ShieldLabs

Frequently asked questions

Answers about how ShieldLabs works: identification, anonymity detection, explainable risk scoring, patterns, pricing, and the five-minute install. Still have a question? Contact us.

Browse all questions

What is ShieldLabs?
ShieldLabs is a visitor identification and anonymous-visitor detection platform, and a visitor identification API for fraud prevention. It helps you identify anonymous visitors, detects anonymity at any level, and returns an explainable risk score with the signals behind it, along with four High-Risk Events detected out of the box: Multi-accounting, Account sharing, Impossible travel, and Account takeover.
How does ShieldLabs work?
You add one JavaScript snippet to your site. On every visit, ShieldLabs collects 300+ signals across device and network, identifies the visitor, and delivers an explainable risk score from 0 to 100 through an API and webhooks. Detection is ready out of the box, and you choose the action for each case.
What is ShieldLabs used for?
ShieldLabs is used to identify anonymous visitors, assess traffic quality, and detect abuse activity such as multi-accounting, fake account creation, account takeover, free trial abuse, bonus abuse, ban evasion, referral fraud, account sharing, coupon abuse, subscription abuse, giveaway fraud, voting manipulation, and survey fraud.
Who is ShieldLabs for?
ShieldLabs is built for platforms that need enterprise-level functionality without enterprise pricing, from a first launch to high-traffic scale: SaaS, fintech, iGaming, e-commerce, Web3, media and streaming, travel, and technology platforms. Product, fraud, and growth teams use it to detect multi-accounting, account sharing, account takeover, and impossible travel, and any business dealing with anonymous traffic and abuse can put it to work.
Can I use ShieldLabs as a visitor identification API for fraud prevention?
Yes. ShieldLabs is a visitor identification API for fraud prevention. You add one JavaScript snippet, and every visit returns a persistent visitor ID, the risk signals behind it such as VPN, proxy, Tor, and anti-detect browser, and an explainable risk score from 0 to 100 over an API and webhooks. ShieldLabs flags risky users and helps block fraudulent and abusive traffic, and you act on the result in your backend.
How is ShieldLabs different from traditional abuse prevention platforms?
ShieldLabs gives you the detection depth large platforms build in-house: network and device intelligence, 99.9% identification accuracy, 99.9% risk signal detection accuracy, and an explainable risk score. It is enterprise-level functionality without enterprise pricing, self-serve, with transparent pricing that scales with traffic and integration in about 5 minutes.
What can ShieldLabs detect?
ShieldLabs detects VPN, proxy, Tor, iCloud Private Relay, anti-detect browsers, datacenter and hosting infrastructure, IP reputation, environment spoofing, device tampering, OS mismatch, location and geolocation spoofing, timezone mismatches, and incognito mode. It also recognizes returning visitors even after cleared cookies and rotated IPs, and detects four High-Risk Events directly: Multi-accounting, Account sharing, Impossible travel, and Account takeover. All detection works in real time.
Does ShieldLabs detect anti-detect browsers?
Yes. Anti-detect browsers are designed to mask device fingerprints and rotate identities. ShieldLabs detects them through cross-layer mismatch analysis, identifying the difference between what the browser claims and what is actually detected.
Can ShieldLabs detect a visitor in incognito mode or on a VPN?
Yes. Device and browser fingerprinting signals remain consistent even in incognito mode. VPN connections are detected through IP intelligence and cross-layer mismatch analysis. ShieldLabs identifies the visitor in both cases.
Can ShieldLabs detect fake accounts and multi-accounting?
Yes. The system builds an identity graph linking visitors, devices, and accounts across sessions. When the same person creates multiple accounts, even using different IPs, browsers, or anti-detect tools, the system connects them through shared device and network characteristics.
Can ShieldLabs detect account takeover?
Yes. When an account is accessed from an unrecognized device, suspicious connection, or unusual location, ShieldLabs detects it as an Account takeover High-Risk Event with Medium or High confidence.
Does ShieldLabs detect account sharing?
Yes. When multiple devices, locations, and network signatures access the same account, ShieldLabs detects it as an Account sharing High-Risk Event with Medium or High confidence, helping protect subscription value and enforce per-user access.
Can ShieldLabs detect location spoofing?
Yes. The system detects timezone and geolocation mismatches between what the browser reports and what the IP and network reveal, and flags masked or spoofed visitor location. Logins from locations too far apart for the time between them are detected as an Impossible travel High-Risk Event.
Can a visitor be recognized when IP changes?
Yes. ShieldLabs generates a persistent visitor ID. This identifier remains stable across sessions even when the visitor changes IP, clears cookies, switches to incognito mode, or creates a new account.
What is a persistent visitor ID?
A persistent visitor ID is a stable identifier assigned to each visitor. Unlike cookies or IP addresses, it survives IP rotation, cookie clearing, incognito mode, and account changes - allowing real-time recognition of returning visitors regardless of how they try to hide.
What is browser fingerprinting?
Browser fingerprinting is a technique for identifying website visitors by collecting unique browser signals such as browser version, preferred language, screen resolution, installed fonts, and graphics rendering. These signals are combined to generate a unique identifier that recognizes the visitor across sessions, even without cookies.
