product

See which agents visit your site, and control what they can do.

Observe mode explains every request on the proof ladder. When you’re ready, one plain-English policy controls access from your own edge account.

01 · Observe mode

free SDK · ten minutes · nothing blocked
edge — yourdomain.com · observe modenothing blocked · every request explained
TimeAgentPathIdentityReasonAction
15:49:18agentcore-browser · AWS/productprovensignature ✓ · acting for a userpass
15:49:16unknown · /jobs/adz-5799…unknownno identity asserted — could be a personpass
15:49:11“GPTBot” · unknown/blog/reportspoofedclaims GPTBot · outside OpenAI’s rangesflagged
15:49:03bytespider · ByteDance/blogclaimedknown name · nothing checkable publishedyour call
15:48:59claudebot · Anthropic/docs/apiderivedIP range match · declared: trainingyour call
15:48:54googlebot · Google/robots.txtderivedreverse-DNS matchpass
15:48:51chatgpt-user · OpenAI/pricingprovensignature ✓ · answering a userpass
simulated session · illustrative traffic · real tiers, reasons, verdictshover to pause

The proof ladder — what “identity” means here

provenThe operator publishes signing keys and the request carries a valid signature. Identity is a checked fact.
derivedNo signature, but the infrastructure checks out: reverse-DNS and published IP ranges. Solid, one step below proof.
claimedA recognizable name with nothing checkable behind it. Common, and worth knowing about.
unknownNo identity asserted at all. Most human visitors live here, and anonymity passes.
spoofedA claim contradicted by evidence — a famous name arriving from the wrong network. We flag it and show you the evidence.

Install & what leaves the box

Install is npm middleware or an observe-only Cloudflare Worker template. Verification runs locally in your edge. Only aggregates leave your infrastructure, and you can turn those off too. Full security-review answers are on the Trust & deployment page. If you’d rather see the numbers without installing anything, ask for the concierge report.

02 · The policy engine

One policy, written in plain English.

The four purposes

Reading for a customer

an assistant fetching your docs or pricing because its user asked. Block this lane and customers feel it.

rag

Sending you readers

engines that index and cite you. This is your top-of-funnel in AI answers.

search

Buying

agents transacting on a user's behalf — the purpose class other standards leave out.

action

Harvesting

bulk reads that take your content once and pay nothing. Most sites want this lane priced or refused, and a bot that won’t state its purpose gets treated as a training crawler.

training

AIPREF has two words for why a bot fetches; Content Signals has three. We normalize every standard into these four.

Where it runs

In your own edge account

The Worker or middleware installs where your traffic already is, so the policy travels with you instead of being welded to one edge. Prefer to paste rules yourself? There’s a rule-set export.

Additive-only, log-first, fail-open. The full security-review answers are on the Trust & deployment page.

03 · Boundaries

What we don’t do.

Never — by design

Payments

A fetch arriving with payment attached is one more purpose class your policy accounts for. We never settle, meter, or hold money, and we take no cut of deals our numbers help you win.

Bot detection wars

Fingerprinting hostile unsigned traffic is your edge's job, and they're good at it. We classify the provable and hand the rest back.

Becoming a hop

No proxy, no CDN, no traffic through our pipes. A feed and a plugin, in your account, forever.

See & manage your agentic traffic

Setup D3 Edge on your own traffic. Schedule a demo.