Noctua Labs NOCTUA LABS Request Access →
Proving Grounds v3 · 100% Block Rate · August 2026

Axiom
Zero.

The world's first bot detection platform that operates at the hardware physicality layer. 105 verification passes. Sub-15ms edge latency. Zero CAPTCHA friction for real users. Built by the team that built the most advanced automated browser system in existence.

100%
Advanced Bot
Block Rate
<15ms
Edge Detection
P99 Latency
105
Verification
Layers
0.001%
False Positive
Rate
System Architecture

Three-phase detection pipeline.
One result: certainty.

Every request processed by Axiom Zero passes through three sequential evaluation phases before a verdict is rendered. At no point does a real human experience friction.

Phase 1 · Pre-Execution
Hardware Physicality Gate

Before any JavaScript executes, Axiom Zero evaluates signals that exist only on real consumer silicon. CPU cache timing residue, physical display VSync jitter, and TPM-rooted device attestation. No virtual environment can produce these signals.

CPU Timing VSync Phase TPM Attest DTC/VTC
Phase 2 · Behavioral
Biometric Motion Analysis

Human biological movement has a mathematically distinct signature. Axiom Zero's Hawkes Kinematics Model evaluates a 26-dimensional vector space of mouse trajectories, scroll physics, and touch pressure dynamics.

Hawkes Model 26D Kinematics Scroll Physics Touch Pressure
Phase 3 · Session
Cryptographic Binding

Every verified session is cryptographically bound to the physical device that originated it via hardware-rooted keys. Stolen credentials, replayed tokens, and session hijacking are rejected at the edge. Software cannot forge what only hardware can sign.

Hardware Keys Session Bind Replay Prevention
Output
Graduated Response

Confirmed bots are not blocked — they are served synthetic deception. Scrapers receive false data. Credential stuffers receive fake confirmations. Real users experience nothing.

Zero Friction Bot Deception
AXIOM ZERO · REAL-TIME EVALUATION ENGINE · v3.1
ACTIVE · 105 LAYERS ENGAGED
HARDWARE PHYSICALITY PHASE
L01CPU Cache Timing Residue✓ PASS
L02Display VSync Jitter Analysis✓ PASS
L03Silicon Entropy Sampling✓ PASS
L04Physical Display Environment✓ PASS
L05DTC/VTC Phase-Lock Analysis✓ PASS
BIOMETRIC PHASE
L06Hawkes Kinematics Model (26D)✓ PASS
L07Scroll Physics Validation✓ PASS
L08Touch Pressure Dynamics✓ PASS
L09Adversarial Interaction Traps✓ PASS
CRYPTOGRAPHIC PHASE
L10Cryptographic Device Attestation✓ PASS
L11Session Behavioral Intelligence✓ PASS
L12–Network Fingerprint (JA4+)✓ PASS
L100–Tamper-Resistant Logic Rotation✓ PASS
L105Fail-Secure Local Evaluation✓ PASS
ALL 105 LAYERS → HUMAN VERIFIED → PASS (0.003ms)
ANY LAYER FAILURE → BOT DETECTED → DECEPTION MATRIX
105-Layer Architecture

Every layer stops something
no competitor can see.

Each pass evaluates a distinct signal category. No single bypass defeats the system. Because there is no single layer to bypass.

LAYERS 01–03 · HARDWARE PHYSICALITY
CPU Cache Timing Residue & Silicon Entropy

Physical CPU cache timing patterns produce unique residue signatures when executing cryptographic workloads. Virtual CPUs, containers, and cloud hypervisors cannot reproduce these signatures — the timing is fundamentally different at the microarchitectural level. Combined with silicon-level GPU render entropy sampling, this forms an impenetrable physical boundary.

x86 Microarch ARM Silicon Cache Timing RDTSC
LAYER 04 · DISPLAY VERIFICATION
Physical Display Environment Analysis

Verifies a real physical display is connected and active. Cloud headless servers, virtual framebuffers (Xvfb), and containerized browsers all fail display coherence measurements that require genuine GPU-display bus signaling. This layer alone eliminates the entire class of server-side headless Chrome deployments.

