Proof of personhood, post-CAPTCHA.

The bots passedthe test. Your usersshouldn't have to.
VERIFIED HUMAN

AI solves CAPTCHAs faster than your customers do. Zonta fuses behavioral, device and cryptographic signals into one personhood score, so your product can tell a person from a script in about 140 milliseconds. No puzzles. No biometrics. No PII stored. Your users see nothing. Your bots see a 403.

STATUS: PRIVATE BETA. P50 LATENCY: 142MS. SIGNALS FUSED: 40+. PII STORED: 0 BYTES. REGIONS: US · EU. CAPTCHAS SERVED: 0

The test got harder. Only the humans noticed.

For twenty years the web checked for humans by asking questions machines couldn't answer. Read the squiggle. Pick the traffic lights. Today a general-purpose agent answers those faster than your customers do, for a fraction of a cent, and then fills in the form.

So the bot tax is paid by humans. Real users bounce, screen-reader users get locked out, and the traffic that actually hurts you looks fine: fresh account, real device, plausible timing. An agent with a card on file is a paying customer right up until it's five thousand of them.

Personhood needs to work like TLS: a cheap, verifiable property of the request, checked in the background, that every product can rely on. That is what Zonta builds. One score, one verdict, reason codes attached, in about 140 milliseconds.

TRAFFIC AUDIT · ONE TYPICAL MONTH
001 AI agent solves your CAPTCHA 0.9 SEC. 002 Customers who quit at the puzzle 12% ABANDON. 003 Proxy sign-ups, none are people 18%. 004 Credential stuffing, 3am, again 40K REQ/HR. 005 Bots clear the drop in 90 SEC. 006 Five-star reviews by no one 1 IN 6. 007 Agent traffic counted as growth ?? %. 008 Real customers blocked anyway 1 IN 40. 009 Screen-reader users locked out MOST OF THEM. 010 Tickets titled 'I'm not a robot' ~200/WK. 011 Hours spent tuning bot rules ∞ HRS. ESTIMATED COST: 1 IN 8 REAL USERS LOST. THE BOTS STAYED. (ILLUSTRATIVE)

Personhood as infrastructure.

One score, forty-plus signals, zero puzzles. Every feature below exists to answer one question well: is there a person on the other end of this request?

  • 001

    Invisible by default

    Most sessions verify in the background from behavioral and device signals gathered while the user is already on the page. No traffic lights, no crosswalks, no 'select all the buses'. Something appears only when the score is genuinely uncertain, and then it's a two-second accessible step, not a quiz.

  • 002

    Signal fusion

    Pointer dynamics, typing cadence, device attestation, network reputation and cryptographic proofs, fused into one calibrated 0-1000 score. No single signal is trusted alone, so no single signal can be spoofed alone. Spoof one and the others disagree, loudly.

  • 003

    Agent-aware

    We don't just catch scripts. We fingerprint the automation protocols and model-driven agent frameworks that drive real browsers, and we tell you which one showed up. Verdicts come back HUMAN, AGENT or UNCERTAIN, so you allow, deny or route each one on purpose.

  • 004

    Privacy by construction

    Signals are hashed on the client and scored at the edge. Raw events are discarded within seconds. No PII, no biometric templates, no cross-site profile. Built to pass a GDPR and CCPA review, not to survive one. Your privacy counsel gets a short document instead of a long one.

  • 005

    Portable proofs

    A verified session mints a short-lived, device-bound proof (passkeys, App Attest, Play Integrity). Returning humans re-verify with a signature instead of a challenge, across every surface you own. Verified once, trusted after, revocable any time.

  • 006

    Tunable, not binary

    Set thresholds per action. Loose on a comment, tight on a checkout, strict at a drop. Every verdict ships with reason codes, so at 2am on call you know why something was blocked instead of trusting a black box. Change policy in the dashboard, not in a deploy.

  • 007

    False-positive budget

    You set the share of real users you're willing to challenge, say 1 in 200, and Zonta tunes thresholds to hold it. The dashboard shows the trade every day, so friction is a decision, not an accident you find in churn.

  • 008

    Accessible

    When a step-up is needed it works with screen readers, keyboards and switch devices, and never depends on vision or hearing. Tested to WCAG 2.2 AA. Being human should not require good eyesight.

  • 009

    Edge latency

    Verdicts return in about 140 ms at p50 from 30+ edge locations, in parallel with your own request, with a fail-open or fail-closed policy per action if we're ever unreachable. Fast enough to sit in your auth path, so it does.

The trade you stop making

Retire the puzzle.

Twenty years of asking humans to prove it, and the only ones still doing the work are your customers. Here is what changes when personhood becomes a property of the request instead of a test.

The CAPTCHA era

  • Humans do work to prove they're human. Read the squiggle, click every bus.