What is device fingerprinting?
Device fingerprinting identifies a visitor based on hardware and operating system signals such as device type, OS version, memory, processor, and screen parameters. Combined with browser fingerprinting, it produces a more stable and accurate identification.
How does device fingerprinting differ from browser fingerprinting?
Browser fingerprinting collects signals from the browser, such as version and language. Device fingerprinting collects signals from the hardware and operating system, such as device type and OS. ShieldLabs combines both to generate a persistent visitor ID with higher accuracy than either method alone.
Does ShieldLabs do device fingerprinting or browser fingerprinting?
Both. ShieldLabs analyzes 300+ signals across device, operating system, and browser to generate a persistent visitor ID. It then cross-validates these signals against network and IP data to detect mismatches and expose anonymous visitors.
Is browser fingerprinting safe?
For businesses, browser fingerprinting is used to identify anonymous visitors and distinguish between legitimate users and potentially fraudulent ones. ShieldLabs does not track users across sites and does not collect personally identifiable information during the fingerprinting process. For visitors, the process is invisible and adds no friction to their experience.
What is an identity graph?
An identity graph is a map of connections between visitors, devices, and accounts. ShieldLabs builds this graph automatically by linking persistent visitor IDs, device fingerprints, and network signals across all sessions, revealing which accounts are connected and the risk level of each connection.
What is Risk Score?
Risk Score is a numerical assessment of explainable risk for every visit. It is calculated from risk signals, cross-layer mismatches, and network signals. A high score indicates an increased probability of an anonymous or masked visit. Every score includes clear reasons for every contributing factor.
How is Risk Score calculated?
Each detected signal contributes to the final score - VPN detection, proxy connection, OS mismatch between browser and network, timezone conflict, data center IP, and more. Risk score reflects the cumulative risk level and explains each factor.
What is traffic risk level?
Traffic risk level is an overall assessment of anonymity across all your traffic. It shows what percentage of visitors fall into each of three bands: Trusted (0-29), Suspicious (30-59), or Dangerous (60-100), giving you visibility into overall traffic quality.
What are High-Risk Events?
High-Risk Events are four detections ShieldLabs runs out of the box across visitors, devices, and accounts: Multi-accounting, Account sharing, Impossible travel, and Account takeover. Each event comes with Medium or High confidence, a separate axis from the Risk Score, and is available in the analytics dashboard, API, and webhooks.
What is traffic quality?
Traffic quality is a measure of how much of your traffic comes from real, identifiable visitors versus anonymous, masked, or suspicious traffic. ShieldLabs assigns a risk level to your overall traffic and a risk score to every visitor.
Does ShieldLabs block fraud?
Yes. ShieldLabs stops fraud and abuse: it flags risky users and helps block fraudulent and abusive traffic. Detection is ready out of the box, with no rule setup. Risk signals, the risk score, and High-Risk Events arrive through the API and webhooks, so you choose the action for each case and act on the result in your backend.
Does ShieldLabs affect real users?
No. The system operates in the background and does not require any additional actions from visitors. No CAPTCHAs, no challenges, no friction.
How accurate is ShieldLabs?
ShieldLabs identifies visitors with 99.9% identification accuracy and detects risk signals with 99.9% risk signal detection accuracy by correlating signals across device and network layers, rather than relying on a single cookie or IP address that breaks within weeks.
How long does integration take?
Integration takes approximately 5 minutes. Add a code snippet to your site, and the system immediately begins anonymous visitor identification and real-time traffic analysis.
Which frameworks are supported?
ShieldLabs works with any stack. The JavaScript snippet drops into a framework, a CMS, or a no-code builder, with ready integrations for JavaScript, WordPress, Shopify, Tilda, Next.js, React, Angular, Vue.js, Preact, and Svelte.
Does ShieldLabs provide API and Webhooks?
Yes. Risk score, visitor IDs, and detailed detection signals are available via API and Webhooks in real time, so you can act on the result in your backend and automate your workflows.
How does pricing work?
ShieldLabs has transparent, self-serve pricing that scales with your traffic, billed per identification. It starts at $0 for a one-time 5,000 identifications (hard cap, no overage), then $99 per month for 25,000, $399 per month for 150,000, and $999 per month for 500,000, with the full feature set on every tier. Yearly billing costs 20% less, for example $79 per month for Starter. On paid plans, extra identifications are billed at the plan rate by default; you can turn overage off in settings. Self-serve, with no "Contact Sales."
Is there a free tier?
Yes. ShieldLabs starts at $0 with a one-time 5,000 free identifications (a hard cap: further checks return 402, with no overage), so you can identify anonymous visitors and score your traffic today. From there, transparent pricing scales with your needs, starting at $99 per month for 25,000 identifications. Every tier includes the API and webhooks.

