How it works Coverage Compare Pricing FAQ Book a call →
Self-hosted anti-bot solvers

No more
anti-bot blocks.

Solvers for the hardest challenges, delivered as Docker images you run on your own hosts. Cloudflare, F5, and MercadoLibre Anubis ship today, with DataDome in migration. They keep working after the vendor's next update, because an autonomous patch loop rebuilds them without you filing a ticket.

Flat monthly fee. No solving service in the request path.

Docker images only. There's no managed endpoint to call.

Built by a team that has run collection and anti-bot infrastructure in production for Fortune 500 retailers and large marketplaces.

unblocker · proxy :8080 SOLVING
0 requests this session sample output
✓ no solving service in the path

Shipping today

CloudflareF5 (Shape)MercadoLibre Anubis

DataDome is in migration. Kasada and Akamai Bot Manager are on the roadmap.

What it does

No browsers. No human solvers.
No third party in the path.

The container is an HTTP and HTTPS forward proxy. You point your existing client at it, it runs the whole challenge lifecycle for you, and it returns the real response from the target. There is no token to fetch and no payload for you to attach yourself.

No browser in the loop

We solve at the payload level. No Playwright instance to spin up, and no CPU or RAM burned rendering a page per challenge.

payload-level solving

Runs in your infra

A Docker image on your own hosts, with no third-party API call in the request path. That removes the hardest question a security review asks, which is where your traffic goes.

your hosts, your registry

Flat fee, unlimited solves

No per-request, per-solve, or per-GB billing at any volume. One number per provider, whatever your traffic does next month.

volume-independent

Coverage, stated straight

Cloudflare, F5, and MercadoLibre Anubis solve today. DataDome is in migration, Kasada and Akamai are on the roadmap. You subscribe only to what you hit, and we will not bill you for a provider we have not shipped.

three shipping today

Where HTTPS stands today

Because the container is a forward proxy, it terminates TLS to run the challenge, which means the client that uses it has to trust the proxy's CA. Today that CA is an embedded prototype one, and the documented client still passes curl -k. That is fine on a bench and it is not fine in your production trust store.

Per-customer CA issuance and proper certificate verification are being built now. Until they ship, treat this as the open item to raise with your security team rather than something we have already solved, and talk to us about how you want the CA handled in your environment.

Coverage

What solves today, and what does not yet.

One image ships, carrying a unit per provider on a shared web platform model. Three units solve now. The rest are in migration or on the roadmap, and they are listed here as exactly that rather than quietly implied.

Cloudflare

unit · shipping today

F5 (Shape)

unit · shipping today

MercadoLibre Anubis

unit · shipping today

DataDome

unit · in migration, next up

Kasada

on the roadmap

Akamai Bot Manager

on the roadmap

Need one that is not here?

tell us which →

These are units inside one image, not six separate images. They share a web platform model, so a change to that model can move more than one provider at once, and you pin and roll the image as a whole. A provider marked on the roadmap does not solve today and we will not sell it to you as if it did.

Compare

Against the two things
you're probably doing today.

Most teams reach for a hosted unblocking API or a fleet of headless browsers. Both work, and both charge you in a currency you didn't expect.

  Fuzzy Unblocker Hosted unblocking API Headless browser farm
Where your traffic goes Stays inside your perimeter Requests, cookies, and tokens transit a third party Stays with you, if you host the fleet
Where the solving happens In your container. No solving service to reach In their cloud. Your requests go to them first In your fleet, but a full browser does the work
How you're billed Flat monthly fee per provider Per request, per solve, or per GB Per CPU-hour, and challenges are expensive
Cost when traffic doubles Unchanged Roughly doubles Roughly doubles, plus fleet headroom
Work per request Solved at the payload level, no page render Whatever their fleet does, behind a queue you don't control A browser boots and renders the page every time
When the vendor ships a change Autonomous loop patches and publishes You wait for their team, behind their other customers Yours to reverse-engineer, from scratch
What a security review looks at One image you can scan and pin, plus the proxy CA A vendor questionnaire and a data-processing agreement Your own fleet, plus every browser CVE in it
Shared-tenancy blast radius None. You're the only tenant Rate limits and outages you didn't cause None, but the fleet is yours to keep alive

// Characterizes the delivery models, not any single named vendor. Ask for the specific comparison against whatever you're running now. We'll tell you where we lose, too.