  • Agents solve the test in under a second, then fill in the form.

  • Real users bounce at the wall. 1 in 40 blocked, screen-reader users locked out.

  • One binary verdict. No reasons, no tuning, no appeal.

  • Every surface runs its own gauntlet. Verify here, verify again over there.

With Zonta

  • Sessions verify themselves in the background. Most people never see a thing.

  • Agents get labeled AGENT, framework named, and you choose the lane.

  • You set a false-positive budget and thresholds hold it, reported daily.

  • A 0-1000 score with confidence and reason codes, tunable per action.

  • Verified once, trusted after. Portable device-bound proofs across your surfaces.

Before you integrate

  • No. A CAPTCHA asks the user to do work a machine supposedly can't. That premise is gone: current agents solve visual and audio CAPTCHAs at above-human accuracy for fractions of a cent.

    Zonta doesn't ask for work. It observes signals a real session already produces, and only asks for a short accessible step when the score is genuinely uncertain. Not a grid of buses. Most users never see anything.

  • Agents driving a browser leave fingerprints: automation protocol markers, unnatural pointer and timing distributions, missing platform attestation, and traffic shapes consistent with known agent frameworks. No single one is decisive. Fused, they are.

    We also report which framework we think we saw, and we support declared agents: one that identifies itself gets an AGENT verdict without the theatre, and you decide what to do with it.

  • An integer from 0 to 1000 with a confidence value and a list of reason codes. Above your allow threshold the verdict is HUMAN and the request proceeds. Below your challenge threshold it is AGENT. In between it is UNCERTAIN, and the user gets a step-up instead of a wall. Thresholds are per action, so checkout can be stricter than a comment.

  • The share of genuine users you're willing to challenge, expressed as a number, for example 1 in 200. Zonta tunes thresholds to hold it and reports against it every day. Friction becomes something you decide, not something you discover in a churn report.

  • Behavioral and device signals are hashed on the client and scored at the edge. Raw events are dropped within seconds. By default we keep the score, reason codes and a salted session hash for 30 days. No names, emails, government IDs, faces or fingerprints.

    We sign a DPA, and you pick the processing region (EU or US) per site key. Data doesn't leave it.

  • No. We do not store or derive biometric templates. Behavioral signals like pointer dynamics are aggregated into a score and discarded; nothing we retain can identify a person across sites or sessions. We can't tell you who someone is. We can tell you that they're someone.

    That is a design constraint, not a policy. There is no per-person profile to leak.

  • Yes. The invisible path needs nothing from the user. The step-up is keyboard-navigable, screen-reader labeled, and does not depend on vision, hearing, or fine motor control. We test to WCAG 2.2 AA and with assistive-technology users.

  • Verdicts return in about 140 ms at p50 and under 400 ms at p99 from 30+ edge locations (illustrative beta numbers). Signal collection happens passively while the user is already on the page, so the check adds one round trip at submit.

  • Your call. Each action has a fail-open or fail-closed setting, and the SDK falls back to a cached policy that returns 'unknown' instead of throwing. Uptime is published on the status page and the Scale plan carries an SLA.

  • Yes. The Swift SDK collects motion, touch and App Attest signals; Kotlin with Play Integrity is in beta. Same score, same server API, same thresholds, so a person verified on iOS and later on web is still one person to you.

  • No. Zonta labels; you decide. Verdicts are inputs, not policies. Many teams route agent traffic to a separate lane with its own rate limits and pricing. Knowing which requests are agents is the point. Blocking them is one option among several.

  • CDN bot management scores requests. Zonta scores sessions, with client-side signals the CDN can't see and cryptographic proofs it can't issue.

    Most customers run both: the CDN handles volumetric junk, Zonta answers 'is this a person' at the moments that matter.

  • It's an arms race, and we'd rather say so than pretend otherwise. Our advantage is that behavior, device and crypto have to be faked simultaneously and consistently, at scale, and that gets expensive fast. Models retrain continuously on the fleet; you get updates without touching your integration.

    When something new shows up we tell you, with the reason codes it tripped.

  • An afternoon for a typical web app: a provider component on the client, one call on the server, thresholds in the dashboard. The Next.js example in the docs is the whole thing, not a sketch.

  • Growth is $249 a month during the private beta ($349 at general availability) for up to 100k verifications, billed monthly, cancel any time. Scale is custom for higher volume, data residency and SLAs. Both include every SDK and every signal. There is no per-seat charge.

  • Twenty minutes. We put the SDK in front of a real browser, a headless one and an LLM-driven agent, and you watch the verdicts come back. Then we look at your surfaces and talk thresholds, including the numbers that aren't flattering yet. No slides, mostly.

Humans still matter.

OUTPUT / ZONTA LABS