German startupthe Vinishu SDK is live

Stop Bots & Fraud
through invisible protection

Vinishu is a drop-in SDK: one script tag, one verify call. It spots bots, fraud and automated abuse and answers with valid and score. Your route does the blocking - without a single CAPTCHA.

Integration
One script tag

Drop in the script tag, put the verify call in your route, write your rule around it. That is the whole install.

Decision
In your route

Vinishu answers with valid and score - blocking, throttling or letting through stays in your code.

Never read
The body

We look at TLS posture, headers and request shape - never the body. Your payload stays with you.

Coverage
Worldwide

Vinishu regions on every populated continent. Your verify call lands in the closest healthy region automatically - no per-region configuration required.

Two ways to protect

One line of code today. All your traffic later.

Same engine, two integrations. The SDK ships today. The reverse proxy follows.

Lightweight - keep your stack

SDK Integration

Drop a tiny script onto your page. It generates a session per browser. Your API verifies the session with Vinishu on each request - no proxying, no DNS changes, just a tiny request.

  • 01
    One-line install
    Add the script tag and Vinishu starts to validate, without delay.
  • 02
    Collect and Validate
    Vinishu collects browser data and validates it in the backend, without the user lifting a finger.
  • 03
    Server-side verify
    Your API calls our /verify endpoint and gets back valid and score. What follows from that lives in your code.
  • 04
    Keeps your stack
    No DNS move, no new route for your traffic. Very easy to integrate, also in big stacks.
index.html
+<script src="https://sdk.vinishu.io/v3.js">
+ async></script>
#On your API, per request:
→POST https://api.vinishu.io/verify
{ cookie: req.cookies.vn_id }
✓200 OK · { valid: true, score: 0.98 }
CapabilitySDK IntegrationReverse ProxyComing soon
Bot detectionYesYes
TLS-VerificationYesYes
TLS termination—Yes
Rate limitingPartialYes
DDoS absorption—Yes
DNS change required—Yes
Code changes required1 script tagNone
Dashboard accessYesYes
Capabilities

Everything your engineering-team actually needs. Nothing they don't.

Built for engineers who ship. Vinishu replaces bot managers and CAPTCHA with one SDK that answers a single question: real or automated. Your WAF stays - it filters payloads, we answer something else.

Invisible bot defense

Every request gets validated - without CAPTCHAs. Legitimate users pass without interference; automation is stopped.

Extended analysis

We check every browser, including its IP, every time. That catches sophisticated bots that spoof fingerprints and rotate through proxy pools.

Optimised validation

Geo-DNS routes your verify call to the closest Vinishu region. Your traffic stays where it is - only the question about the verdict takes the short path.

Explainable decisions

Every request, every decision, every block is accessible live. Not just batched reports.

Works with any stack

Vinishu drops into virtually any stack, with little work.

Simple but effective rules

Rules are simple to write, without overcomplicated options your team doesn't know. We make the decisions for you.

How it works

Protection that thinks - before anything gets through.

Vinishu scores every single request and answers with valid and score. The threshold in your code turns that into pass, throttle or block. Today through the SDK inside your stack, later through the reverse proxy in front of it.

An SDK that asks - before your API answers.

01
The script tag loads
A small script on your page collects browser signals and picks up a signed session. Your user notices nothing.
02
The request carries the session
Login, checkout, API call - the session rides along, without you touching a single form.
03
Your API asks once
One verify call with the session ID. Answer in 8–10 ms: valid, score and two IDs to look it up with.
04
Your API decides
We hand you valid and score. Your threshold turns that into pass, throttle or block. The rule stays in your code.
A better way

Your users shouldn't have to prove they're human.

CAPTCHAs leak intent to adversaries, break accessibility, and cost conversions. Vinishu is invisible - to humans and to bots.

CapabilityVinishuLegacy CAPTCHAs
Blocks sophisticated botsYesPartial
Friction for real usersNoneHigh
Mobile coverageYesLimited
Decision time8–10 ms3–12 s
Accessibility compliantYesNo
AI resistantYesNo
Installation effortLowHigh
Explainable per-request decisionsYesNo
Pricing

No shelf price. Just an honest quote.

We tailor your price to you - your traffic, your bot load, your risk. The SDK runs today. We plan the reverse proxy with you.

Lightweight - keep your infra
SDK Integration

A small script + a /verify call. Same validation, lower complexity - ideal for big stacks.

  • 1 script tag - 1 verify call
  • No DNS changes
  • Works with big stacks too
Talk about SDK Integration
Protection in front of your server
Reverse Proxy
Coming soon

All your traffic will go through Vinishu. TLS and browser fingerprinting, rate limiting, DDoS absorption - without changing a line of code.

  • One DNS change once the proxy ships · 0 code changes
  • Decisions in 8–10 ms
  • Extended security
Talk about Reverse Proxy
Deploy in under 10 minutes

Ready to trade CAPTCHAs for invisible protection?

Get in touch, no strings attached. We'll give you honest, no-pressure advice - then see the value for yourself in a risk-free two-week pilot, with a traffic analysis at the end.

Or first see which of your forms a bot can submit