Back to overview
Scraping

Stop scrapers, before they read.

Catalogs, prices, listings, model outputs, reviews - every line of text on your site is something someone wants to grab and sell in their own product. Vinishu detects the scrapers before they see your content.

How the attack unfolds

This is what modern scraping looks like.

Headless Chromium. Residential proxies that rotate per request. JavaScript runs. TLS-fingerprints matched to real browsers. The old tells are gone - the intent still shows.

PHASE
Reconnaissance
TOOLS
Puppeteer · Playwright · curl-impersonate
COST
< 200 USD per month per scraper
HARD TO DETECT FOR
static rules
How Vinishu solves it

Detect intent. Block the request. Let real users through.

01 · TLS/Header analysis

See the full picture, not just a part.

JA3/JA4-fingerprints, cipher order, header order: automation libraries mostly can't fake this data perfectly, and that's how they get caught.

ja3771,4865-4866…
mismatchdetected
02 · Watch behavior

Timings give everything away.

Real users click all over the place. Scrapers go page by page at a steady rhythm. We measure cadence, depth and shape against your traffic baseline - learned per origin, not from a fixed rulebook.

rate47/min
baseline4/min
03 · Proxy-pool detection

One IP crawling your entire site?

We track IP reputation across the entire Vinishu network. An IP that scraped someone else yesterday is on its way to you today.

IP reputation0.07
cross-tenantflagged
How you integrate it

One verify call on your listing route.

Your route asks once before it hands out the catalogue. If the score sits below your threshold, the scraper reads nothing - and your database does no work.

Same validation in every integration
Decision in 8–10 ms
Every decision looked up in the dashboard
products-handler.tstypescript
01import { vinishu } from "@vinishu/sdk";
02
03export async function GET(req: Request) {
04 // 1 verify call before the catalog query runs
05 const v = await vinishu.verify(req, {
06 intent: "catalog",
07 route: "/products",
08 });
09 // { valid, score, fingerprint_id, session_id }
10
11 // the threshold is yours, not ours
12 if (!v.valid) return deny(v.fingerprint_id);
13 if (v.score < 0.4) return cachedCopy(req);
14
15 return renderCatalog(req); // 8–10 ms added
16}
FAQ

Questions security teams actually ask.

Missing a question? Ask a developer.

Are search engines blocked too?

No. Verified bots - Googlebot, Bingbot, GPTBot and the like - we check them, and if they're real, they're let through, of course. They're allowed by default and can be put on a whitelist or blacklist per route.

Does it work on JSON APIs?

Yes. Modern scraping targets your data endpoints, not HTML. Vinishu scores every HTTP request - JSON, form, GraphQL - with the same rigor.

What about scrapers that use real browsers?

Headless Chromium, Playwright and CDP can still be detected by our systems - no automated browser stands a chance.

How do I deploy without affecting users?

Vinishu has a Shadow mode. In it, Vinishu only scores and doesn't block. You can watch every decision live in your dashboard.

Does it make my site slower?

No, Vinishu adds almost no overhead - the Vinishu decision engine decides in 8–10 ms.

Pilot first, then production

The fastest way to see who's scraping you:
one week of Vinishu in Shadow mode.

SHADOW MODE · 2 WEEKS · FREE · NO COMMITMENT
Deploy in under 10 minutes

Ready to trade CAPTCHAs for invisible protection?

Get in touch, no strings attached. We'll give you honest, no-pressure advice - then see the value for yourself in a risk-free two-week pilot, with a traffic analysis at the end.

Or first see which of your forms a bot can submit