BotKavach doesn't just block bots, it generates the HMAC-signed forensic evidence you need to claim refunds from Google Ads and Meta. 80+ signals per click, tamper-evident dossiers, one-click email to your ad account manager. No competitor offers signed refund evidence. This is the moat.
BotKavach generates the HMAC-signed evidence you need to claim refunds from Google Ads and Meta. No competitor offers signed refund evidence. A single successful claim can recover more than a year of subscription costs. This is the feature that turns $299/month from an expense into an investment that pays for itself.
When BotKavach blocks a fake click, it logs every signal, every layer, every fingerprint, 80+ data points per click. Export a tamper-evident dossier signed with HMAC-SHA256 so the evidence is provably unmodified. Submit it to Google Ads and Meta for refund claims. No competitor offers signed refund evidence, this is the moat.
Every export includes a manifest of row hashes so you can prove no row was added, removed, or altered. CSV for spreadsheets and ad-platform portals. JSON for programmatic intake. Both formats include the full 80+ signal payload per click.
Send a complete forensic dossier to your ad account manager, your agency, or your finance team directly from the dashboard. One click, no screenshots, no manual compilation. The recipient gets a signed, self-contained evidence package.
The built-in AI assistant can pull up the full forensic detail for any click by ID, IP, or campaign. No SQL, no filters, no digging through tables. Just ask in plain English and get the complete evidence chain.
A single successful refund claim can recover more than a year of BotKavach subscription costs. Users have recovered ad credits from Google and Meta using our signed dossiers. This is the feature that turns "$299/month" from an expense into an investment that pays for itself.
The HMAC-SHA256 signature, row-hash manifest, and 80+ signal payload create an evidence chain that withstands ad-platform review, chargeback disputes, agency audits, and internal compliance reviews. Every decision BotKavach makes is backed by provable, timestamped evidence.
Start with a free audit, no signup, no script, no card. Then connect Google Ads or Meta Ads with OAuth and BotKavach monitors your campaigns through the platform's own API. No routing link, no redirect, no code on your landing page. Your existing destination URLs stay exactly as they are.
Open the audit page and you immediately see a full sample report of what BotKavach detects on a typical Meta Ads account: fake-click percentage, wasted spend per campaign, flagged clicks with the signal that caught each one, and a preview of the signed evidence dossier. Connect your own Meta Ads account to swap the sample for your real last-30-days data.
Authorise BotKavach from your dashboard with OAuth 2.0, Google Ads uses PKCE, Meta uses a long-lived token exchange. Tokens are encrypted at rest with AES-256-GCM and scoped to your account only. Disconnect any time and the tokens are deleted immediately.
This is the setup-friction unlock. Because BotKavach reads your clicks through the ad platform's own API, you don't swap a single destination URL, add a redirect, or drop a script on your landing page. Your campaigns keep running exactly as they are while monitoring starts immediately.
Meta and Google don't expose raw IPs or user-agents through their APIs, so BotKavach adds a statistical layer: any ad/day row with 3x or more the account median click count is flagged high-severity. A sudden click concentration on one ad is a classic click-fraud signature that per-click detection alone would miss.
A background job pulls recent click and spend data from every connected account, runs it through the detection layers, datacenter IPs, bot user-agents, VPN and proxy exits, AI agents, click bursts, and stores each flagged click with its campaign, country, risk score, signals, and estimated cost. You just read the results.
Every click flagged from your connected ad account carries the same forensic treatment as link-level traffic: signals, risk score, and estimated wasted spend, exportable as an HMAC-signed dossier. Connect the account, wait a few hours, then submit evidence for a refund claim, no integration work in between.
Every layer runs automatically on every click, in real time. Toggle them per campaign. No code, no config files, no developer. This is what "trust your data" looks like in practice.
BotKavach trains a model every night on your traffic, scoring every visitor across 16 signals to separate real buyers from sophisticated bots. It gets smarter on its own, so new attack patterns are caught before they cost you. You never touch a rule.