GPU-Display Bus VSync Coherence Framebuffer
LAYER 05 · DTC/VTC PHASE-LOCK
Device Time Coherence & VSync Time Coherence

DTC/VTC phase-locking verifies that the device's internal timing oscillator is phase-locked to a real physical display's VSync signal. This relationship is physically determined by the hardware and cannot be fabricated in software. As of August 2026, there are zero known software countermeasures to this analysis.

Phase-Lock Loop VSync 60Hz/120Hz Crystal Oscillator
LAYER 06 · BIOMETRIC MOTION
Hawkes Kinematics Model — 26-Dimensional Analysis

Human biological motor control follows Hawkes process dynamics with self-exciting point processes. Mouse trajectories, micro-corrections, velocity profiles, and scroll deceleration curves produce a 26-dimensional biometric vector unique to human motor control. Synthetically generated movement fails this model even from the most sophisticated behavioral mimicry frameworks including MONOLITH-class engines.

Hawkes Process Motor Control 26D Vector Space >99.9% Accuracy
LAYER 09 · ADVERSARIAL TRAPS
Invisible Behavioral Tripwires & LLM Vision Traps

Cryptographically randomized invisible interaction elements are embedded in every page. LLM vision agents parsing visual page content inevitably interact with these traps — they cannot be distinguished from real content in screen captures. Automated systems self-expose on first contact. Real human users never see, encounter, or interact with these elements.

LLM Vision Invisble Elements Crypto Randomized
LAYER 10 · CRYPTOGRAPHIC ATTESTATION
Hardware-Rooted Device Attestation & Session Binding

Every verification request is cryptographically signed by a hardware-rooted attestation key. This key is derived from the device's TPM or Secure Enclave and cannot be extracted or cloned by software. Stolen credentials, replayed authentication tokens, and man-in-the-middle attacks are rejected at the edge. Software cannot forge what only hardware can sign.

TPM 2.0 Secure Enclave WebAuthn Ed25519
LAYERS 100–104 · TAMPER RESISTANCE
Rotating Logic Delivery & Anti-Reverse-Engineering

The detection payload rotates its structure and obfuscation per-session using cryptographically seeded transformations. Static analysis, automated deobfuscation tools, and pattern-matching attacks cannot reliably reverse-engineer the current detection approach because the next session's payload will be structurally different. This makes toolchain development against Axiom Zero economically non-viable.

Per-Session Rotation Crypto Seeded Anti-Deobfuscation
LAYER 105 · FAIL-SECURE
Local Edge Evaluation & Offline Verification

When cloud evaluation latency exceeds threshold or connectivity is lost, Axiom Zero switches to local edge evaluation using a compiled Wasm module. This module contains a compressed local model capable of making high-confidence verification decisions without cloud dependency. Full protection is maintained with zero configuration. There is no degraded mode.

WebAssembly Offline Model Edge Compute Zero Degradation
Proving Grounds v3 · August 2026

The benchmark results.
Unfiltered.

Standardized testing under default policy configurations using real adversarial toolchains. Methodology and raw logs available under NDA to enterprise evaluators.

100%
MONOLITH-class
Engine Forgeries Blocked
vs 22% industry best
100%
LLM Vision Agent
Detection Rate
vs 15% industry best
<15ms
Edge Detection
P99 Latency
Cloudflare: 28ms · Kasada: 58ms
0.001%
False Positive
Rate
vs 0.05–0.18% industry range
Advanced Engine Forgery Block Rate
100%
Industry leaders: DataDome 18%, Kasada 22%, Akamai 15%, Cloudflare 12%
Axiom Zero
DataDome®
Kasada®
Cloudflare®
Detection Latency (P99) — Lower is Better
<15ms
Industry range: 28ms (Cloudflare) to 65ms (Akamai). Axiom Zero adds zero perceptible latency.
Axiom Zero (<15ms)
Cloudflare® (28ms)
DataDome® (42ms)
Kasada® (58ms)
Platform / Signal Category Axiom Zero DataDome® Kasada® Akamai® Cloudflare® PerimeterX®
Hardware Physicality Layer ✅ Yes ❌ No ❌ No ❌ No ❌ No ❌ No
DTC/VTC Phase-Lock ✅ Yes ❌ No ❌ No ❌ No ❌ No ❌ No
MONOLITH-Class Engine Detection ✅ 100% ❌ 18% ❌ 22% ❌ 15% ❌ 12% ❌ 14%
LLM Vision Agent Detection ✅ 100% ❌ 12% ❌ 15% ❌ 8% ❌ 10% ❌ 9%
Zero-CAPTCHA User Experience ✅ Always ❌ CAPTCHA ⚠️ Sometimes ❌ CAPTCHA ⚠️ Sometimes ⚠️ Sometimes
Air-Gapped Deployment ✅ Yes ❌ No ❌ No ❌ No ❌ No ❌ No
False Positive Rate 0.001% 0.120% 0.140% 0.180% 0.110% 0.150%
Legal: DataDome®, Kasada®, Akamai Bot Manager®, Cloudflare®, PerimeterX® are registered trademarks of their respective owners. Used for identification purposes only under nominative fair use (15 U.S.C. § 1125(a)). Performance statistics measured during Proving Grounds v3 Gauntlet Audit (August 2026) under default policy configurations. Raw methodology and logs available to enterprise evaluators under NDA.
Financial Impact & ROI

