hCaptcha is a bot-detection and fraud-prevention service that websites and apps embed at the points where abuse happens: signup forms, login pages, checkout flows and APIs. If you have ever clicked squares containing buses, you have met the consumer-facing end of it — but that widget is the smallest part of the product. hCaptcha now presents itself as an enterprise-grade platform for real-time bot detection, AI agent verification and fraud prevention, evaluating behaviour continuously across a session rather than gating a single moment with a puzzle.
The company behind it matters to the story. hCaptcha is a service of Intuition Machines, Inc., which holds the trademark, and its advisor list includes Brave CEO and JavaScript creator Brendan Eich alongside UC Berkeley professor Dawn Song. That lineage explains the positioning: the pitch is explicitly aimed at Google's reCAPTCHA, and the differentiator is that hCaptcha is not owned by an advertising business. Its architecture is marketed as Zero-PII, and the claim is that detection can work without the browser fingerprinting that ad-adjacent security products rely on. Rather than relying on browser fingerprinting or personal data, it continuously assesses whether activity reflects legitimate user intent, using what the company calls Advanced Threat Signatures plus behavioural analysis and risk scoring drawn from thousands of signals.
It is worth knowing where the product came from, because the origin still shows. The About page's own description still calls it a drop-in replacement for reCAPTCHA that earns website owners money and helps companies get their data labeled — a two-sided marketplace where publishers were paid for the human labour of solving challenges, and that labour produced training data. The enterprise security platform grew out of that machine, and both halves still exist in the documentation.
This is infrastructure, not an app. Nobody signs up to use hCaptcha the way they sign up for a writing assistant; a developer integrates it, a security team tunes it, and millions of end users encounter it without ever choosing it.
h-captcha class and your data-sitekey, typically inside the form you want to protect. Teams arriving from Google's product usually rely on drop-in reCAPTCHA compatibility here and keep their existing markup almost untouched.script-src, frame-src, style-src and connect-src. Critically, do not hard-code specific subdomains, like newassets.hcaptcha.com, into your CSP: asset subdomains used may vary over time or by region.callback, error-callback and expired-callback so your application handles token expiry gracefully rather than failing at submit time.There is a genuinely free tier. hCaptcha offers a free Basic tier, a Pro tier that bundles a monthly evaluation allowance and then charges per thousand evaluations beyond it, and an Enterprise tier sold through sales. The free plan is not a trial: it includes the core bot protection, global availability and the compliance posture, which is why the service is common on small sites and open-source projects.
The tier boundaries are worth studying before committing, because the capabilities most people assume are core are not. Risk scores, the fully passive No-CAPTCHA mode, APT mitigation, enterprise SLAs, SAML SSO and the reporting APIs are all Enterprise-only, while the low-friction passive mode, custom themes and analytics sit at Pro. If your plan depends on reading a numeric risk score in your own logic, you are buying Enterprise regardless of your traffic volume. Pro is offered with a time-limited free trial that requires no payment details and reverts to the free plan automatically. Note also that the headline competitive claim about accuracy and cost carries a footnote: cost and accuracy estimates are based on customer-reported comparison data — that is, customer self-reporting rather than independent benchmarking. Confirm current figures on the official pricing page.
Yes, there is a permanent free tier that includes core bot protection, global availability and the stated compliance posture — not merely a trial. Paid tiers add passive modes, analytics, risk scores and enterprise controls, with usage metered by evaluation volume.
Deliberately easy. The methods are API-compatible with reCAPTCHA equivalents such as render() and onload(), and attributes like theme, size and tab-index work the same way, so most existing integrations need a script swap and a new key rather than a rewrite.
That is not quite the claim. The Zero-PII architecture is about minimising personal information, but the privacy policy discloses collection of behavioural signals such as mouse movements, scroll position and keypress events to determine whether a visitor is human. The stated position is that this is not tied to an identified individual.
The privacy policy classifies responses to prompts as Labeled Data, used for labeling data for machine learning applications, and states it is not tied to any identified individual. This reflects the product's origins as a data-labelling marketplace alongside its security function.
The vendor states it supports compliance with GDPR and CCPA and maintains ISO 27001, SOC 2 Type II and PCI DSS certifications, with EU transfers handled under standard contractual clauses in its data processing addendum. Importantly, end-user data processing is governed by your agreement with hCaptcha rather than by its public privacy policy, so your own DPA and privacy notice carry the obligation.
Partly, and the vendor is candid about the boundary. It offers a text-based accessibility challenge and a registered accessibility cookie, targets WCAG 2.2 AA, but states that visual challenges cannot be fully accessible while performing their security function, and that the site operator decides which accommodations to enable.
To some degree, yes — this is true of the whole category. Independent reporting has documented commercial solving services priced at fractions of a cent per solve and AI-based attacks against widely used CAPTCHAs, which is why the vendor's roadmap emphasises passive behavioural detection over harder puzzles.
Always. The browser only receives a token; your server must submit it to the verification endpoint before trusting the request. Any check that exists only on the client can be bypassed by the attacker who controls that client.
It is a service of Intuition Machines, Inc., which holds the trademark. The company's advisors include Brave CEO and JavaScript creator Brendan Eich and UC Berkeley professor Dawn Song, and its stated specialism is deep learning and large-scale visual-domain machine learning.
The vendor explicitly markets global availability as a differentiator against reCAPTCHA, which is not reliably reachable everywhere. This was one of Cloudflare's stated reasons for adopting it in 2020, alongside cost and privacy considerations.