Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Kasada announced a $23 million Series C on December 6, 2021, pitching its bot-defense platform as a way for enterprises to stop malicious automation without routinely making customers solve visible CAPTCHA puzzles. The round was real; “abolish the CAPTCHA” was a product ambition, not evidence that verification challenges had become obsolete.
What Kasada raised—and what it planned to do
The New York- and Sydney-based company said the Series C was led by StepStone Group, with participation from Ten Eleven Ventures, Main Sequence Ventures, Reinventure, Our Innovation Fund, and Turnbull & Partners. It brought Kasada’s total funding to $39 million. The company planned to use the money to expand U.S. sales and grow development, customer-support, and marketing teams. Kasada’s funding announcement and contemporary coverage describe a company founded in 2015 by Sam Crowther, with about 70 employees at the time.
Kasada reported 230% revenue growth since its Series B. It also said its customer count had grown 80% in the prior 18 months, that 85% of customers had previously used another anti-bot provider, and that most of its revenue came from the United States. These are company-reported figures, not independent performance measurements. Kasada did not disclose an absolute customer count in the contemporary interview.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The problem: automation that can cost more than a CAPTCHA interruption
Bot defense is not limited to stopping spam submissions. Automated traffic can test stolen username-password pairs in credential-stuffing attacks, take over accounts, create fake accounts, scrape prices or content, test stolen payment cards, hoard tickets or scarce products, and abuse APIs. Some attacks aim to overwhelm application features rather than the whole network. The damage can include fraud, inventory distortion, service disruption, and extra work for security and support teams.
#1 Best Overall
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Kasada said its customers’ e-commerce activity represented more than $20 billion in annual transactions and hundreds of millions of account logins. That is a company-reported measure of customer activity; it should not be read as $20 billion in fraud prevented or as an independently audited result.
Why challenge the CAPTCHA?
A visible CAPTCHA adds a step at exactly the moments when a business often wants a smooth experience: signing up, logging in, checking out, or buying tickets. Challenges can be awkward on phones and difficult for some people with disabilities. They can also interrupt legitimate users when a browser, network, or privacy tool looks unusual to a risk system.
Kasada cited a survey in which 87% of companies said customer experience would improve if CAPTCHAs were eliminated. That figure comes from a survey promoted by the company, not a universal estimate of conversion gains. The survey announcement provides its context.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsRank #2
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
Challenges also are not an unbreakable boundary. Attackers may automate recognition, route work to human solvers, use real browsers and residential proxies, or combine browser automation with stolen accounts. Kasada has argued that some CAPTCHA-solving bypasses can be bought cheaply; that claim should not be generalized to every challenge design or implementation. A CAPTCHA can still serve as one signal or an escalation step, but it cannot by itself guarantee that traffic is human.
How Kasada said its defense worked
In 2021, Kasada described protection for websites, mobile applications, and APIs. Its model combined client-side interrogation with server-side analysis, machine-learning capabilities, and other signals. The company also emphasized proprietary obfuscation, intended to make its defenses harder for attackers to inspect and work around, and real-time detection designed to block malicious automation before it reached customer infrastructure. Actual traffic routing and deployment determine where a product can intervene, so that “before it reaches” description is a vendor claim rather than a universal property of every setup.
Kasada said it sought to identify malicious automation immediately rather than wait for it to build a recognizable history, and to reduce reliance on manually written rules and risk scores. The company called this a “zero-trust” approach. In this context, that meant treating incoming automation as untrusted; it should not be confused with a claim that the product implements every aspect of a formal zero-trust identity or access-control architecture.
Rank #3
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
The target was not just one bot framework. Kasada pointed to changing automation tools such as Puppeteer and Playwright, stealth plugins, anti-detect browsers, and residential proxy networks. The underlying point is that IP blocking or a static browser fingerprint alone may be inadequate against sophisticated abuse. Kasada’s description of its combination of signals and obfuscation was its technical proposition, not independent proof that it outperformed other vendors.
Kasada’s later product positioning is broader than the 2021 announcement: its current site presents Bot Defense alongside account intelligence, AI-agent trust, and fraud-related offerings. Those are later portfolio claims and should not be projected backward onto what the Series C product did in 2021. Kasada’s current product site outlines that positioning.
What “abolish CAPTCHA” really means
Removing a visible puzzle does not necessarily remove verification or friction. An invisible defense may inspect the browser or device, run JavaScript, analyze behavior, apply rate limits, temporarily block a session, or escalate a suspicious login to another check. The user may see no puzzle on an ordinary visit, while suspicious traffic still faces a challenge or denial.
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Invisible decisions can also be harder to understand. A visible CAPTCHA makes an interruption obvious; silent blocking can leave a legitimate user unsure what went wrong. Any deployment should provide useful logs and reason codes, a way to test policies, and a process for investigating or allowing legitimate traffic.
Nor is there a universal answer to whether a CAPTCHA should be removed. A site defending a high-value login or ticket release may need layered bot intelligence. A small site protecting a public form may reasonably prefer a quick, inexpensive managed challenge. A CAPTCHA can remain a fallback even when a provider’s routine path is invisible.
Recommended Free Tools
Traction is not the same as independent validation
At the time of the round, Kasada said it had added Fortune 50 and ASX 50 customers. It named Hyatt, Empire Cat, AGL, True Alliance, and the Sydney Opera House. It also said customer traffic encompassed more than $20 billion in annual e-commerce transactions. Named customers and reported growth indicate commercial traction, but do not establish detection accuracy, false-positive rates, or superiority over alternatives.