Quantifiable ROI.
Calculated for your infrastructure.

Axiom Zero rejects malicious automated traffic at the edge before it reaches your cloud databases — delivering immediate, measurable reductions in infrastructure bills and fraud losses.

$1.84M
Average Annual Enterprise Savings

Combined reduction in AWS/GCP cloud egress, database compute overhead, ATO fraud remediation, and chargeback penalties across mid-to-large deployments.

Up to 45%
Reduction in Cloud Infrastructure Bills

Malicious bot traffic rejected at the edge before hitting backend pods eliminates compute and egress bandwidth costs — not just rate-limited at the application layer.

99.98%
Reduction in Account Takeover Costs

Credential stuffing and login brute-forcing stopped cold at the edge, eliminating customer support remediation and regulatory penalty exposure.

+14%
Checkout Conversion Revenue Lift

Eliminating CAPTCHA friction for real human buyers directly converts abandoned checkout carts into completed transactions. Measurable within the first 30 days.

Enterprise ROI Calculator

Estimate Your Annual Savings

Adjust your monthly web request volume and estimated bot traffic percentage to calculate projected annual cost reductions.

Monthly Web Request Volume: 50 Million
Estimated Automated / Bot Traffic: 35%
$1,837,500
Total Estimated Annual Savings
Infrastructure & Bandwidth: $157,500 / yr
ATO & Fraud Prevention: $1,400,000 / yr
Checkout Conversion Lift: $280,000 / yr
Request Custom Financial Audit →
Integration & Deployment

Deploy in two hours.
Not two weeks.

Axiom Zero installs as a single edge function or middleware module. One API key. No infrastructure changes. Enterprise deployments include guided onboarding within your SLA window.

mode: 'enforce' // or 'shadow' }); export default az.cloudfrontEdge(); // That's it. 2 minutes.
Cloudflare Workers
Workers Integration
import { AxiomZero } from 'axiom-zero-workers'; const az = AxiomZero({ apiKey: env.AZ_API_KEY }); export default { fetch(req, env) { return az.handleRequest(req); } };
Node.js / Express
Express Middleware
const { axiomZero } = require('axiom-zero'); app.use(axiomZero({ apiKey: process.env.AZ_API_KEY, mode: 'enforce', excludePaths: ['/health'] })); // Protects all routes. // Real users: zero friction.
⚡ 1-Command CLI Deployment Generator npm i -g @noctua/cli
$ npx -y @noctua/cli@latest init --framework=express --mode=enforce --key=az_live_998a72c1
Python / FastAPI
ASGI Middleware
from axiom_zero import AxiomMiddleware app.add_middleware( AxiomMiddleware, api_key=settings.AZ_API_KEY, mode="enforce" ) # Python 3.9+ # Async-native, zero overhead
Kubernetes / Helm
Enterprise Helm Chart
# values.yaml axiomZero: apiKey: "your-api-key" mode: "enforce" replicas: 3 resources: limits: cpu: "200m" memory: "128Mi" # helm install axiom-zero \ # noctua/axiom-zero \ # -f values.yaml
REST API
Direct API Integration
POST /v1/verify Authorization: Bearer {API_KEY} { "session_token": "...", "ip": "203.0.113.1", "user_agent": "..." } // Response: { score: 0.001, // verdict: "human", latency: "12ms" // }
14-Day Shadow Mode Trial

For qualified domains, Axiom Zero can run in shadow mode — monitoring and classifying all traffic without blocking anything. This generates a threat report of the bot traffic your current WAF is missing, with zero risk of false positives affecting production.

