Risk Signals

Detect anonymous traffic with 99.9% accuracy

Know every visitor hiding behind anonymization tools, in real time

Risk signals analytics dashboard with 0-100 risk score per visitor

Identification

Identify and collect 300+ signals across device, OS, browser, IP, and network layers, detecting inconsistencies

BI-grade analytics

Measure anonymous risk across traffic, with per-visitor signal data and High-Risk Event detection

Risk Scoring

Score every visitor 0-100 with a signal-by-signal breakdown

API & Webhooks

Get detailed identification, risk score, and risk signal data, ready to act on in your backend

Risk Signals

The complete risk signal set, returned on every visit

Network Intelligence

Reveal the real IP behind a masked connection, even on fresh or residential addresses that look clean

IP Geolocation

Determine the geographic location and timezone of the real IP address

VPN

Detect traffic routed through a VPN to mask the real IP address and location

Proxy

Detect traffic routed through proxy servers

Tor

Detect connections through the Tor network, the highest-effort anonymization method

Privacy Relay

Detect Apple's iCloud Private Relay connections

Datacenter

Detect connections from cloud providers, data centers, and hosting infrastructure

Abuser (IP Reputation)

Detect IP addresses with poor reputation, reported in IP blocklist and IP reputation databases for fraud or policy violations

Anti-Detect Browser

Detect browsers specifically engineered to appear as a completely different identity on every visit

Browser Automation

Detect browsers driven by an automation framework instead of a real person

Geolocation Spoofing

Detect spoofed or inconsistent geographic location signals

OS Tamper Detection

Detect inconsistencies and anomalies in the reported operating system

Incognito Detection

Detect visitors masking identity and history through incognito mode

IP Mismatch

Flag when the visible IP does not match the real IP revealed behind the connection

Suspicious Paid Click

Flag paid ad clicks arriving on anonymized connections before they reach your attribution

5 minutes to first risk signal

  1. 1

    Sign up free

    Create a free account with 5,000 identifications included

  2. 2

    Install the snippet

    It identifies every visitor and returns their risk signals and a risk score

  3. 3

    Check your traffic quality

    See how much of your traffic is masked, with an overall traffic score

  4. 4

    Use the API and Webhooks

    Act on the risk score and risk signals in your backend to stop fraud and abuse

api.shieldlabs.ai/v1/visits/latest
{
  "request_id": "0c284695-cf0b-4755-8beb-0a2e9536595e",
  "visitor_id": "aa8c616a-8a25-4a5e-bee2-a9a08e5128a4",
  "device_id": "6a45967d-1371-9652-ba99-b01ea3992208",
  "user_hid": "u_9f2a41c7",
  "public_ip": { "ip": "62.197.149.124", "country": "United States" },
  "local_ip": { "ip": "45.83.91.7", "country": "United States" },
  "connection_type": "vpn",
  "os": "Windows",
  "browser": "Chrome",
  "device_type": "desktop",
  "risk_score": 85,
  "signals": [
    { "name": "antidetect_browser", "weight": 60 },
    { "name": "vpn", "weight": 15 },
    { "name": "timezone_mismatch", "weight": 10 }
  ]
}

See every risk signal on your traffic.

Free 5,000 one-time identifications, with transparent pricing that scales with your needs

Frequently asked questions

Risk signals are individual detection results that show a visitor is hiding their real identity, connection, or location. Each one fires independently on every visit. Network layer: VPN, Tor, proxy, datacenter, iCloud Private Relay, IP reputation; Device & OS layer: anti-detect browser, browser automation, OS mismatch, incognito mode; Location layer: geolocation spoofing and timezone mismatch. ShieldLabs returns all of them on the first visit, each contributing to a single 0-100 risk score.

iCloud Private Relay is Apple's privacy feature that routes Safari traffic through two separate internet relays so no single party sees both who the user is and which site they visit. ShieldLabs detects it as a standalone signal on every visit. It hides the user's real egress IP, so IP geolocation reflects the relay, not the device; It is a legitimate privacy tool, not anonymization for abuse, so it carries lighter weight than a VPN or proxy; It is reported separately, never merged into the VPN or proxy signal. ShieldLabs keeps Private Relay as its own signal so your team can treat privacy-conscious users differently from connections routed to evade detection.

ShieldLabs detects anonymous visitors on every visit and helps block fraudulent and abusive traffic, and you choose the action for each case. ShieldLabs returns a 0-100 risk score plus the signal-by-signal breakdown behind it; Detection is ready out of the box, with no rule setup; You act on the result in your backend: block, challenge, or monitor, since anonymity on its own is not the same as abuse. ShieldLabs flags risky users so privacy-conscious visitors keep a smooth experience.

A single risk signal is never treated as proof of abuse, which keeps false positives low. Many people legitimately use a VPN or Private Relay. No signal counts as abuse on its own; they combine into one risk score; Lower-risk signals like Private Relay carry less weight than a Tor connection or an anti-detect browser; The score lands in one of three bands, Trusted, Suspicious, or Dangerous. ShieldLabs reports the full signal context on every visit, so privacy-conscious users stay separate from abusive traffic.

Yes. Every visit carries full traffic attribution, so you can measure anonymous traffic per channel and campaign. Each request includes the referring domain and the full UTM set: source, medium, campaign, and content; The analytics dashboard breaks anonymity rates down by channel, so you can spot which sources send the most VPN, proxy, or anti-detect browser traffic; The same attribution is available over the API for your own reporting. ShieldLabs ties every risk signal to its traffic source, turning paid-channel abuse into something you can measure instead of guess.

IP reputation reflects how an IP address has behaved across the web, indicating whether it has previously been reported for abuse or policy violations elsewhere. ShieldLabs returns it as the Abuser signal on every visit. It draws on public IP blocklist and reputation databases that track shared abuse history; A poor reputation often points to recycled residential or datacenter ranges already used for abuse; It runs alongside every other risk signal, so a reputation hit never acts alone. ShieldLabs surfaces IP reputation as one input among many in the risk score.

No. The ShieldLabs snippet runs asynchronously, so it never blocks rendering or slows page load. It loads in the background and does not sit in the critical path of the page; Signals are collected in the background and scored server-side, off the user's render thread; You can drop it on any checkpoint (signup, login, or checkout) without touching page-load budgets. ShieldLabs is built as a single async snippet, so detection runs without your users ever feeling it.