Castle
castle.ioBuild Difficulty: 4/5
A few focused days to build a solid replacement
Stop bots and account abuse in minutes
How to Replace CastleOverview
Features
41 features across 12 categories
AI & ML(1)
Self-learning AI that spots account takeover attempts and abusive behavior
Analytics(4)
Spot network of bad user activity via shared devices, emails, IPs, payment methods, or addresses
Uncover bad user activity by querying and visualizing large amounts of data and turn into rules with a few clicks
Get a complete history of each user and company down to individual page views and custom actions
Monitor, analyze, and alert on up to 18 months of historical data enriched with user and device intelligence
Customization(2)
Define and track custom metrics for your fraud detection
Create custom signals based on your application's specific needs
Deployment(1)
Deploy Castle at the edge to analyze every request and stop credential stuffing and scripted abuse before they reach your backend
Detection(21)
Identify both bot and human account takeover attacks using scores and heuristics
Use out-of-the-box signals or create custom aggregations and rate limiters
Detect generated emails, abuse IPs, credential stuffing, web crawlers, and automated patterns
Detect bots, scripts, and coordinated attacks while identifying automated behavior and tampering
99.5% accurate fingerprinting that uncovers headless browsers, tampering, and carrier data
Identify disposable and temporary email addresses
Assess email reputation and risk, detect disposable domains and enumeration patterns
Detect when users are accessing from emulated environments
Block fake accounts in minutes using Abuse Score and Disposable Email signals
Identify unusual high activity levels that may indicate abuse
Detect impossible travel patterns indicating account compromise
Determine user location based on IP address
Identify mobile devices that have been jailbroken or rooted
Identify multiple accounts per device and multi-accounting fraud
Detect logins and registrations from new countries for users
Identify when users access accounts from new devices
Detect when users access accounts through proxy IPs or VPNs
Identify Android devices that have been rooted
Detect when device fingerprints or request data has been tampered with
Detect when users are accessing accounts through VPN services
Advanced fingerprinting for both web and mobile platforms
Integration(3)
Connect Castle to Cloudflare with no code for edge deployment
Add SDK to track sessions, devices, and behavior enriched with business context for in-app fraud detection
Receive real-time webhooks for fraud events and policy decisions
Management(1)
Manage dynamic trust, block, and review lists of users, devices, or any custom attribute
Notifications(1)
Get real-time fraud alerts in Slack
Policy & Rules(2)
Create and manage security policies for different user actions and risk levels
Real-time allow, challenge, or deny actions with seamless rule management without code changes
Scoring(3)
Risk score indicating likelihood of abusive activity (0-100)
Account Takeover risk score indicating likelihood of account compromise (0-100)
Risk score indicating likelihood of bot activity (0-100)
Testing & Validation(1)
Test complex risk logic on historical data first, ensuring zero disruption to legitimate users
Pricing
Free
- ✓All core features
- ✓3 days data retention
- ✓3 seats, 1 environment
- ✓Up to 1,000 API calls per month
- ✓Bot Score
- ✓Abuse Score
- ✓ATO Score
- ✓API data
- ✓Web & mobile fingerprinting
- ✓IP geolocation
- ✓Raw device attributes
- ✓VPN Detection
- ✓Jailbroken device detection
- ✓Emulator detection
- ✓Rooted detection
- ✓Tamper detection
- ✓Disposable email
- ✓Policies
- ✓Lists
Pro
Popular- ✓Everything in Free, plus:
- ✓Higher rate limits (5 API requests / second)
- ✓7 days data retention
- ✓5 seats, 2 environments
- ✓Chat & email support
- ✓Unlimited API calls (pay per use)
- ✓Real-time API Querying
- ✓API data exploration
- ✓Bot Score
- ✓Abuse Score
- ✓ATO Score
- ✓Web & mobile fingerprinting
- ✓IP geolocation
- ✓Raw device attributes
- ✓VPN Detection
- ✓Jailbroken device detection
- ✓Emulator detection
- ✓Rooted detection
- ✓Tamper detection
- ✓Disposable email
- ✓Automation
- ✓Custom Signals
- ✓Custom Metrics
- ✓Policies
- ✓Lists
- ✓Webhooks
- ✓Slack alerts
Enterprise
- ✓Everything in Pro, plus:
- ✓No rate limits
- ✓Up to 18 months data retention
- ✓Unlimited seats & environments
- ✓Dedicated Slack channel & SLA
- ✓Service Level Agreements (SLAs)
- ✓Real-time API Querying
- ✓API data exploration
- ✓Dedicated support for setup and integration
- ✓MTU-based pricing option
- ✓Bot Score
- ✓Abuse Score
- ✓ATO Score
- ✓Web & mobile fingerprinting
- ✓IP geolocation
- ✓Raw device attributes
- ✓VPN Detection
- ✓Jailbroken device detection
- ✓Emulator detection
- ✓Rooted detection
- ✓Tamper detection
- ✓Disposable email
- ✓Automation
- ✓Custom Signals
- ✓Custom Metrics
- ✓Policies
- ✓Lists
- ✓Webhooks
- ✓Slack alerts
Cost Calculator
Keep Paying Castle
Build It Yourself
Total Cost Comparison
DIY hosting estimate based on Vercel + Supabase free/pro tiers (~$20/mo). Build time estimated from 41 features at easy complexity.
Build vs Buy
Should you build a Castle alternative or buy the subscription? Estimate based on 41 features.
Buy Castle
Build Your Own
Better ValueBuilding could save ~$16,560 over 3 years.
Estimates based on 41 features and a BuildScore of 4/5. Actual costs vary.
Integrations
1 known integrations