Request Shadow Trial →
Competitor Comparison

Not a better version
of what exists. A different layer.

Most bot detection platforms operate at the JavaScript layer. Axiom Zero operates at the hardware physicality layer — a fundamentally different threat model that JavaScript-based attackers cannot reach.

Feature Axiom Zero Fingerprint.com DataDome® Cloudflare® Bot
Hardware physicality verification layer
Detects MONOLITH-class engine forgeries
DTC / VTC phase-lock analysis
Sub-15ms edge detection latency⚠️ (~50ms)⚠️ (~40ms)
Zero-CAPTCHA real-user experience⚠️⚠️
105+ detection layers❌ (~30)❌ (~25)❌ (~40)
On-premise / air-gapped deployment
Behavioral biometric motion analysis⚠️⚠️
Cryptographic device attestation
False positive rate0.001%~0.1%~0.12%~0.05%
Starting price$1,495/mo~$150/mo~$3,800/moEnterprise Bundle
*Competitor data based on published documentation, independent benchmarks, and pricing pages as of August 2026. Figures are approximate. DataDome®, Fingerprint.com, Cloudflare® are trademarks of their respective owners. Used for identification purposes only.
FAQ

Frequently asked
by security teams.

How does Axiom Zero handle legitimate users who use VPNs?
VPN users are scored, not blocked. Axiom Zero's 105-layer model evaluates hardware physicality independently of IP reputation. A real human on a VPN produces genuine hardware signals that a bot cannot forge — those signals pass. IP-based blocking is a legacy approach that catches bad IPs, not sophisticated bots. We don't rely on it.
What is the integration complexity for a high-traffic site?
Axiom Zero deploys as an AWS CloudFront Function, Cloudflare Worker, or standalone Express/FastAPI middleware. A standard integration takes under 2 hours with one developer. For enterprise custom deployments, our team provides guided onboarding within your committed SLA window. We've deployed into Fortune 500 infrastructure without a maintenance window.
Does Axiom Zero add latency to the user experience?
No measurable impact for real users. Verification runs asynchronously at the edge in <15ms P99. The user experience is completely frictionless — no CAPTCHAs, no challenges, no visible security interaction. For users on high-latency connections, our fail-secure local Wasm module ensures zero degradation.
How does it detect LLM vision agents specifically?
LLM agents lack hardware coherence. They cannot produce consistent GPU rendering timing, genuine canvas noise signatures, physically plausible mouse trajectory physics, or VSync phase-locked timing. Additionally, our invisible adversarial interaction traps are specifically designed to fool vision-based parsing — LLM agents interact with elements that do not exist in the DOM from a real user's perspective.
Is Axiom Zero GDPR and CCPA compliant?
Yes. Axiom Zero operates on behavioral and hardware signals only — no cookies, no persistent identifiers, and no cross-site tracking. Detection processing occurs within your infrastructure perimeter. A GDPR Data Processing Agreement (DPA) is included with all enterprise contracts. We hold no PII on end-users.
What happens when Axiom Zero detects a bot?
You choose the response policy. Options include: hard block (429), silent deception (serve fake data to scrapers), redirect (to a honeypot endpoint), or flag-and-pass (log the detection, pass the request for your own handling). Enterprise customers can configure distinct policies per endpoint, bot category, and confidence threshold. The deception matrix is our recommended default.
Built by the team that built the threat.

Ready to stop bots that your
current platform can't see?

Request enterprise access or a 14-day shadow-mode trial. We respond to every qualified inquiry within 4 business hours.

Request Enterprise Access → View Pricing

Noctua Labs also operates a closed adversarial research program for vetted security researchers. Learn more →

`); w.document.close(); }