ShieldLabs is a visitor identification and anonymous-visitor detection platform, and a visitor identification API for fraud prevention. It helps you identify anonymous visitors, detects anonymity at any level, and returns an explainable risk score with the signals behind it, along with four High-Risk Events detected out of the box: Multi-accounting, Account sharing, Impossible travel, and Account takeover.

You add one JavaScript snippet to your site. On every visit, ShieldLabs collects 300+ signals across device and network, identifies the visitor, and delivers an explainable risk score from 0 to 100 through an API and webhooks. Detection is ready out of the box, and you choose the action for each case.

ShieldLabs is used to identify anonymous visitors, assess traffic quality, and detect abuse activity such as multi-accounting, fake account creation, account takeover, free trial abuse, bonus abuse, ban evasion, referral fraud, account sharing, coupon abuse, subscription abuse, giveaway fraud, voting manipulation, and survey fraud.

ShieldLabs is built for platforms that need enterprise-level functionality without enterprise pricing, from a first launch to high-traffic scale: SaaS, fintech, iGaming, e-commerce, Web3, media and streaming, travel, and technology platforms. Product, fraud, and growth teams use it to detect multi-accounting, account sharing, account takeover, and impossible travel, and any business dealing with anonymous traffic and abuse can put it to work.

Yes. ShieldLabs is a visitor identification API for fraud prevention. You add one JavaScript snippet, and every visit returns a persistent visitor ID, the risk signals behind it such as VPN, proxy, Tor, and anti-detect browser, and an explainable risk score from 0 to 100 over an API and webhooks. ShieldLabs flags risky users and helps block fraudulent and abusive traffic, and you act on the result in your backend.

ShieldLabs gives you the detection depth large platforms build in-house: network and device intelligence, 99.9% identification accuracy, 99.9% risk signal detection accuracy, and an explainable risk score. It is enterprise-level functionality without enterprise pricing, self-serve, with transparent pricing that scales with traffic and integration in about 5 minutes.

ShieldLabs detects VPN, proxy, Tor, iCloud Private Relay, anti-detect browsers, datacenter and hosting infrastructure, IP reputation, environment spoofing, device tampering, OS mismatch, location and geolocation spoofing, timezone mismatches, and incognito mode. It also recognizes returning visitors even after cleared cookies and rotated IPs, and detects four High-Risk Events directly: Multi-accounting, Account sharing, Impossible travel, and Account takeover. All detection works in real time.

Yes. Anti-detect browsers are designed to mask device fingerprints and rotate identities. ShieldLabs detects them through cross-layer mismatch analysis, identifying the difference between what the browser claims and what is actually detected.

Yes. Device and browser fingerprinting signals remain consistent even in incognito mode. VPN connections are detected through IP intelligence and cross-layer mismatch analysis. ShieldLabs identifies the visitor in both cases.

Yes. The system builds an identity graph linking visitors, devices, and accounts across sessions. When the same person creates multiple accounts, even using different IPs, browsers, or anti-detect tools, the system connects them through shared device and network characteristics.

Yes. When an account is accessed from an unrecognized device, suspicious connection, or unusual location, ShieldLabs detects it as an Account takeover High-Risk Event with Medium or High confidence.

Yes. When multiple devices, locations, and network signatures access the same account, ShieldLabs detects it as an Account sharing High-Risk Event with Medium or High confidence, helping protect subscription value and enforce per-user access.

Yes. The system detects timezone and geolocation mismatches between what the browser reports and what the IP and network reveal, and flags masked or spoofed visitor location. Logins from locations too far apart for the time between them are detected as an Impossible travel High-Risk Event.

Yes. ShieldLabs generates a persistent visitor ID. This identifier remains stable across sessions even when the visitor changes IP, clears cookies, switches to incognito mode, or creates a new account.

