CaptchaCore is a German project built on an uncomfortable question: why should you have to report the visitors of your own website to an American corporation just to get rid of spam?
Why
Every website needs protection from bots. The usual tools solve that problem but create a new one: they load code from US servers, set cookies, link users across websites and, in case of doubt, require a consent nobody enjoys explaining.
There is also a point that is rarely raised: picture puzzles are a barrier. People with visual impairments regularly fail them, older users give up in frustration, and every abandonment is a lost form. A protective mechanism that locks out your own customers has missed its purpose.
CaptchaCore is the attempt to solve both at once: effective protection through proof of work, behavioural analysis and an adaptive risk engine, and still a check nobody notices and that reports nobody to third parties.
How that differs from reCAPTCHA and hCaptcha in practice is set out on the comparison page.
Who
CaptchaCore is run by SpeedIT Solutions UG (haftungsbeschränkt) from Isernhagen near Hanover. We are not a start-up with a growth mandate but a hosting business that has been running its own servers for years, and learned along the way what bot traffic really looks like.
That is the difference from a bought-in service: we do not rent infrastructure from a provider who in turn rents from a hyperscaler. The application, the database and the processing of your verifications run on machines we own, standing in a Frankfurt data centre.
That is why we can make commitments others cannot. Anyone who does not know where their data sits cannot promise it will stay there either.
Operator
SpeedIT Solutions UG
Registered office
Isernhagen, Germany
Data centre
Frankfurt am Main
Full details in the legal notice.
The supply chain
Data protection does not end at your own application. It ends at the provider you use yourself. That is why we disclose the entire chain, in full, not only the convenient parts.
| Component | Provider | Registered office | Note |
|---|---|---|---|
| Application, API & database | SpeedIT Solutions UG |
|
Our own hardware, no hyperscaler |
| Data centre | NTT Global Data Centers |
|
Housing only, no access to content |
| Widget delivery (CDN) | BunnyWay d.o.o. (Bunny.net) |
|
European company, EU endpoint by default |
| Payments: card, SEPA, Sofort | Mollie B.V. |
|
Dutch payment service provider |
| Payments: PayPal | PayPal (Europe) S.à r.l. |
|
European entity, optional |
| Payments: bank transfer | Your bank |
|
No payment provider at all |
| Invoicing | Haufe-Lexware GmbH & Co. KG |
|
Electronic invoices in ZUGFeRD format |
| Fonts | Self-hosted |
|
Outfit & JetBrains Mono, no Google Fonts |
| Audience measurement | Our own instance |
|
No Google Analytics, no advertising pixel |
The one exception
There are two endpoints for the widget file. The EU endpoint delivers exclusively via European edge locations. Anyone who embeds the global endpoint instead has the same file delivered worldwide, which means the CDN operator sees the visitor's IP address and browser identification outside the EU as well, covered by standard contractual clauses.
This affects only the loading of the script file. The verification itself, meaning challenge, risk engine and database, runs exclusively on our servers in Germany and never through the CDN. Anyone who wants to keep the loading inside the EU as well embeds the EU endpoint.
Evidence
Every sub-processor we use is named in the data processing agreement, which you can conclude electronically in your account as a customer and file as a PDF. Which data is processed for which purpose is set out in the privacy centre.
How
Behavioural data never leaves the browser as raw data, only as condensed metrics and a hash. IP addresses are stored truncated and you set the retention period yourself. What is never collected cannot leak, be sold or be seized.
Normally there is no puzzle, no traffic lights, no waiting. The computation in the background is imperceptible for a single visitor and expensive for a bot farm making millions of requests. If an interaction does become necessary, it is keyboard operable and marked up for screen readers.
We name every provider, including the ones not based in Germany. The system status is public, incidents included. Prices are net prices without asterisks, and cancelling does not require a phone call.
Ready-made plugins for WordPress, WoltLab and Symfony, a Composer package for Laravel and a lean REST API for everything else. Anyone who wants full control can run CaptchaCore on their own infrastructure on request.
The counter-check
A promise only becomes one when it also rules something out.
Where to
The European market is currently looking for alternatives to American services, not out of ideology but because regulators and customers are asking concrete questions. That is the gap we want to fill, with a component small enough to fit in anywhere.
After WordPress, WoltLab, Symfony and Laravel come WooCommerce, Shopware, Joomla and phpBB. Every platform that has a form should be able to use CaptchaCore without writing code.
The risk engine learns from attack patterns across websites. What matters is the pattern, not the person, which is why it works with truncated IP addresses and hashes.
A public system status, traceable reason codes and a data processing agreement you conclude in your account and file as a PDF. External audit reports are the next step.
Missing an integration, or have a requirement that is not listed here? Write to us. Short paths are the advantage of a small team.
The live demo shows the check from the user's side, the pricing page the terms for commercial use. For private websites CaptchaCore stays free permanently.