Verdict-based detection
Heretic compares browser-reported claims with measurement results from browser tests and the connection itself, then returns a verdict instead of a raw score that you still have to interpret.
Heretic detects bots and devices, returns verdicts with documented findings, and supports optional phone challenges for browser, backend, and form verification.
Heretic is a bot and device detection product that checks whether a browser’s reported claims match what the browser, network, and session measurements actually show. Instead of giving a single opaque score, it returns a verdict with specific findings and the reasons behind them.
The product is aimed at workflows where you need to decide whether to trust a session, step up verification, or stop a protected action. The site shows browser checks, optional phone challenges, and structured outputs that can be read by a backend or used in a form flow.
Heretic’s checks cover several families of evidence, including network geometry, transport stack, TLS, HTTP construction, compute behavior, and reachability. The pricing page also says every plan includes the current detection rules, available device identifiers, zero-retention mode, and phone challenges.
A typical setup starts with a browser check, and the site says the collector returns a request ID for your backend while the widget adds verification to a form. The free Sandbox includes 1,000 probes and 1,000 challenges each month with no card required.
Heretic compares browser-reported claims with measurement results from browser tests and the connection itself, then returns a verdict instead of a raw score that you still have to interpret.
The homepage shows documented finding IDs and tiers such as absolute, composite, conditional, and weak, so the result can explain what was checked and what changed the outcome.
The product supports checks across network geometry, transport stack, TLS, HTTP construction, compute behavior, and reachability, covering multiple ways a browser claim can be inconsistent.
The site describes optional phone challenges that can be required before a protected action, with a passkey step and recorded motion checks for mobile verification.
The pricing page lists site-scoped identifiers, including instance, machine, and rendering identifiers, plus zero-retention mode for one authorized read within ten seconds.
Heretic offers both a collector and a widget, letting teams run browser checks for backend decisions or add verification to a form without mixing the product into application traffic.
Use Heretic to evaluate whether a browser session is consistent with its claimed timezone, platform, device characteristics, and connection behavior before letting a user proceed.
Apply a phone challenge when a policy needs stronger proof before a sensitive action such as signup or another protected step. The site shows the challenge can be required by policy.
Use the collector to send a request ID to your backend and make an access decision based on the returned verdict and findings, rather than a raw score alone.
Add the widget to a form when you want verification in the user flow itself, while keeping Heretic separate from your application traffic.
Review documented findings and their tiers when you need to understand why a session was flagged, especially for cases that look contradictory, refused, or only conditionally suspicious.
Start with a browser check in the Sandbox. The homepage says you can test this browser there, and the signup page notes the Sandbox includes 1,000 probes and 1,000 challenges per month with no card required.
Heretic returns a verdict such as contradicted, refused, or uncontradicted, along with documented findings and their IDs. The homepage and API example show that the response includes the reasons behind the decision.
The site shows both a collector and a widget. The collector checks a browser session and sends a request ID to your backend, while the widget adds verification to a form.
The pricing page says paid plans include current detection rules, available device identifiers, zero-retention mode, and phone challenges. The same page also notes that plans differ mainly in included usage and commercial terms.
The pricing page says allowance resets on the first day of each UTC month, plan changes are prorated by Stripe, and overage is billed on paid plans. Enterprise terms are handled separately.
EAS Observe monitors production performance in Expo and React Native apps, showing startup metrics, session timelines, release markers, and errors in the Expo dashboard.
ByteAsk is a terminal-first AI coding agent for C and C++ that edits repos and verifies changes with compilers, debuggers, sanitizers, and tests.
PromptScout tracks how ChatGPT, Gemini, Google AI Overviews, and Perplexity mention your brand or competitors, with source analysis and website audits.
Sleek Analytics is a privacy-friendly web analytics tool with real-time visitor tracking, Core Web Vitals, and revenue attribution.
MacSpoof is a macOS MAC address changer that lets you change or randomize your Wi‑Fi MAC to reconnect and limit device logging on public Wi‑Fi.
Manta AI is an autonomous web app testing tool that maps app behavior, catches regressions, and generates tests from a URL, no scripts or selectors needed.