See what is actually arriving
We look at real traffic and real enquiries across your site, forms and sign-ups, and separate genuine demand from automation, farms and known sources. Most businesses have never seen this split.
Most security is built to survive an attack. This is built so the wrong party never reaches you in the first place — screened at the door, before an enquiry lands in an inbox, before a form is submitted, before anyone in your business has spent a minute on it.
THE SITUATION
Automated traffic scrapes your content and your contact details. Fake enquiries fill your pipeline and waste real people's afternoons. Farmed accounts sign up in bulk to abuse whatever is free. Somewhere in that noise are the parties you genuinely should never have engaged with — and by the time you find out, you have already replied, quoted, onboarded or handed over information.
The usual answer is to add friction: harder sign-ups, more verification, more checks on everyone. That protects you by slowing your real customers down. We would rather the obstruction fell only on the people who deserve it, and that everyone else never noticed anything happened at all.
SYMPTOMS WE HEAR MOST
Enquiries that go nowhere, from people who were never buying Sign-ups in bulk from what is obviously one operator Content and contact details scraped and reused elsewhere Time lost to parties you would have avoided if you had knownHOW THE WORK RUNS
This is not a product you install and configure yourself. We assess what actually reaches you, tune it to your traffic, and stay responsible for it.
We look at real traffic and real enquiries across your site, forms and sign-ups, and separate genuine demand from automation, farms and known sources. Most businesses have never seen this split.
How aggressive should this be, and what happens in the ambiguous middle? A business taking cold enquiries needs a different setting from a closed member platform. You decide where uncertainty goes.
Integrated into your site, forms, sign-up and login paths. Genuine customers should notice no change whatsoever — if they do, it is set wrong and we adjust it.
Threat behaviour changes constantly. We monitor, tune the thresholds, and your protection benefits from what the network sees elsewhere.
WATCH THE DOOR
Every arrival is assessed before it reaches a person. Pick one and watch what happens in the fraction of a second before your team would have been interrupted.
Nothing has arrived yet. Choose an arrival below.
Enquiry submitted from a corporate network Signals Domain registered 2014 · no prior incidents on record Intelligence Human interaction pattern · consistent device fingerprint Viper Pit Passed through untouched, in 340 milliseconds OutcomeNothing has arrived yet. Choose an arrival below.
Rapid sequential requests across every service page Signals Source not previously recorded Intelligence Automated pattern · no human interaction present Viper Pit Contained at the first layer. Your contact details were never served. OutcomeNothing has arrived yet. Choose an arrival below.
Fourteen sign-ups in nine minutes, all slightly different Signals No individual identifier previously flagged Intelligence Emulator characteristics · SIM farm pattern · shared infrastructure Bombardier Beetle Cluster identified as one operator and contained together OutcomeNothing has arrived yet. Choose an arrival below.
Contact attempt from a previously recorded source Signals Matched on record · associated with prior abuse across the network Intelligence No further assessment required The Den Never connected. There was no engagement to manage. OutcomeNothing has arrived yet. Choose an arrival below.
Enquiry arrives outside normal hours from an unfamiliar region Signals Nothing on record either way Intelligence Some automation indicators · some genuine human behaviour Viper Pit Not blocked. Flagged, delivered, and noted for a person to judge. OutcomeFour of those five never reached a person. The fifth did, with a note attached. That is the difference between security that protects you and security that slows you down.
THE SERPENT DEFENCE FRAMEWORK
Built and proven in production, running against real abuse every day. Each layer handles a different degree of persistence, and each one escalates only what it cannot settle.
BOMBARDIER BEETLE
Coordinated abuse rarely looks like an attack. It looks like fourteen ordinary sign-ups. Bombardier Beetle strengthens Viper Pit specifically against farm-based operations — mobile emulator environments, SIM farm activity, mixed device clusters, hardware fingerprint anomalies and coordinated infrastructure — by recognising the relationships between arrivals rather than judging each one alone.
