loader
Research
Privacy & Identity

reCAPTCHA Alternatives: What Actually Differs

Every captcha claims privacy and accuracy. The real differences are where the decision is made, what leaves your site, and what happens to users the model dislikes.

The comparison most articles get wrong

Captcha comparisons usually rank products on accuracy and price. Both are close to unmeasurable from the outside — accuracy depends entirely on the traffic mix a given site sees, and published pricing rarely survives contact with a real volume negotiation.

The differences that actually matter are structural, and they are visible without a trial: where the risk decision is computed, what data leaves your site to get there, what the user experiences when the score is unfavourable, and what it costs to leave.

Where the decision happens

Every modern captcha scores rather than tests. The visible challenge, if there is one, is a consequence of the score rather than the substance of it.

That score is computed somewhere, and the location has consequences. If it is computed by a provider whose primary business is advertising, the signals that make the score good — device consistency, behavioural history, cross-site recognition — are the same signals that make ad targeting good. That is not an accusation of misuse; it is an observation that the data has a second value to that company and none to you.

If it is computed by a provider whose business is only security, the incentive is narrower. If it is computed on infrastructure you control, the question does not arise at all.

Ask a concrete version of the question rather than an abstract one: does the vendor set a cookie or persist an identifier on your visitors, and is that identifier readable by the vendor across other sites? The answer determines whether your captcha is also a tracker.

What leaves the page

Every provider receives something. The meaningful differences are how much, and what it is joined to.

At minimum a captcha sees the visitor's IP address, user agent and the referring page — enough to know who visited which page on your site and when. Most also collect interaction telemetry: pointer movement, timing, keystroke cadence, and device and browser characteristics.

The question worth asking is whether that data is scoped to your site or pooled across the provider's whole customer base. Pooling genuinely improves detection — an address abusing one site is useful evidence elsewhere — and it also means your visitors are profiled through infrastructure you have no relationship with. Both statements are true, and the trade is legitimate; it should be a decision rather than a default.

For anyone operating under GDPR or similar regimes, this determines whether the provider is a processor acting on your instructions or something closer to a joint controller. That is a documentation question with real consequences, and the answer varies by provider.

What happens to users the model dislikes

This is the criterion most comparisons skip, and it is the one users experience.

Some visitors will always score poorly through no fault of their own: people on shared or carrier-grade NAT connections, on VPNs, on older devices, with tracker blocking, using assistive technology, or in regions with sparse training data. What the product does to those people is a product decision, not a technical inevitability.

The failure modes differ. Some providers escalate to image challenges that become progressively harder and can trap a legitimate user in an unwinnable loop. Some fail closed and simply refuse. Some fall back to an audio challenge that is worse than the visual one. Some degrade to a low-friction proof-of-work check that costs the device a moment of computation and lets the user through.

Ask any vendor what the worst experience their system produces looks like, and how often it occurs. A vendor who has thought about it will have an answer; the answer tells you how much of your conversion rate you are trading for bot defence.

Proof of work as an alternative axis

An increasingly common design asks the browser to perform a small computation instead of asking the human to solve a puzzle. The cost is trivial for one legitimate visitor and meaningful for an attacker making millions of attempts.

Its appeal is that it degrades honestly. A visitor who looks unusual pays a slightly longer computation rather than being handed an image grid, which is a far better failure mode for accessibility and conversion. It also requires no judgement about whether a person is a person.

It is not a complete answer. A determined attacker with budget can absorb the computation, and the technique does nothing against a human solving service. It works best as one signal among several rather than as the whole decision — which is true of every technique in this category.

Migration cost, and the lock-in nobody prices

The switching cost is usually underestimated in one direction and overestimated in the other.

Overestimated: the client-side integration. Most providers expose a near-identical shape — a script tag, a container element, a token in the form, a server-side verification call. Some deliberately accept the exact endpoints and response field names of the incumbents so that switching requires changing a hostname rather than rewriting logic. If you are evaluating, check whether the candidate offers this, because it removes most of the work.

Underestimated: everything around the widget. Allow-lists built up over years, per-form tuning, exceptions for particular partners, and the accumulated knowledge of which thresholds cause complaints. That configuration is rarely portable and rarely documented, and it is the real reason migrations stall.

Before committing, ask whether the risk decision can be exported — whether you can obtain the score and the reasons for it through an API rather than only a pass/fail. A provider that will tell you why it made a decision is a provider you can leave.

A short evaluation checklist

  • Where is the score computed, and by a company in what business?
  • Does the provider set a cross-site identifier on my visitors?
  • Is telemetry scoped to my site or pooled? Is that disclosed in my privacy notice?
  • What is the worst experience a legitimate user can have, and how often does it happen?
  • Is there a non-visual fallback that is not worse than the visual one?
  • Can I retrieve the score and its reasoning, or only the verdict?
  • Does it accept the incumbent's integration shape, so migration is a hostname change?
  • What is the free ceiling, and is it a plan or a trial?

None of these require a proof of concept, and together they separate products far more reliably than a published accuracy figure.