Privacy-first • Server-verified
Stop bots and abuse without handing your visitors' data to Big Tech. Sentinel pairs a server-verified proof-of-work captcha with the deepest self-owned IP-reputation engine — geo, ASN, datacenter, VPN, Tor and abuse intelligence, all under your control.
One lightweight script scores every visitor on IP reputation and behavior, challenges only the risky ones, and lets real people straight through — all on infrastructure we run ourselves.
Every signal is computed on infrastructure you own. No third-party trackers, no data sales, no surprises.
No fingerprinting, no cross-site tracking, and we never sell or share visitor data. Only coarse, non-PII signals are collected.
The browser solves a SHA-256 challenge; the hash is recomputed and verified server-side. The work is real and cannot be faked.
Challenge difficulty scales with the visitor's live risk band — clean traffic glides through, risky traffic works harder.
Pointer entropy, automation tells and headless signals feed a bot-likelihood score that flags or blocks automation.
Country, ASN and ASN org plus datacenter, VPN, Tor, proxy and abuse classification — built from data we own, not rented.
Your reputation lookups stay yours. Sentinel is built privacy-first, so your security posture is never someone else's product.
The big providers verify humans. Sentinel verifies humans and tells you exactly who is connecting — without selling the answer.
| Capability | Redeyed | reCAPTCHA | hCaptcha | Cloudflare Turnstile |
|---|---|---|---|---|
| Privacy-first (no tracking / no data sales) | Yes | No | Partial | Partial |
| Self-owned data | Yes | No | No | No |
| Server-verified proof-of-work | Yes | No | No | Partial |
| Adaptive, risk-based difficulty | Yes | Partial | Partial | Partial |
| Built-in IP-reputation depth (ASN, VPN, Tor, abuse) | Deep | No | No | Basic |
| Datacenter / proxy / Tor classification | Yes | No | No | Partial |
| Queryable reputation API | Yes | No | No | No |
If drops, restocks or limited releases are being taken by automation, you already know the stack: residential proxy pools, a solver API, and a few hundred tasks queued for the second the product goes live. Sentinel is built against exactly that stack — because the puzzle was never the part that decided anything.
At the top of the risk scale there is no puzzle to solve, because no puzzle is issued. Challenge cost scales with how much the connection is trusted: clean visitors barely notice it, and the worst never get something solvable in the first place. That inverts the economics the whole bot market runs on — the operator pays more per attempt precisely as their attempts get less likely to work.
Three steps to bot-resistant, reputation-aware verification.
Add one script tag and a <div class="redeyed-captcha"> to your form. The widget mounts itself — no build step.
Sentinel issues an adaptive proof-of-work challenge scored against the visitor's live IP reputation and behavior.
Your backend posts the token + your Secret Key to /captcha/siteverify (reCAPTCHA-style, no API key) and receives a passed / challenged / blocked outcome with a score.
Lightweight, self-contained and server-verified. Most visitors just tick a box — the harder challenges only appear when the risk score asks for them.
Challenge type
Colour scheme
Live, server-verified widget. Only one challenge exists at a time.
Keep your markup and your server code. Sentinel answers the same verify endpoints
and ships shims for grecaptcha, hcaptcha and
turnstile — so an existing integration keeps working while you swap
the keys. Most migrations are a script tag and a secret.
Already rendering <div class="g-recaptcha" data-sitekey>? Sentinel picks it up and mounts itself in place. No template changes.
The JS API surface (render, reset, getResponse) is shimmed, and the verify call keeps the same request and response shape.
Official plugins for WordPress, Joomla, Drupal, MyBB, XenForo and vBulletin — per-form control and a block log, no editing templates.
Pick one per site, or let Sentinel escalate on its own. Every type is verified entirely server-side — nothing is decided in the browser, and no third party is ever involved.
Recommended. Clean traffic gets a low-friction proof; elevated risk escalates to fresh procedural reasoning challenges.
data-widget="adaptive"
One click. Pointer entropy, timing and focus signals decide in the background — no puzzle at all.
data-widget="behavioral"
Fully invisible. The browser solves a SHA-256 challenge and the hash is recomputed server-side, so the work cannot be faked.
data-widget="pow"
Hold the button until it fills. Reads pressure and steadiness — trivial for a person, awkward for a script.
data-widget="press_hold"
Drag the missing piece into the gap. Drawn procedurally on canvas, so there are no image assets to scrape or pre-solve.
data-widget="image_puzzle"
Turn the shape upright. Also generated on canvas from the challenge seed — every render is unique.
data-widget="rotate_align"
Choose the image that matches the prompt. Familiar to anyone who has met a captcha, without the roads and traffic lights.
data-widget="image_pick"
A short arithmetic question with no dragging or fine motor control.
data-widget="text_math"
Reason about distance and containment in a one-time scene instead of recognizing a reusable stock photograph.
data-widget="relational_scene"
Follow independent moving objects through time and identify which one reaches the marked destination.
data-widget="motion_track"
Identify which cast shadow is physically consistent with a visible light source in a procedurally generated scene.
data-widget="light_shadow"
Spot the two 3D objects that match — the question rotates between same shape and same colour. The scene, palette and prompt are generated fresh every time, so there is nothing to memorise or pre-solve.
data-widget="shape_match"
A key lists objects with a required quantity; find every one of them in the grid. Counting and shape recognition together — and selecting everything fails, so it cannot be brute-forced.
data-widget="count_match"
Friction scales with risk. Clean visitors get a single round. Riskier traffic is asked for two or three, and anything already known to be malicious never gets a solvable challenge at all. Difficulty tunes itself from 0–6 on the same signal, so real people rarely notice the ceiling exists.
Match Sentinel to your brand. Every scheme composes with a light, dark or auto theme — every palette below is live in the demo further up the page. The three animated schemes add a moving backdrop and unlock on any paid plan.
One install, one widget tag, one verify call. Works the same everywhere — free until your keys are set.
Sentinel plugins & SDKs for every framework, CMS, and mobile platform — free and MIT-licensed.
github.com/Brutednpm i @redeyed_/sentinel-react
View on GitHub
npm i @redeyed_/sentinel-nextjs
View on GitHub
npm i @redeyed_/sentinel-vue
View on GitHub
npm i @redeyed_/sentinel-angular
View on GitHub
composer require redeyed/sentinel-laravel
View on GitHub
pip install redeyed-sentinel-django
View on GitHub
npm i @redeyed_/sentinel-react-native
View on GitHub
Every figure below is a live count from the intelligence table — not a marketing number.
Not every match is equally certain, so we record which kind of evidence each range rests on and weight the score accordingly. A network-level match never counts the same as a published exit node.
Confirmed — the provider publishes this host as an exit node.
Likely — a block dense enough with published exits to be one pool.
Network-level — the operator sells VPN capacity, so treated as a weak signal.
Enumeration ran 5 hours ago — the corpus is current.
The captcha is free up to 1,000,000 verifications a year — no card, no trial clock. Sentinel Pro unlocks the developer IP-reputation API — geo, ASN, VPN/proxy/Tor/datacenter and abuse signals — from $29/mo. Privacy-first, no Google.
Free captcha for every account. The IP-reputation API is a $29/mo Sentinel Pro add-on — start free, upgrade when you need the API.