Puppeteer, Playwright, Selenium, PhantomJS, ChromeDriver and 9 more, caught and blocked before they reach your landing page. Real Chrome users never notice a thing. Your offer stays visible only to people who can actually buy.
ChatGPT, Claude, Perplexity, and other AI assistants are browsing the web on behalf of users. Some are useful. Some scrape your funnel. BotKavach detects synthetic visitors and lets you decide: block or watch. Defaults to log-only because some AI traffic is a real person's assistant.
Competitor-intel crawlers, SEO scrapers, and policy-audit bots are identified and routed to a compliance page, not your real offer. They see a legitimate content site. Your angles, your creatives, your competitive edge, protected automatically.
Multi-source detection catches VPNs, residential proxies, and Tor exits, even ones that fool basic IP checks. If it's not a real residential connection from a country you accept, it never reaches your offer.
Traffic from AWS, Google Cloud, Azure, DigitalOcean and other hosting providers is blocked on arrival. Real people don't browse from datacenters, bots do. You stop paying for clicks that were never human.
Canvas, WebGL, audio context, and font analysis create a device signature that's nearly impossible to spoof. A bot can set a Chrome user-agent, but it can't fake a real browser's fingerprint. This is where sophisticated bots fail.
TLS handshake patterns and HTTP header consistency expose automated clients, even behind residential proxies. A live known-bot catalogue auto-updates daily. If the connection doesn't match a real browser, it doesn't reach your offer.
Every browser has a WebRTC stack that can leak the real IP address behind any VPN or proxy. BotKavach checks if the WebRTC IP matches the request IP. If it doesn't, the visitor is hiding behind a VPN. They never reach your offer. This catches VPN users that basic IP checks miss completely.
Some bot farms use residential 4G connections that fool every basic IP check. The ASN looks like a real ISP. BotKavach combines five weak signals, timezone mismatch, WebRTC leak, cross-campaign velocity, geo diversity, and bot-like behavior, to catch them anyway. No single signal is enough. Together, they're hard to beat.
When a visitor clears cookies and rotates IPs, most tools see a brand new user. BotKavach groups visitors by stable fingerprint similarity instead. If five or more distinct IPs share one fingerprint, it's a bot farm. Blocked automatically. Clearing cookies doesn't help them anymore.
BotKavach now runs a hand-rolled Random Forest alongside the logistic regression model. The forest captures non-linear patterns the linear model misses, like a visitor being fine on signal A alone, but bad on A and B together. Both models retrain nightly on your traffic. You get smarter detection without touching a thing.
Geo, language, device, and schedule filters. Stop paying for clicks from countries, devices, or hours that never convert.
Allow or block by country with per-campaign rules. Browser language is cross-checked to catch VPN users whose IP says one country but whose browser is set to another.
Schedule campaigns for weekdays, weekends, or specific hours. Stop wasting budget at 3 AM when nobody buys. Included on every plan.
Send mobile and desktop visitors to different offer pages from one campaign. No duplicate streams, no extra setup.
If a visitor's IP says France but their browser is set to Russian, that's a VPN. BotKavach catches the mismatch and blocks them before they cost you money.
DNS lookup, reverse IP, SSL certificate check, HTTP header inspection - all built in. No external tools, no extra cost. Vet traffic sources and debug campaigns in seconds.
Split traffic across multiple landing pages with weighted URLs. Find the winner without a separate tracker. Built into every plan.
Click fraud detection, cross-campaign rate limiting, form fraud protection, silent bot challenges, self-hosted CAPTCHA, federated peer intelligence, false-positive measurement, auto-pause on traffic drops, and a threat feed that grows daily, all built in.
Same IP clicking 20 times in a minute? Banned. Coordinated farm hitting from multiple IPs? Auto-detected. You set the rules, or just use the defaults that work out of the box. Your budget goes to real buyers, not repeat offenders.
Click farms rotate campaigns to dodge per-campaign limits. BotKavach tracks IPs across all your campaigns at once, so switching links doesn't reset their quota. Wherever they go in your account, the limit follows them.
