# One explained decision for every request

Source: https://kavralab.com/platform/

**Kavra** reads each visit on several layers at once (network, device and environment, browser integrity, behavior, identity and history), weighs the evidence with an AI/ML risk engine and returns an explained assessment with a recommended action. Your backend decides what happens; the visitor never has to do anything.

## How a decision is made

1. **The script loads from Kavra's edge**: A small script on your page (under 64 KB, loaded asynchronously) starts on Kavra's own edge network, so the very first request already carries evidence about the connection.
2. **Signals are collected in the background**: The script reads the browser and device environment without any action from the visitor and sends it in an encrypted envelope.
3. **Kavra weighs the evidence**: Every layer is checked on its own and against the others. The AI/ML risk engine looks for the contradictions a disguise leaves behind.
4. **Your page receives a signed token**: The token is short-lived, single-use and bound to the action it was issued for, such as signup, login or checkout.
5. **Your backend gets the assessment**: One server call redeems the token and returns the classification, the findings and a recommendation. Your rules decide: allow, verify or block.

## The layers Kavra reads

A disguise can polish the layer it controls. It rarely keeps every layer consistent at once.

| Layer | What is read | Why it is hard to fake |
|---|---|---|
| Network | Where the connection really comes from: IP reputation, proxy, VPN and datacenter classification, network owner, velocity | Observed by Kavra's edge, not reported by the browser; includes Kavra's own measurements of commercial proxy exits |
| Device and environment | Graphics, screen, hardware, fonts and system settings the device exposes | Measured values are compared with what the device claims to be |
| Browser integrity | Whether the browser is genuine or automated, and whether it has been modified | Automation and tampering leave artifacts in the running browser |
| Behavior | How the visitor moves, types and navigates | Scripts and farms produce patterns that differ from people |
| Identity and history | Whether this device has been seen before, under which accounts, and how it changed | A changed fingerprint on the same actor is kept as one actor with a rotation, not a new visitor |
| AI/ML risk engine | Weighs all layers together into risk by domain | No single signal can push a score to certainty on its own |

## What counts as a data point

Kavra analyzes **3,000+ data points** on a visit. A data point is one measured property: a network attribute, a device or graphics value, a browser behavior, a timing, or a comparison between two of them. Not every data point is available on every device or browser, so each assessment also reports how much Kavra could see (coverage), and a thinly observed visit is never presented as a clean one.

## What your backend receives

| Field | What it tells you |
|---|---|
| Client classification | Likely human, automation, verified bot, verified AI agent, declared but unverified bot, or unknown, with the bot's name and operator when known |
| Risk by domain | None, low, elevated or high for automation, impersonation, network and tampering |
| Headline | One sentence a person can read, for example "Automation: HTTP library impersonating Chrome" |
| Findings | The specific checks that fired, each with a title and severity |
| Network context | Country, network owner, network class (residential, datacenter, mobile), privacy service and IP risk |
| Recommendation | Allow, verify or block under your policy preset (cautious, balanced or strict) |

## Built around your decision

- **Allow, verify or block**: Kavra recommends; your code applies your rules. Verify can mean a one-time code, 3-D Secure, a held reward or a manual review, whatever fits the action.
- **Observe-only mode**: See every assessment on your real traffic before any decision changes for your customers.
- **Good bots and AI agents**: Verified crawlers and agents are recognized by cryptographic signatures and published IP ranges and reported separately. You choose to allow, check or block them.
- **Console for your team**: Search every assessment, open the evidence behind it, follow linked devices and accounts, and review trends, with roles and an audit log.

## What Kavra is and is not

**Kavra is**

- A detection and decision service with explained results
- Invisible to visitors: no puzzles, sliders or checkboxes
- Added to your site with one script and one API call
- Complementary to KYC, payment screening and your WAF

**Kavra is not**

- A CAPTCHA or challenge widget
- A CDN, firewall or DDoS scrubbing network; no DNS change is needed
- An identity document or KYC service
- A black box: every decision shows its reasons

## FAQ

### Does Kavra show anything to my visitors?

No. Every check runs in the background. When the evidence is not conclusive, Kavra runs more background checks and reports its uncertainty; any extra step, such as a one-time code, is a choice your own backend makes.

### Do I need to route my traffic through Kavra?

No. Kavra is not a proxy or CDN. You add a script to your pages and one server-side call; your DNS and hosting stay as they are.

### How fast is a decision?

The script loads asynchronously and never blocks rendering. The assessment is prepared while the visitor uses the page, so your backend has it when the protected action happens.

### Can I see why a request was flagged?

Yes. Every assessment includes a readable headline, the findings with their severity and the network context. The same explanation is available to your backend and in the console.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
