Back to overview
Account takeover & fraud

Block credential stuffing, without ever blocking a real user.

The known leaks hold over 11 billion username-password pairs. Attackers don't guess anymore - they replay the lists. Vinishu spots velocity and posture before a single attempt reaches a password.

How the attack unfolds

How a stuffing attack plays out.

A leaked cred list, a residential proxy pool, a cheap script. One in a hundred gets through - the whole business rests on that. Vinishu pushes it down to one in a million.

How Vinishu solves it

Detect intent. Block the request. Let real users through.

01 · Prevention

Handle it before it happens.

Vinishu decides the moment the request arrives, not later, after the fact. That stops attacks before they start.

attempts/email/15m47
baseline< 3
02 · Two fields

No guesswork.

Vinishu answers with valid and score, not a cloud of hints you have to weigh up yourself. You set the threshold once, in your route.

validfalse
score0.03
03 · Invisible challenge

Effort only for attackers.

Borderline cases get a computational challenge or a delayed response - invisible to humans, expensive for scripts. No CAPTCHA, no MFA spam, no support tickets.

user impactno prompt
bot impactblock
How you integrate it

A single verify call. Decision in 8–10 ms.

You call the SDK from your auth API. We made the decision long before that. The reverse proxy will do the same further up once it is live - same decision, different integration.

Same validation in every integration
Decision in 8–10 ms
Every decision looked up in the dashboard
auth-handler.tstypescript
01import { vinishu } from "@vinishu/sdk";
02
03export async function POST(req: Request) {
04 // 1 verify call, answered before the password check
05 const v = await vinishu.verify(req, {
06 intent: "login",
07 account: req.body.email,
08 });
09 // { valid, score, fingerprint_id, session_id }
10
11 // you set the bar: block hard, step up when unsure
12 if (!v.valid) return deny(v.fingerprint_id);
13 if (v.score < 0.6) return stepUp(req, v.session_id);
14
15 return loginAsUsual(req); // 8–10 ms added
16}
FAQ

Questions security teams actually ask.

Missing a question? Ask a developer.

Does this replace 2FA?

No, 2FA can't be replaced. A stolen password typed in by hand isn't something we can stop either. The user's identity should still be confirmed properly.

Can I rely on Vinishu?

Yes - you can. Vinishu is built to stay up and made exactly for your use case. You look up every decision by fingerprint_id and session_id in the dashboard.

Do you store passwords?

Never. Vinishu sees request metadata - TLS posture, cadence, headers, optionally the email for per-account velocity. The password never leaves your stack.

Are there false positives on legitimate spikes?

We learn the baseline per tenant. A 10× spike is read as a shifted baseline, not an attack. For planned events you can raise the score threshold per route.

Are results available to me?

Yes, every decision is available via dashboard and API.

Pilot first, then production

Try it first,
enforce only after.

SHADOW MODE · 2 WEEKS · FREE · NO COMMITMENT
Deploy in under 10 minutes

Ready to trade CAPTCHAs for invisible protection?

Get in touch, no strings attached. We'll give you honest, no-pressure advice - then see the value for yourself in a risk-free two-week pilot, with a traffic analysis at the end.

Or first see which of your forms a bot can submit