A persistent visitor ID is a stable identifier assigned to each visitor. Unlike cookies or IP addresses, it survives IP rotation, cookie clearing, incognito mode, and account changes - allowing real-time recognition of returning visitors regardless of how they try to hide.

Browser fingerprinting is a technique for identifying website visitors by collecting unique browser signals such as browser version, preferred language, screen resolution, installed fonts, and graphics rendering. These signals are combined to generate a unique identifier that recognizes the visitor across sessions, even without cookies.

Device fingerprinting identifies a visitor based on hardware and operating system signals such as device type, OS version, memory, processor, and screen parameters. Combined with browser fingerprinting, it produces a more stable and accurate identification.

Browser fingerprinting collects signals from the browser, such as version and language. Device fingerprinting collects signals from the hardware and operating system, such as device type and OS. ShieldLabs combines both to generate a persistent visitor ID with higher accuracy than either method alone.

Both. ShieldLabs analyzes 300+ signals across device, operating system, and browser to generate a persistent visitor ID. It then cross-validates these signals against network and IP data to detect mismatches and expose anonymous visitors.

For businesses, browser fingerprinting is used to identify anonymous visitors and distinguish between legitimate users and potentially fraudulent ones. ShieldLabs does not track users across sites and does not collect personally identifiable information during the fingerprinting process. For visitors, the process is invisible and adds no friction to their experience.

An identity graph is a map of connections between visitors, devices, and accounts. ShieldLabs builds this graph automatically by linking persistent visitor IDs, device fingerprints, and network signals across all sessions, revealing which accounts are connected and the risk level of each connection.

Risk Score is a numerical assessment of explainable risk for every visit. It is calculated from risk signals, cross-layer mismatches, and network signals. A high score indicates an increased probability of an anonymous or masked visit. Every score includes clear reasons for every contributing factor.

Each detected signal contributes to the final score - VPN detection, proxy connection, OS mismatch between browser and network, timezone conflict, data center IP, and more. Risk score reflects the cumulative risk level and explains each factor.

Traffic risk level is an overall assessment of anonymity across all your traffic. It shows what percentage of visitors fall into each of three bands: Trusted (0-29), Suspicious (30-59), or Dangerous (60-100), giving you visibility into overall traffic quality.

High-Risk Events are four detections ShieldLabs runs out of the box across visitors, devices, and accounts: Multi-accounting, Account sharing, Impossible travel, and Account takeover. Each event comes with Medium or High confidence, a separate axis from the Risk Score, and is available in the analytics dashboard, API, and webhooks.

Traffic quality is a measure of how much of your traffic comes from real, identifiable visitors versus anonymous, masked, or suspicious traffic. ShieldLabs assigns a risk level to your overall traffic and a risk score to every visitor.

Yes. ShieldLabs stops fraud and abuse: it flags risky users and helps block fraudulent and abusive traffic. Detection is ready out of the box, with no rule setup. Risk signals, the risk score, and High-Risk Events arrive through the API and webhooks, so you choose the action for each case and act on the result in your backend.

No. The system operates in the background and does not require any additional actions from visitors. No CAPTCHAs, no challenges, no friction.

ShieldLabs identifies visitors with 99.9% identification accuracy and detects risk signals with 99.9% risk signal detection accuracy by correlating signals across device and network layers, rather than relying on a single cookie or IP address that breaks within weeks.

Integration takes approximately 5 minutes. Add a code snippet to your site, and the system immediately begins anonymous visitor identification and real-time traffic analysis.

ShieldLabs works with any stack. The JavaScript snippet drops into a framework, a CMS, or a no-code builder, with ready integrations for JavaScript, WordPress, Shopify, Tilda, Next.js, React, Angular, Vue.js, Preact, and Svelte.

Yes. Risk score, visitor IDs, and detailed detection signals are available via API and Webhooks in real time, so you can act on the result in your backend and automate your workflows.

ShieldLabs has transparent, self-serve pricing that scales with your traffic, billed per identification. It starts at $0 for a one-time 5,000 identifications (hard cap, no overage), then $99 per month for 25,000, $399 per month for 150,000, and $999 per month for 500,000, with the full feature set on every tier. Yearly billing costs 20% less, for example $79 per month for Starter. On paid plans, extra identifications are billed at the plan rate by default; you can turn overage off in settings. Self-serve, with no "Contact Sales."

Yes. ShieldLabs starts at $0 with a one-time 5,000 free identifications (a hard cap: further checks return 402, with no overage), so you can identify anonymous visitors and score your traffic today. From there, transparent pricing scales with your needs, starting at $99 per month for 25,000 identifications. Every tier includes the API and webhooks.