Every control has a price. Who pays when it is wrong?

Chitmark is not bot detection. CAPTCHAs and fingerprints ask whether traffic looks automated; Chitmark asks whether a costly action should proceed, and learns from what happens after. Rate limiting vs fraud prevention is the wrong binary if you only cap volume. Ask three things instead: who pays when a decision is wrong, what it costs your real users, and whether the next decision learns from this one. Here is the scorecard for free-tier signup abuse.

ApproachStops farms?The agent storyWho really paysLearns from outcomes?
Manual rate limitsSlows a single box; a distributed farm spreads under every thresholdAgents pace themselves and rotate identitiesYour heaviest legitimate users hit limits firstNo record of what a blocked action would have cost
CAPTCHAsSolver services clear them for fractions of a centHeadless browsers solve vision and audio challengesEvery real user pays seconds and rage-tapsNothing: pass or fail, no outcome joins back
Device fingerprintingAn arms race; farms rotate stacks faster than vendors patchFresh browser profiles are cheap and plentifulPrivacy-heavy: the strictest regulators watch this closestSignals only: no tie to what the signup was worth
Email verificationDisposable inboxes are free at any quantityFully automated, including the confirmation clickA second inbox hop for your best usersConfirmed is not the same as valuable
Stripe RadarScores signups for multi-account abuse with no card required, predicts nonpayment mid-cycle; real power, but Stripe documents these signals as advisory and fail-openEvaluations anchor on payment methods and Customer objects; the pre-card moment, a fresh signup or a first quota grant, stays invisibleA score can block quietly; the trial control still leans on card-on-file friction for everyone who starts a trialYou can report outcomes back; the labels and the network they sharpen stay with Stripe
Agent gateway guardrailsCaps what an approved agent can spend inside one gateway; the farm hits your signup form firstGoverns agents you already let in; silent on who is at the doorNone: configuration, not frictionBudgets and allowlists; no outcome joins back to the signup
ChitmarkEvery uncertain signup pays a challenge: compute or card, before touching creditsLegitimate agents clear proof-of-work invisibly and get a signed receiptNear zero: a human's browser pays ~50 ms once, no puzzlesEvery outcome (converted, credit burn, chargeback) tunes the next decision

See for yourself

The playground runs real production decisions on a customer payload and a farm payload. The status page publishes the latency targets we hold ourselves to.