Trust architecture
Bound tokens
Verification tokens are short-lived and bound to site, hostname, action, version, and challenge context.
- Authenticated envelopes
- Clock-skew checks
- Atomic replay claims
SECURITY ARCHITECTURE
GIWS CAPTCHA treats browser input as untrusted, verifies decisions on the server, and keeps customer and platform access explicitly separated.
Trust architecture
Verification tokens are short-lived and bound to site, hostname, action, version, and challenge context.
Trust architecture
Site secrets are displayed once, stored as hashes, rotated with controlled grace periods, and revocable.
Trust architecture
Unavailable replay or rate-limit stores fail closed at public verification boundaries, while analytics remain off the critical path.
START WITH A REAL SITE
Register a hostname and choose the amount of verification friction each action deserves.