Best Value
Funding likewise signals investor backing, not a security benchmark. The available contemporary account reports company claims and product framing; it does not provide a neutral head-to-head test against CDN bot controls, CAPTCHA providers, or other enterprise platforms.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How the options differ for buyers in 2026
These products occupy adjacent but not identical categories. A widget that verifies form submissions is not automatically an account-fraud platform; a CDN bot feature is not necessarily equivalent to a dedicated managed bot-defense service.
| Option | Potential fit | Important distinction |
|---|---|---|
| Kasada Bot Defense | Large organizations protecting web, mobile, API, login, scraping, or fraud-sensitive workflows. | Dedicated enterprise positioning; request a proof of concept and confirm scope, deployment, and pricing for your traffic. |
| Cloudflare Turnstile | Teams seeking a low-friction challenge alternative for sites and forms. | It uses non-interactive browser and environment checks; it is verification, not by itself an equivalent to a broad account-fraud platform. It can be embedded without routing all site traffic through Cloudflare’s CDN. |
| hCaptcha | Organizations seeking CAPTCHA or passive-verification options with self-service tiers. | Widget and verification capabilities should not be conflated with enterprise-wide bot and account-abuse management. |
| DataDome | Organizations evaluating a wider bot and cyberfraud offering across sites, APIs, mobile apps, and related use cases. | Compare the exact included features, event volumes, deployment requirements, and service levels. |
| Cloudflare bot controls | Existing Cloudflare customers who want bot controls alongside WAF and CDN services. | Available controls depend on plan; an integrated ecosystem may not suit buyers seeking vendor-neutral deployment or a separately managed specialist platform. |
Published prices are only directional and can change. As seen August 18, 2026, one Kasada AWS Marketplace listing showed $99,000 for a 12-month contract covering up to 20 million requests per year; other listings direct buyers to request a private offer. Cloudflare listed a free Turnstile tier and an Enterprise tier requiring a sales contact. hCaptcha listed a free Basic plan and Pro at $139 per month month-to-month or $99 per month billed annually, including 100,000 monthly evaluations and then $0.99 per 1,000. DataDome listed Essentials at $3,830 per month, Advanced at $8,670, Premium at $10,160, and Enterprise from $13,270 per month. Check each provider’s live terms, geography, usage definitions, and contract scope before comparing totals. Sources: Kasada AWS Marketplace, Turnstile plans, hCaptcha pricing, and DataDome pricing.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →These figures do not make one option automatically cheaper in practice. A fair comparison includes integration and operations work, the cost of false positives, support, the endpoints and channels covered, and losses or chargebacks avoided. A low-cost challenge widget may solve a narrow form problem; a high-volume enterprise may need broader detection and response.
A practical evaluation checklist
- Match the product to the abuse. Specify whether the problem is credential stuffing, account takeover, scraping, fake accounts, carding, ticket or inventory hoarding, API abuse, or application-layer denial of service. Ask which controls address that exact workflow.
- Map channels and deployment. Confirm support for web, mobile SDKs, and APIs, plus compatibility with your CDN, WAF, and API gateway. Establish whether traffic must pass through the vendor, and how rollback works.
- Ask what “frictionless” means. Find out when the system runs JavaScript, inspects device or browser signals, rate-limits, blocks, or escalates to a visible challenge. A CAPTCHA-free promise may still involve invisible checks and step-up verification.
- Measure false positives in your own traffic. Request results by geography and device, including privacy browsers, VPNs, corporate proxies, mobile carriers, accessibility tools, and legitimate crawlers. Define an allowlist and appeal path before enforcement.
- Test operational transparency. Ask for decision logs, reason codes, tuning requirements, incident response, testing or monitor-only modes, and the time required to adjust to a new attack. Do not assume “machine learning” removes the need for operational oversight.
- Protect legitimate automation. Identify search crawlers, monitoring services, partner APIs, logistics integrations, internal automation, and approved AI agents. The goal is selective access, not indiscriminate bot blocking.
- Review privacy and compliance. Ask what browser and device signals are collected, whether fingerprints are generated, where data is processed, how long it is retained, whether it trains models, and whether the service works when JavaScript or third-party cookies are blocked. Vendor compliance statements are not legal advice; assess them against your obligations.
- Calculate total economics. Compare request or evaluation limits, protected endpoints, domains, channels, infrastructure and support fees, implementation labor, and the business cost of false positives against measurable reductions in abuse.
- Run a controlled proof of concept. Use representative legitimate traffic and attack cases. Agree on latency, block accuracy, user friction, privacy, and operational-effort thresholds before choosing a vendor; define an exit and rollback plan.
The takeaway
Kasada’s 2021 Series C was a credible sign that investors saw demand for enterprise bot defense that imposed less visible friction on legitimate users. But the headline’s promise is best read narrowly: replace routine CAPTCHA puzzles in selected workflows with adaptive, often invisible detection. It does not mean all CAPTCHAs are useless, all verification disappears, or sophisticated bots can be stopped with certainty. Buyers should judge the product by measured security and user outcomes, privacy, transparency, and total cost—not by the phrase “CAPTCHA-free.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

