Isernhagen, Lower Saxony

Bot protection that
hands nobody over.

CaptchaCore is a German project built on an uncomfortable question: why should you have to report the visitors of your own website to an American corporation just to get rid of spam?

Servers in Germany European providers No cookies No Google services Self-hosted fonts

Why

Why this project exists

Every website needs protection from bots. The usual tools solve that problem but create a new one: they load code from US servers, set cookies, link users across websites and, in case of doubt, require a consent nobody enjoys explaining.

There is also a point that is rarely raised: picture puzzles are a barrier. People with visual impairments regularly fail them, older users give up in frustration, and every abandonment is a lost form. A protective mechanism that locks out your own customers has missed its purpose.

CaptchaCore is the attempt to solve both at once: effective protection through proof of work, behavioural analysis and an adaptive risk engine, and still a check nobody notices and that reports nobody to third parties.

How that differs from reCAPTCHA and hCaptcha in practice is set out on the comparison page.

Who

Who is behind it

CaptchaCore is run by SpeedIT Solutions UG (haftungsbeschränkt) from Isernhagen near Hanover. We are not a start-up with a growth mandate but a hosting business that has been running its own servers for years, and learned along the way what bot traffic really looks like.

That is the difference from a bought-in service: we do not rent infrastructure from a provider who in turn rents from a hyperscaler. The application, the database and the processing of your verifications run on machines we own, standing in a Frankfurt data centre.

That is why we can make commitments others cannot. Anyone who does not know where their data sits cannot promise it will stay there either.

Operator

SpeedIT Solutions UG

Registered office

Isernhagen, Germany

Data centre

Frankfurt am Main

Full details in the legal notice.

The supply chain

Where every byte comes from

Data protection does not end at your own application. It ends at the provider you use yourself. That is why we disclose the entire chain, in full, not only the convenient parts.

Component Provider Registered office Note
Application, API & database SpeedIT Solutions UG Germany Our own hardware, no hyperscaler
Data centre NTT Global Data Centers Frankfurt am Main Housing only, no access to content
Widget delivery (CDN) BunnyWay d.o.o. (Bunny.net) Slovenia European company, EU endpoint by default
Payments: card, SEPA, Sofort Mollie B.V. Amsterdam Dutch payment service provider
Payments: PayPal PayPal (Europe) S.à r.l. Luxembourg European entity, optional
Payments: bank transfer Your bank SEPA area No payment provider at all
Invoicing Haufe-Lexware GmbH & Co. KG Freiburg Electronic invoices in ZUGFeRD format
Fonts Self-hosted Germany Outfit & JetBrains Mono, no Google Fonts
Audience measurement Our own instance Germany No Google Analytics, no advertising pixel

The one exception

There are two endpoints for the widget file. The EU endpoint delivers exclusively via European edge locations. Anyone who embeds the global endpoint instead has the same file delivered worldwide, which means the CDN operator sees the visitor's IP address and browser identification outside the EU as well, covered by standard contractual clauses.

This affects only the loading of the script file. The verification itself, meaning challenge, risk engine and database, runs exclusively on our servers in Germany and never through the CDN. Anyone who wants to keep the loading inside the EU as well embeds the EU endpoint.

Evidence

Every sub-processor we use is named in the data processing agreement, which you can conclude electronically in your account as a customer and file as a PDF. Which data is processed for which purpose is set out in the privacy centre.

How

The four principles we want to be judged by

Data minimisation is the architecture, not a setting

Behavioural data never leaves the browser as raw data, only as condensed metrics and a hash. IP addresses are stored truncated and you set the retention period yourself. What is never collected cannot leak, be sold or be seized.

The human notices nothing, the bot pays

Normally there is no puzzle, no traffic lights, no waiting. The computation in the background is imperceptible for a single visitor and expensive for a bot farm making millions of requests. If an interaction does become necessary, it is keyboard operable and marked up for screen readers.

Honesty instead of marketing fog

We name every provider, including the ones not based in Germany. The system status is public, incidents included. Prices are net prices without asterisks, and cancelling does not require a phone call.

Portable, not locked in

Ready-made plugins for WordPress, WoltLab and Symfony, a Composer package for Laravel and a lean REST API for everything else. Anyone who wants full control can run CaptchaCore on their own infrastructure on request.

The counter-check

What we deliberately do not do

A promise only becomes one when it also rules something out.

No sharing or monetising of user data. To nobody, at no price.
No tracking cookies and no advertising pixel in the widget.
No Google services: no fonts, no analytics, no maps.
No fonts from foreign servers: Outfit and JetBrains Mono are hosted by us.
No processing of your verification data outside the EU, not at our providers either. The only exception is the delivery of the widget file if you enable the global endpoint.
No raw behavioural data on our servers.
No hidden contract terms and no cancellation via phone hotline.
No picture puzzles that lock out people with disabilities.

Where to

What we are working on

The European market is currently looking for alternatives to American services, not out of ideology but because regulators and customers are asking concrete questions. That is the gap we want to fill, with a component small enough to fit in anywhere.

Connecting more systems directly

After WordPress, WoltLab, Symfony and Laravel come WooCommerce, Shopware, Joomla and phpBB. Every platform that has a form should be able to use CaptchaCore without writing code.

Sharpening detection without collecting more

The risk engine learns from attack patterns across websites. What matters is the pattern, not the person, which is why it works with truncated IP addresses and hashes.

Evidence instead of assertion

A public system status, traceable reason codes and a data processing agreement you conclude in your account and file as a PDF. External audit reports are the next step.

Missing an integration, or have a requirement that is not listed here? Write to us. Short paths are the advantage of a small team.

Want to try it yourself?

The live demo shows the check from the user's side, the pricing page the terms for commercial use. For private websites CaptchaCore stays free permanently.