│ ├── AbuseIPDB reputation plus VPN, proxy and datacenter detection
│ └── Datacenter/VPN/Tor detection
├── Geographic Consistency
│ └── Timezone/IP/Language correlation
├── Honeypot Detection
│ ├── Decoy Links (hidden spider traps)
│ └── Endpoint Decoys (fake API routes)
├── Behavioral Analysis (Bot Scanner)
│ └── Mouse entropy, keystrokes, forms
└── Vision AI Detection (FCaptcha)
└── Signals designed for screenshot-driven agents
↓
Threat Score (0-100) → Allow / Challenge / BlockWebDecoy’s focus: Multiple independent detection signals that catch threats the others miss.
Detection Method Comparison
| Capability | HUMAN Security | WebDecoy |
|---|---|---|
| Behavioral Biometrics | Primary method (deep analysis) | Included (Bot Scanner) |
| Device Fingerprinting | Extensive (100+ signals) | TLS fingerprinting only (JA3/JA4) |
| Honeypots | No | Decoy Links + Endpoint Decoys |
| IP Intelligence | HUMAN network | AbuseIPDB reputation plus VPN, proxy and datacenter detection |
| Geographic Checks | Basic | Timezone/IP/Language consistency |
| Vision AI Detection | No | FCaptcha signals designed for screenshot-driven agents |
| AI Crawler Detection | Via bot rules | Registry of 186 known bots and AI agents |
| Account Takeover Focus | Strong (primary use case) | Included (credential stuffing) |
| Ad Fraud Prevention | Yes (White Ops heritage) | No |
| Mobile SDK | Yes | No |
| SIEM Integration | Enterprise | Every paid plan (Splunk, CrowdStrike Falcon LogScale, Datadog) |
Key Differences
HUMAN’s Strengths
Behavioral Biometrics Depth
HUMAN has deep behavioral analysis from years of focus:
- Mouse movement entropy and velocity curves
- Keystroke timing patterns and rhythm
- Touch pressure and gesture analysis (mobile)
- Session-long behavioral profiling
Account Takeover Prevention
HUMAN excels at ATO with:
- Device trust across sessions
- Behavioral consistency scoring
- Risk-based authentication integration
Ad Fraud Prevention
From the White Ops heritage:
- Invalid traffic detection
- Ad verification
- Publisher fraud prevention
WebDecoy’s Strengths
Honeypot Detection (HUMAN doesn’t have this)
The snippets below are illustrative examples, simplified for readability; they are not WebDecoy’s API output format.
// Illustrative example: Endpoint Decoy detection
{
"endpoint_decoy": {
"path": "/api/admin/users",
"method": "POST",
"attack_patterns": [
{ "type": "sql_injection", "severity": "critical" },
{ "type": "path_traversal", "severity": "high" }
],
"score_impact": +50
}
}No legitimate user accesses honeypots, only bots and attackers.
Vision AI Detection (HUMAN doesn’t have this)
// Illustrative example: FCaptcha vision-agent signals
{
"vision_ai": {
"screenshot_loop_timing": true, // 2-3s intervals
"pixel_perfect_clicks": true, // Center of element
"movement_entropy": 0.01, // Near-zero
"classification": "vision_ai_agent"
}
}FCaptcha has signals designed to detect screenshot-driven agents such as GPT-4V, Claude Computer Use and OpenAI Operator, which can pass traditional behavioral analysis.
IP Intelligence
// Illustrative example: IP enrichment
{
"abuseipdb": { "score": 85, "reports": 200 },
"datacenter": true,
"vpn": false
}TLS Fingerprinting
// Illustrative example: TLS mismatch detection
{
"ja4": "t13d1516h2_8daaf6152771_e5627efa2ab1",
"claimed": "Chrome/121",
"actual": "Playwright",
"mismatch": true
}Even when behavioral analysis passes, TLS fingerprints reveal the true client.
Real-World Scenarios
Scenario 1: Sophisticated Credential Stuffing
Threat: Stealth browser with human-like timing, residential proxies.
HUMAN’s Detection:
- Behavioral biometrics: May detect anomalies over time
- Device fingerprint: Real browser (may pass)
- Result: Depends on behavioral deviation from baseline
WebDecoy’s Detection:
- TLS fingerprint: Playwright signature ✅
- Honeypot form field: Filled by bot ✅
- IP enrichment: Datacenter IP flagged ✅
- Result: Flagged (blocked if you turn on enforcement)
Scenario 2: Vision AI Agent (Claude Computer Use)
Threat: AI agent using screenshots and vision models.
HUMAN’s Detection:
- Sees real browser with real mouse movements
- Behavioral: Designed for traditional automation
- Result: Likely passes as human
WebDecoy’s Detection: FCaptcha has signals designed for this pattern:
- Pixel-perfect clicks
- Screenshot loop timing (regular multi-second intervals)
- Zero movement during “thinking”
- Possible result: classified as a vision AI agent (no published recorded test yet)
Scenario 3: AI Content Crawler
Threat: GPTBot-style crawler scraping content.