Bots don't just click, they fill forms. LeadShield watches keystroke timing, mouse movement, time-to-fill, honeypot fields, and disposable email domains. Suspicious leads are flagged or blocked before they hit your CRM. One toggle per campaign, no code. Fail-open: if the endpoint is down, forms still submit. No PII stored.
A silent JavaScript check stops bots without annoying real users. No CAPTCHA, no friction, no drop in conversion rate. Real visitors never know it's there. Bots never get past it.
A proof-of-work CAPTCHA with behavioral signals and honeypots. Three difficulty levels. No reCAPTCHA keys, no Cloudflare dependency, no per-call billing. Your visitor data never leaves your platform.
Any IP blocked 3+ times across the BotKavach network gets shared with everyone. Your threat list updates daily, new bad IPs are blocked before they reach you. The more campaigns run on BotKavach, the smarter every campaign gets.
Trusted BotKavach installs share threat data with each other, hashed by default, raw IPs only with explicit per-peer consent. Your blocklist learns from peers the same way it learns from your own traffic. No central authority, no third-party data broker.
Every blocked click is scored against a cohort of similar allowed visitors. When a conversion comes from an IP that was also blocked, that's a signal. You get a statistical estimate, a manual review queue, and a confirmed FP rate, transparency no other platform shows you.
BotKavach watches daily click volume per campaign and auto-pauses if traffic collapses, protecting your ad spend from a broken lander or dead proxy before it drains your budget. You wake up to an alert, not a loss.
14 external threat intelligence feeds plus crowdsourced data from BotKavach campaigns, all merged and updated daily. Bad IPs are blocked before they ever reach your offer.
Plain-English filters, compliance page generator, embed mode, live dashboard, REST API, GDPR self-service, and crypto payments, everything you need in one place.
Type something like "Block Russia and China on weekends except mobile Android" and the AI configures every filter and layer for you. No settings pages. No documentation. Just tell it what you want.
Generate real, policy-compliant content websites across 20+ niches - each with unique design, working links, and proper legal pages. Bots and auditors see a legit site. Your offer stays hidden.
Paste one snippet in your <head> and BotKavach filters any page on any domain you own. Cross-origin protection, CORS whitelist, JSON-only responses - you keep full control.
Live world map, real-time clicks feed, recent threats panel, and top-campaigns leaderboard - all in one dashboard. See exactly what's happening, right now.
Server-to-server postback and first-party pixel tracking built in. Know which campaigns convert - without paying for another tool.
Pay your subscription in BTC, ETH, or USDT directly from the dashboard. No payment processor, no card, no middleman.
A simple REST API gives you clicks, stats, campaigns, and data rights endpoints. JSON responses, CSV export, API key auth. No SDK to install. Build custom dashboards, feed your data warehouse, or plug into your existing stack. Available on Pro and above.
A self-service page lets your users download all their data as JSON or schedule account deletion with a 30-day grace period. No support ticket needed, no back-and-forth emails. Built with GDPR compliance tools so you can serve European customers without worry.
Everything you need to know about BotKavach's features and how they protect your campaigns.
<head> snippet - and LeadShield works through embed mode too.webrtc_detection_enabled (default off) so you can watch the signal first, then switch to block./api/v1/. Endpoints include paginated click lists with search and filtering, single-click forensic detail (all 80+ fields), CSV bulk export (max 10,000 rows, last 30 days), aggregate stats with custom date ranges, campaign list and detail with layer config, and GDPR data-rights actions (export and delete). Authentication is via API key in the X-API-Key header. JSON responses, standard HTTP status codes. Available on Pro and above.dashboard/data-rights.php lets your users: (1) Export all their data as a JSON file, profile, campaigns, and all click records. (2) Schedule deletion, their account status changes to pending_deletion, they lose access immediately, and a cron job hard-deletes their data after a 30-day grace period. No support ticket needed. The API also exposes these actions at /api/v1/?endpoint=data-rights.Set up a campaign in 5 minutes. See exactly how much of your traffic was never real. All layers, free to try - no card needed.