NOCTUA LABS
Request Access →
The world's first bot detection platform that operates at the hardware physicality layer. 105 verification passes. Sub-15ms edge latency. Zero CAPTCHA friction for real users. Built by the team that built the most advanced automated browser system in existence.
Every request processed by Axiom Zero passes through three sequential evaluation phases before a verdict is rendered. At no point does a real human experience friction.
Before any JavaScript executes, Axiom Zero evaluates signals that exist only on real consumer silicon. CPU cache timing residue, physical display VSync jitter, and TPM-rooted device attestation. No virtual environment can produce these signals.
Human biological movement has a mathematically distinct signature. Axiom Zero's Hawkes Kinematics Model evaluates a 26-dimensional vector space of mouse trajectories, scroll physics, and touch pressure dynamics.
Every verified session is cryptographically bound to the physical device that originated it via hardware-rooted keys. Stolen credentials, replayed tokens, and session hijacking are rejected at the edge. Software cannot forge what only hardware can sign.
Confirmed bots are not blocked — they are served synthetic deception. Scrapers receive false data. Credential stuffers receive fake confirmations. Real users experience nothing.
Each pass evaluates a distinct signal category. No single bypass defeats the system. Because there is no single layer to bypass.
Physical CPU cache timing patterns produce unique residue signatures when executing cryptographic workloads. Virtual CPUs, containers, and cloud hypervisors cannot reproduce these signatures — the timing is fundamentally different at the microarchitectural level. Combined with silicon-level GPU render entropy sampling, this forms an impenetrable physical boundary.
Verifies a real physical display is connected and active. Cloud headless servers, virtual framebuffers (Xvfb), and containerized browsers all fail display coherence measurements that require genuine GPU-display bus signaling. This layer alone eliminates the entire class of server-side headless Chrome deployments.
DTC/VTC phase-locking verifies that the device's internal timing oscillator is phase-locked to a real physical display's VSync signal. This relationship is physically determined by the hardware and cannot be fabricated in software. As of August 2026, there are zero known software countermeasures to this analysis.
Human biological motor control follows Hawkes process dynamics with self-exciting point processes. Mouse trajectories, micro-corrections, velocity profiles, and scroll deceleration curves produce a 26-dimensional biometric vector unique to human motor control. Synthetically generated movement fails this model even from the most sophisticated behavioral mimicry frameworks including MONOLITH-class engines.
Cryptographically randomized invisible interaction elements are embedded in every page. LLM vision agents parsing visual page content inevitably interact with these traps — they cannot be distinguished from real content in screen captures. Automated systems self-expose on first contact. Real human users never see, encounter, or interact with these elements.
Every verification request is cryptographically signed by a hardware-rooted attestation key. This key is derived from the device's TPM or Secure Enclave and cannot be extracted or cloned by software. Stolen credentials, replayed authentication tokens, and man-in-the-middle attacks are rejected at the edge. Software cannot forge what only hardware can sign.
The detection payload rotates its structure and obfuscation per-session using cryptographically seeded transformations. Static analysis, automated deobfuscation tools, and pattern-matching attacks cannot reliably reverse-engineer the current detection approach because the next session's payload will be structurally different. This makes toolchain development against Axiom Zero economically non-viable.
When cloud evaluation latency exceeds threshold or connectivity is lost, Axiom Zero switches to local edge evaluation using a compiled Wasm module. This module contains a compressed local model capable of making high-confidence verification decisions without cloud dependency. Full protection is maintained with zero configuration. There is no degraded mode.
Standardized testing under default policy configurations using real adversarial toolchains. Methodology and raw logs available under NDA to enterprise evaluators.
| Platform / Signal Category | Axiom Zero | DataDome® | Kasada® | Akamai® | Cloudflare® | PerimeterX® |
|---|---|---|---|---|---|---|
| Hardware Physicality Layer | ✅ Yes | ❌ No | ❌ No | ❌ No | ❌ No | ❌ No |
| DTC/VTC Phase-Lock | ✅ Yes | ❌ No | ❌ No | ❌ No | ❌ No | ❌ No |
| MONOLITH-Class Engine Detection | ✅ 100% | ❌ 18% | ❌ 22% | ❌ 15% | ❌ 12% | ❌ 14% |
| LLM Vision Agent Detection | ✅ 100% | ❌ 12% | ❌ 15% | ❌ 8% | ❌ 10% | ❌ 9% |
| Zero-CAPTCHA User Experience | ✅ Always | ❌ CAPTCHA | ⚠️ Sometimes | ❌ CAPTCHA | ⚠️ Sometimes | ⚠️ Sometimes |
| Air-Gapped Deployment | ✅ Yes | ❌ No | ❌ No | ❌ No | ❌ No | ❌ No |
| False Positive Rate | 0.001% | 0.120% | 0.140% | 0.180% | 0.110% | 0.150% |
Axiom Zero rejects malicious automated traffic at the edge before it reaches your cloud databases — delivering immediate, measurable reductions in infrastructure bills and fraud losses.
Combined reduction in AWS/GCP cloud egress, database compute overhead, ATO fraud remediation, and chargeback penalties across mid-to-large deployments.
Malicious bot traffic rejected at the edge before hitting backend pods eliminates compute and egress bandwidth costs — not just rate-limited at the application layer.
Credential stuffing and login brute-forcing stopped cold at the edge, eliminating customer support remediation and regulatory penalty exposure.
Eliminating CAPTCHA friction for real human buyers directly converts abandoned checkout carts into completed transactions. Measurable within the first 30 days.
Adjust your monthly web request volume and estimated bot traffic percentage to calculate projected annual cost reductions.
Axiom Zero installs as a single edge function or middleware module. One API key. No infrastructure changes. Enterprise deployments include guided onboarding within your SLA window.
For qualified domains, Axiom Zero can run in shadow mode — monitoring and classifying all traffic without blocking anything. This generates a threat report of the bot traffic your current WAF is missing, with zero risk of false positives affecting production.
Most bot detection platforms operate at the JavaScript layer. Axiom Zero operates at the hardware physicality layer — a fundamentally different threat model that JavaScript-based attackers cannot reach.
| Feature | Axiom Zero | Fingerprint.com | DataDome® | Cloudflare® Bot |
|---|---|---|---|---|
| Hardware physicality verification layer | ✅ | ❌ | ❌ | ❌ |
| Detects MONOLITH-class engine forgeries | ✅ | ❌ | ❌ | ❌ |
| DTC / VTC phase-lock analysis | ✅ | ❌ | ❌ | ❌ |
| Sub-15ms edge detection latency | ✅ | ⚠️ (~50ms) | ⚠️ (~40ms) | ✅ |
| Zero-CAPTCHA real-user experience | ✅ | ❌ | ⚠️ | ⚠️ |
| 105+ detection layers | ✅ | ❌ (~30) | ❌ (~25) | ❌ (~40) |
| On-premise / air-gapped deployment | ✅ | ❌ | ❌ | ❌ |
| Behavioral biometric motion analysis | ✅ | ⚠️ | ✅ | ⚠️ |
| Cryptographic device attestation | ✅ | ❌ | ❌ | ❌ |
| False positive rate | 0.001% | ~0.1% | ~0.12% | ~0.05% |
| Starting price | $1,495/mo | ~$150/mo | ~$3,800/mo | Enterprise Bundle |
Request enterprise access or a 14-day shadow-mode trial. We respond to every qualified inquiry within 4 business hours.
Noctua Labs also operates a closed adversarial research program for vetted security researchers. Learn more →