Detection engines make good defaults.
But you know your audience: where they live, what devices they use, and what has no business touching your site.
ZeroBot lets you encode that knowledge per domain.
All configurable per protected domain, from the dashboard or the API.
Serve only the markets you operate in, or shut out regions your traffic never legitimately comes from.
Independent toggles for VPN, Tor and datacenter traffic — the classic hiding places of automation.
Restrict which device classes are allowed when your campaign or product only serves specific ones.
Turn the built-in captcha on selectively — with your own logo — as an escalation for suspicious traffic rather than a wall for everyone.
Choose where blocked visitors land: a block page, or any redirect link you configure.
Wire a bot token and chat ID to get pinged as detections happen — no dashboard-watching required.
Your rules run on top of the scoring pipeline — fingerprinting, JS validation, IP reputation — so a permissive rule set still catches automation, and a strict one still lets whitelisted users through.
Per-account whitelisting overrides every rule and every detection layer. You can never lock out your own office, your monitoring, or a VIP customer.
Rules are configured per protected domain, so a strict setup on your admin panel can coexist with a permissive one on your public site — wildcard domains are supported.
You decide: block it, send it to a redirect link of your choice, or challenge it with the built-in captcha (brandable with your own logo).
Yes — connect a Telegram bot token and chat ID to any rule set and receive alerts as detections happen.
Yes. The full rules surface is available over the REST API alongside domains, traffic logs and whitelist/blacklist management.
Country, infrastructure, device and captcha rules — live in minutes.
Free tier included.