An anti-detect browser can change what your page sees. Heretic checks those claims against browser tests and the connection itself. You get the verdict and the reasons behind it.
A score leaves you to choose a cutoff. Move this example slider to see how that choice changes the action, without explaining what the browser did.
61 to 85: manual review.
Required measurement completed and a conclusive contradiction was found. The response names the finding.
Required measurement did not complete. The response identifies what was missing.
Required measurement completed with no conclusive contradiction. Coverage and any conditional findings are included.
This example browser reports a timezone in Japan. The sensor checks how quickly its connection reaches Warsaw.
The minimum round trip for the claimed timezone is 45.1 ms, even at the speed of light in a vacuum. The measured connection cannot originate there.
The browser reports ten logical processors. Heretic runs a parallel workload to check how throughput changes as workers are added.
Adding workers produces no further speedup in this example. This is a conditional finding: scheduling and other workloads can affect throughput, so it does not establish a physical core count.
The browser identifies as macOS. Its connection provides a separate observation of the network stack.
The TCP option order and window scale match a Linux stack. That conflicts with the macOS claim. A proxy can also account for the different stack.
Heretic offers a session-specific QUIC connection and records whether the browser attempts it.
The session returned its other measurements but made no required QUIC attempt. This finding requires a working packet sensor.
A new browser profile can change the reported platform, timezone, and graphics card. The example below changes those declarations while the connection observations stay fixed.
Each family tests a different part of the session. One conclusive contradiction is enough to determine the verdict.
Round-trip time against the distance implied by the claimed timezone.
TCP connection parameters against the claimed operating system.
Handshake fields against the browser claim and protocol rules.
Headers, HTTP/2 settings, and browser properties checked for inconsistencies.
CPU and graphics workloads checked against the reported results.
Required connection attempts, including QUIC.
A fixed constraint was violated, or required measurement was refused. Determines the verdict.
A confirmed contradiction. One finding is enough to set the verdict.
The conclusion depends on an unverified premise. Reported without changing the verdict.
A contextual observation. Does not change the verdict.
An opened session with missing required measurements returns refused. If the collector never loads, no result exists. Require a fresh completed check on your backend before accepting the action.
Your policy can require a phone challenge before a signup or another protected action. The visitor holds the phone level, keeps it steady during a workload, turns it upright and sideways, then confirms with a passkey.
Heretic checks the recorded movement and elapsed time, then verifies a signature over the measurements. Your backend receives the outcome and device records. Desktop visitors continue on a phone through a rolling QR code.
The required checks and passkey verification completed.
A conclusive finding or invalid signature contradicted the challenge.
The response identifies the step that did not finish.
The signature binds browser-supplied readings to the challenge. It does not authenticate the motion sensor or establish a unique person.
Each finding has a documented ID and tier. Save the result with your decision to retain the measurements and ruleset version used at the time.
A later read returns the original assessment, even after the ruleset changes.
Available browser inputs produce instance, machine, and rendering identifiers. Compare them with your account records. Matching inputs can occur on distinct devices.
Enable zero retention for one authorized read within ten seconds. The result is deleted on read and never enters stored history.
The collector checks a browser session and returns a request ID for your backend. The widget adds verification to a form. Both connect to Heretic separately from your application traffic.
Create a site and verify its domain to start. The integration guides cover collector results, form tokens, and backend policy checks.
<script src="https://probe.heretic.tech/client.js"></script> <script> heretic({ siteKey: 'hrtc_live_9f2c…' }); </script>
The probe reports concealment indicators alongside the verdict. Your policy decides how to treat them. If you request a phone challenge, detected concealment holds the challenge until the visitor disables the VPN, proxy, or relay and retries.
Your application decides. The default widget requests a phone challenge for contradicted or refused probes. The visitor follows the motion instructions and confirms with a passkey. Your server receives passed, contradicted, or not_completed, with the findings and stopping step.
No. The collector opens a separate connection from the browser to the Heretic sensor. Your application traffic continues to your own server. Verify ownership of your site with a DNS TXT record or a file.
An opened session that does not complete required measurement returns refused. If collection is blocked before a session opens, no result exists. Your server must require a completed check before accepting the protected action.
No. Once finalized, an assessment keeps its original verdict, findings, and versions. Run a new probe to check the browser again.
The observed connection address, browser claims, browser test results, and available site-scoped identifiers. Ordinary results are available for seven days. Zero-retention mode allows one authorized read within ten seconds and keeps no stored history.
The free Sandbox includes 1,000 probes and 1,000 challenges each month. No card required. For help choosing an integration or plan, leave your email.