SYSTEM OPERATIONAL
SPARK L3
NETSPECTRA.ORG© 2026FORMALLY VERIFIED
[ PASSIVE FINGERPRINT ENGINE / ADA + SPARK ]
◆ EDGE-SEC / L3-VERIFIED

NetSpectra: Formally Verified Bot Detection at the Edge

▼ INBOUND TRAFFICCRAWLERS142 / SECSCANNERS317 / SECBOT FARMS2.4K / SECAI AGENTS488 / SECHUMANS96 / SECNETSPECTRAJA4 · TCP · H2 · BEHAVIORNTERMINATED3 347 / SECFORWARDED96 / SECcheckoutapi/v1login▼ ONLY VERIFIED HUMANS REACH ORIGIN

NetSpectra is a formally verified edge security platform — the rest of the market makes real customers prove they are not bots through CAPTCHAs that kill conversion, JavaScript checks that burn round-trips, probabilistic blocks that quietly drop paying users. We chose another way. Passive TLS, TCP and HTTP signals. Decided in microseconds. No friction visible to the visitor.

See how it works
// WHY

Why we turned deep engineering into a
product.

LOG 01 / 03
STATUS: EXPLAINED
FR_01

Too much trust in black boxes

Security teams are asked to trust scores they cannot inspect, thresholds they cannot explain, and decisions they cannot defend. That may be acceptable for experimentation. It is weak infrastructure for production.

FR_02

Too little signal before HTTP

Most products wait until JavaScript runs, headers arrive, or behaviour accumulates. By then, the session has already consumed application logic, origin capacity, and business risk. We made the call before HTTP.

FR_03

Too much friction for real users

Challenge-heavy protection shifts the cost of detection onto legitimate traffic. CAPTCHAs, scripts and browser checks slow down real buyers while better bots route around them. The market normalized friction. We did not.

FR_04

Too little proof for security teams

When a platform blocks traffic, the question is no longer whether it scored highly. The question is whether the decision can be traced, explained and audited. Most products optimize for detection. Serious teams also need defensibility.

// HOW WE DO IT

We built our own TLS stack — in Ada/SPARK, the language used in flight control and nuclear safety systems. Every line that touches a connection has been mathematically verified.

That is what prove means here.

// WHAT IT MEANS

You can audit every verdict. You can explain every decision. You can defend every block — in audit, in compliance review, in front of a security architect.

No retraining cycles. No model drift. No “the AI decided” excuses.

// DEPLOYMENT

Five minutes from zero to edge.

LOG 02 / 03
ZERO CODE CHANGES
01
~ 30s

Point DNS

Create a free account and add one A-record pointing to an edge node. No SDK, no library, no server-side change.

DNSA-RECORD
02
~ 2 min

Tunnel up

WireGuard tunnel comes online between the edge and your origin. TLS is terminated at the edge; your backend stays on a private IP.

WIREGUARDCURVE25519
03
LIVE

Passive scoring

Every TCP/TLS handshake is fingerprinted and scored. Four signal layers fused into one deterministic verdict — under 500 microseconds.

JA44-LAYER<500μs
04
ENFORCED

Origin hidden

Verified humans reach your app. Automated traffic gets blocked or filtered at the edge. Your real IP never appears in DNS, headers or logs.

VERIFIEDHIDDEN IP
DEPLOYMENT READOUT
[EDGE-OPS-01]
CLIENT JS
0
LATENCY P99
<500μs
TLS STACK
OWN
// SCOPE

We don’t just filter your traffic. We protect your backend too.

Edge filtering matters only when the edge is the only way in. Your origin sits behind a private tunnel, your filter never sleeps, and the verdict gate covers every request — paid traffic, login form, checkout, API endpoint, everything.

01 · Network protection

Bot clicks, scrapers, credential stuffing — filtered at the TLS handshake before any HTTP processing runs. The decision is made at the protocol layer, in microseconds.

02 · Backend protection

Your origin never appears in public DNS. Direct attacks on your CMS or framework hit a closed door. Edge is the only valid path to your application — even if your IP leaks elsewhere.

03 · Always on

The same verdict gate guards every endpoint, every minute. No downtime windows for rule updates, no DDoS-driven outages. The filter does not sleep, and neither does your store.

// PLANS

Pick a tier.

5 PLANS
START FREE
SOL_01
Lite
Freeforever

See your traffic.

  • 1 site
  • Read-only fingerprints
  • No filtering
▸ Start
SOL_02
Identify?formerly: deanon
$199/ month

Block automated, pass humans.

  • 3 sites
  • Verdict at handshake
  • Read-only API
▸ Deploy
SOL_03◆ RECOMMENDED
Adaptive?formerly: cloaker
$499/ month

Differential delivery.

  • 10 sites
  • Real users see your real page
  • <500 µs decision
▸ Deploy
SOL_03+
Adaptive PRO?formerly: cloaker pro
$999/ month

Full API + webhooks.

  • 10 sites
  • Conversion tracking
  • 99.9% SLA
▸ Deploy
SOL_04
Enterprise
Custom

Self-host. Audit-grade.

  • Unlimited sites
  • All 85 signals
  • mTLS via your CA
▸ Contact
Compare all features
// FEATURE
Lite
Free
Identify
$199
Adaptive
$499
Adaptive PRO
$999
Enterprise
Custom
Sites included131010
Extra sites+$49/site+$29/site+$29/site
Passive fingerprinting
Automated traffic filtering
Scoring threshold control
Differential delivery
Response shaping
X-AE-* headers
Read-only API
Full API + webhooks
Conversion tracking
Dedicated edge nodes
Custom scoring rules
SupportemailprioritypriorityTAM
SLA99.9%99.9%99.99%

// NO CONTRACTS · NO SETUP FEES · CANCEL ANYTIME · START WITH LITE AND UPGRADE WHEN YOU NEED

NetSpectra: Formally Verified Bot Detection at the Edge