WHY WE DO NOT PUBLISH THE DETAIL
We describe what the framework addresses, not how it decides. Detection logic, thresholds and responses stay unpublished on purpose — a security system that explains exactly how it works has told the wrong people how to pass it. Expect the same discretion about your own configuration.
KNOWN ACTORS
Alongside the framework we maintain records of sources associated with abuse — the ones that have already tried it, somewhere on the network. When one of them reaches you, the assessment is already made.
WHY THIS MATTERS COMMERCIALLY
Some parties do not attack your systems at all. They occupy your time, dispute in bad faith, misrepresent your business, or approach your people in ways that turn a working week into a problem to be managed. None of that shows up in a firewall log. All of it costs you. Knowing before you engage means you decline the meeting rather than escalating it six weeks later.
We are not interested in blocking for its own sake. Blockage is not the goal — smooth operation is. This exists so the obstruction falls on the people who earned it and nobody else notices a thing.
ONE WEEK, ONE PROTECTED PLATFORM
Seven days on a platform running this framework. Nothing dramatic happened, which is the point — you are looking at the week you would have called uneventful.
SEARCH ENGINES EXCLUDED
Bing, Google, Facebook, Apple and the SEO tools are stripped out of every figure below. They are welcome, and most security dashboards quietly count them as threats to make the numbers look impressive. What is left is the part that actually matters.
WHAT WAS ACTUALLY CAUGHT
Volumes are small. Two of these were not scrapers.
WHERE THEY CAME FROM
Germany, Ukraine, Pakistan, Japan, India, the Netherlands, Turkey, Russia and the Czech Republic — almost all of it routed through rented infrastructure, proxy services and hosting providers rather than anywhere a customer would be.
One provider appearing for the first time this week has gone on a watchlist rather than a block. New is not the same as hostile.
WHY THIS IS THE ARGUMENT
Nine thousand actions in a week, and the two that genuinely mattered were the quietest things in the log — five requests, no volume, no alarm. A business without this in front of it would have recorded a completely normal week. That is how most breaches begin: not with an incident, but with a Tuesday nobody remembers.
You get this as a report, in plain language, with the operational detail kept out of it.
WHAT YOU ACTUALLY GET
HONEST SCOPE
GOOD FIT WHEN
You take enquiries or sign-ups from people you have never met Your content, pricing or contact details are being scraped and reused Bulk or farmed accounts are abusing something you offer You have been drawn into engagements you would have declined if you had knownWAIT, OR DO SOMETHING ELSE FIRST
You want a penetration test or a compliance audit — that is different work The risk is internal rather than external; start with access control You want every visitor challenged. We do not build friction for genuine customersCOMMON QUESTIONS
A firewall decides what traffic may reach your server. This decides whether an engagement should begin at all — including approaches that are technically legitimate and commercially damaging. The two are complementary, and we would not suggest replacing infrastructure security with this.
It is designed not to, and that is the whole design philosophy. Genuine arrivals pass through untouched. Where a case is genuinely ambiguous it is flagged and delivered rather than blocked, so a person makes the call. Blocking a real customer costs far more than reading one flagged message.
Records are based on observed behaviour — activity associated with abuse, fraudulent approach or coordinated exploitation — not on opinion or dispute. Anyone recorded in error can be reviewed and removed, and we would rather be told than not.
Because a security system that publishes its logic has explained to the wrong people exactly how to pass it. We will tell you what it addresses and what it caught. We will not publish the thresholds, and we will be equally discreet about your configuration.
No. Smaller businesses are often hit harder, because a week lost to a bad-faith engagement or a fake enquiry pipeline is proportionally far more expensive when there are eight of you.
Usually not structurally. It integrates at the points where arrivals happen — pages, forms, sign-up and login. Most deployments require no visible change to your site at all.
Most businesses have never seen their traffic split into genuine demand, automation, farms and known sources. That assessment is where this starts, and it is usually the most surprising thing we show a client.