HUMAN’s Detection:
- Server-side crawler, no JavaScript
- Detection: Based on User-Agent rules
- Result: Dependent on blocklist maintenance
WebDecoy’s Detection:
- AI crawler signature: Immediate match ✅
- Decoy Link: Sitemap honeypot followed ✅
- Options: monitor, allow, or block according to your policy
- Result: Automatic detection with a response you choose
Block the Actor, Not the IP
HUMAN (formerly PerimeterX) enforces through its own sensor and API, so the block lives in HUMAN’s platform rather than infrastructure you own.
WebDecoy treats a rotating adversary as a single actor. It correlates every request into a persistent identity built from composite fingerprints: JA4 (the TLS handshake, which a proxy can’t rewrite), device signals, and cryptographic agent identity. So one scraper cycling through thousands of residential IPs collapses into one actor instead of thousands of anonymous hits.
Then enforcement follows the actor. WebDecoy is not an inline proxy: your traffic never routes through us. When an actor is a confirmed rotator with a non-browser JA4, a Block actor at WAF response action can push a JA4-based rule into your own AWS WAF, or into Cloudflare if your zone has Bot Management (Cloudflare’s Enterprise add-on), so the block follows the actor across the IPs it rotates to. The rule lives in your account where you can inspect it, and it is never built from a browser-like fingerprint real users could share. Automatic blocking from detections is held off until scores are calibrated, so today you review and apply blocks yourself.
Deep dive: Defeat IP Rotation: Block Bots by JA4 at the WAF
Pricing Comparison
HUMAN Security
- Enterprise pricing with custom quotes
- Typically thousands to tens of thousands per year
- Includes enterprise support and SLAs
- Contact sales for pricing
WebDecoy
| Plan | Price | Properties | Stored events | Features |
|---|---|---|---|---|
| Free | $0 | 1 property | 5,000 stored events/mo | Continuous detection, seven days of detail |
| Starter | $20/mo | 3 properties | 50,000 stored events/mo | 90-day history, webhooks, basic response actions |
| Pro | $99/mo | 10 properties | 500,000 stored events/mo | Full enrichment, persistent actor identity, integrations, enforcement |
| Agency | $299/mo | 25 properties | 2,000,000 pooled stored events/mo | Client reporting and everything in Pro |
WebDecoy keeps detection running on every tier. See the current pricing page for the source of truth.
When to Choose Each
Choose HUMAN If:
- Account takeover is your primary concern
- You need comprehensive fraud detection (not just bots)
- Ad fraud prevention is important
- You need mobile SDK support
- You have enterprise budget
Choose WebDecoy If:
- Bot detection is your primary concern
- You need to detect vision AI agents
- You want honeypot-based detection
- You prefer transparent, explainable detection
- You have budget constraints
- You need SIEM integration without enterprise pricing
Use Both Together
For maximum coverage:
- HUMAN: Behavioral biometrics, ATO prevention, ad fraud
- WebDecoy: Honeypots, vision AI detection, TLS fingerprinting
What WebDecoy Provides
- Multi-Signal Detection - TLS + IP + Geo + Behavioral + Honeypots
- Vision AI Detection - FCaptcha has signals designed to detect screenshot-driven agents such as GPT-4V, Claude Computer Use and Operator
- Honeypot Technology - Decoy Links and Endpoint Decoys
- IP Enrichment - AbuseIPDB reputation plus VPN, proxy and datacenter detection
- Geographic Consistency - Timezone/language/IP correlation
- Transparent Detection - See exactly which signals triggered
- SIEM Integration - Splunk, CrowdStrike Falcon LogScale and Datadog on every paid plan
- Accessible Pricing - A free plan, then $20 to $299/month vs enterprise quotes
Get Started
Try WebDecoy: Start Your Free Trial and see multi-signal detection in action.
Questions? Contact us to discuss your threat model.
Frequently Asked Questions
Is PerimeterX the same as HUMAN Security?
Yes. PerimeterX merged with White Ops in 2021 and rebranded to HUMAN Security. The bot detection product is now HUMAN Bot Defender.
What's the main difference between HUMAN and WebDecoy?
HUMAN specializes in behavioral biometrics and comprehensive fraud detection. WebDecoy uses multi-signal detection including honeypots, TLS fingerprinting, vision AI detection, and IP enrichment. Different approaches with different strengths.
Can WebDecoy detect vision AI agents like GPT-4V?
WebDecoy's FCaptcha has signals designed to detect vision AI agents (GPT-4V, Claude Computer Use, OpenAI Operator), such as screenshot loop timing, pixel-perfect clicks, and movement entropy. We have not yet published a recorded test against these agents.
Which is more expensive, HUMAN or WebDecoy?
HUMAN is enterprise-priced (typically thousands to tens of thousands per year). WebDecoy has transparent pricing: a free plan, then $20 to $299/month depending on tier.
Need help choosing a bot protection solution?
Our team can help you compare options and find the right fit for your needs.