Pricing

Priced per provider,
not per request.

One flat monthly fee for each provider you subscribe to. Your invoice doesn't move when your traffic does.

Self-hosted Unblocker
Flat monthly per provider you subscribe to
Get a quote →
  • Unlimited solvesNo per-request, per-solve, or per-GB billing at any volume. Your traffic can move without your invoice moving.
  • Pick only what you needSubscribe to the providers that are actually blocking you. You pay for what you hit, and only for what has shipped.
  • Patched builds includedEvery validated rebuild lands in your private registry for as long as the subscription runs, including work on units you do not subscribe to, since they ride in the same image.
  • Runs on your infrastructureCompute is yours, so scaling the solver is a decision you make in your own cluster, not a line item with us.

// We quote against the providers you need rather than publishing a number that would be wrong for most teams. A call is 20 minutes.

Built for authorized use

This is infrastructure for teams that already have a right to the traffic they're sending: your own properties, your own staging and load tests, systems you have written permission to reach, and data collection you've taken legal advice on.

We won't pretend that removes the question. Authorization is yours to establish and yours to hold, and the terms you agree with us say so. We'd rather say that plainly than sell you cover we can't give.

Questions

The ones every team
asks us first.

How do you update a solver when a vendor breaks it?

Our tooling auto-discovers the change against the live challenge and patches the solver, then pushes a new image to your registry. You pull it. No work on your side, and no waiting for a human to reverse-engineer it from scratch.

Because the solvers target the challenge VM rather than individual scripts, most vendor changes never trigger this path at all.

How do we integrate it?

Run the image, then set it as the HTTP and HTTPS proxy for whatever already makes your requests. That is usually one environment variable or one client option. Your request goes out through the proxy, the challenge is handled in the container, and you get the target's real response back.

No SDK to adopt, no framework to move to, and no token plumbing on your side. For HTTPS the proxy terminates TLS, so you install its CA in the client that uses it.

Do you depend on any external solving vendors?

No. There's no CAPTCHA farm, no human-solver marketplace, and no upstream solving API behind us. The challenge runs in our own sandbox, and that sandbox is what ships in the image.

Can we run it with outbound internet disabled?

No, and we would rather correct that here than on your first call. The container needs a route out: it fetches the provider's current challenge programs, submits challenge requests, and makes the final request to your target. Fully air-gapped is not a mode this supports.

What is true is narrower and still the point: none of that traffic goes to us, or to any other solving service. The egress it needs is to your targets and their providers, over your own network or your own upstream proxy, under your rules. There is no call to a Fuzzy Data endpoint anywhere in the request path, so there is nothing of yours for us to see, log, or hand over.

Do you see our traffic?

No. Not as a policy, as an architecture. Your requests never reach a system we operate, so there's nothing for us to log, retain, or be compelled to hand over. That's the entire reason this is a container rather than an API.

What does it need to run?

A host that can run a Docker image and a port your own services can reach. No GPU, no browser, and no persistent datastore in the request path. It is one container carrying every unit, so you size and scale that one image rather than a container per provider.

Can we run it alongside our current setup?

Yes, and that's the sane way to start. Point a slice of traffic at the container, compare success rate and latency against whatever you're paying for now, and move the rest when the numbers say so. Nothing about the integration is exclusive.

Which providers are supported?

Solving today: Cloudflare, F5 (Shape), and MercadoLibre Anubis. DataDome is in migration and is next up. Kasada and Akamai Bot Manager are on the roadmap and do not solve yet, so we will not sell you either one today. If you need a provider that is not on that list, tell us which and we'll tell you honestly whether and when we can ship it.

What does it cost?

A flat monthly fee per provider, with unlimited solves. We quote against the providers you need rather than publishing a headline number that would be wrong for most teams, so the answer takes a 20-minute call.

Engineered in London built & operated in the UK Your data stays yours we never receive your traffic System status live system status
Stop losing requests to a wall

See it running in your stack.

20 minutes with the engineers who build it. Bring the provider that's blocking you.