Browser scripts can change most reported device values. Heretic compares those claims with packet location, kernel-written fields, UDP behavior, and CPU performance. The result is a verdict with supporting measurements.
Risk scores estimate.
Heretic measures.
Every verdict includes
the supporting measurements.
Run it beside
your current bot controls.
The browser reported Asia/Tokyo, but its TCP handshake reached Warsaw in 2.1 ms. The physical minimum is 27 ms. The endpoint returns a conclusive contradicted verdict and includes both values.
Each ruling includes its measurements and stable rule ids for policy checks.
This synthetic example uses documentation-range addresses and contains no customer data. Every response includes the verdict, edge measurements, client claims, and coverage for each evidence family.
Heretic checks physical limits and independent evidence instead of adding behavioral signals to a risk score.
Heretic compares round-trip time with the minimum travel time between the edge and the claimed location. A browser cannot be in Tokyo if its handshake reaches Warsaw in 2 ms. The evidence tier determines whether one signal is conclusive or requires support from another family.
The client kernel writes the SYN packet fields. Browser scripts cannot change them, and a proxy replaces them with its own fields. CPU probes also compare claimed core counts with measured scaling under load.
The edge advertises QUIC and records whether the client attempts it. Browsers normally attempt QUIC when it is available. Some residential proxy setups do not pass the attempt through.
Absolute violations are conclusive alone. Composite findings require support from an independent family. Weak signals provide context but never make a verdict conclusive.
The collector compiles into the site bundle and connects directly to a bare-metal edge. It requires no DNS handover and adds no reverse proxy to the request path. If the collector connection is blocked, the session returns insufficient with a no-return reason.
A physical limit was violated or required measurements were refused. This tier is conclusive on its own.
A second evidence family must support the finding before it becomes conclusive.
May justify a policy action but is never conclusive. The network can produce this signal during normal use.
Provides context only. Weak signals cannot make a verdict conclusive.
A physical limit contradicts a claim, or two independent evidence families agree. This verdict is conclusive.
The client completed the request but withheld required collector measurements. This verdict is conclusive.
One evidence family contradicts a claim without independent support. This verdict is not conclusive.
No rule contradicted the session. The coverage field lists every evidence family that reported.
The edge received too little data to assess the session. The reason identifies missing sensor or client data.
Risk scoring returns a number that needs a policy threshold. Heretic returns a verdict with the measurements used to reach it.
The collector compiles into the site bundle and reports to a signed first-party endpoint. The backend requests a verdict when needed. Heretic requires no nameserver handover or reverse proxy, so an edge outage does not stop site requests.
Published signal ids keep the same meaning and can be used in policy rules.
$ npm install @heretic-hq/collectorBilling, metering, and self-service checkout are not available yet. Early access is private and free. Every proposed plan includes the complete signal catalogue and explain endpoint.
Every plan will return the same verdicts and signals. Planned pricing will vary by request volume and edge placement.
Early access is free for teams testing Heretic alongside an existing bot detection system.