How a decision is made
- 01
The script loads from Kavra's edge
A small script on your page (under 64 KB, loaded asynchronously) starts on Kavra's own edge network, so the very first request already carries evidence about the connection.
- 02
Signals are collected in the background
The script reads the browser and device environment without any action from the visitor and sends it in an encrypted envelope.
- 03
Kavra weighs the evidence
Every layer is checked on its own and against the others. The AI/ML risk engine looks for the contradictions a disguise leaves behind.
- 04
Your page receives a signed token
The token is short-lived, single-use and bound to the action it was issued for, such as signup, login or checkout.
- 05
Your backend gets the assessment
One server call redeems the token and returns the classification, the findings and a recommendation. Your rules decide: allow, verify or block.
The layers Kavra reads
A disguise can polish the layer it controls. It rarely keeps every layer consistent at once.
| Layer | What is read | Why it is hard to fake |
|---|---|---|
| Network | Where the connection really comes from: IP reputation, proxy, VPN and datacenter classification, network owner, velocity | Observed by Kavra's edge, not reported by the browser; includes Kavra's own measurements of commercial proxy exits |
| Device and environment | Graphics, screen, hardware, fonts and system settings the device exposes | Measured values are compared with what the device claims to be |
| Browser integrity | Whether the browser is genuine or automated, and whether it has been modified | Automation and tampering leave artifacts in the running browser |
| Behavior | How the visitor moves, types and navigates | Scripts and farms produce patterns that differ from people |
| Identity and history | Whether this device has been seen before, under which accounts, and how it changed | A changed fingerprint on the same actor is kept as one actor with a rotation, not a new visitor |
| AI/ML risk engine | Weighs all layers together into risk by domain | No single signal can push a score to certainty on its own |
What counts as a data point
Kavra analyzes 3,000+ data points on a visit. A data point is one measured property: a network attribute, a device or graphics value, a browser behavior, a timing, or a comparison between two of them. Not every data point is available on every device or browser, so each assessment also reports how much Kavra could see (coverage), and a thinly observed visit is never presented as a clean one.
What your backend receives
| Field | What it tells you |
|---|---|
| Client classification | Likely human, automation, verified bot, verified AI agent, declared but unverified bot, or unknown, with the bot's name and operator when known |
| Risk by domain | None, low, elevated or high for automation, impersonation, network and tampering |
| Headline | One sentence a person can read, for example "Automation: HTTP library impersonating Chrome" |
| Findings | The specific checks that fired, each with a title and severity |
| Network context | Country, network owner, network class (residential, datacenter, mobile), privacy service and IP risk |
| Recommendation | Allow, verify or block under your policy preset (cautious, balanced or strict) |
Built around your decision
Allow, verify or block
Kavra recommends; your code applies your rules. Verify can mean a one-time code, 3-D Secure, a held reward or a manual review, whatever fits the action.
Observe-only mode
See every assessment on your real traffic before any decision changes for your customers.
Good bots and AI agents
Verified crawlers and agents are recognized by cryptographic signatures and published IP ranges and reported separately. You choose to allow, check or block them.
Console for your team
Search every assessment, open the evidence behind it, follow linked devices and accounts, and review trends, with roles and an audit log.
What Kavra is and is not
Kavra is
- A detection and decision service with explained results
- Invisible to visitors: no puzzles, sliders or checkboxes
- Added to your site with one script and one API call
- Complementary to KYC, payment screening and your WAF
Kavra is not
- A CAPTCHA or challenge widget
- A CDN, firewall or DDoS scrubbing network; no DNS change is needed
- An identity document or KYC service
- A black box: every decision shows its reasons