SECURITY ARCHITECTURE

Verification is only useful when its boundaries hold.

GIWS CAPTCHA treats browser input as untrusted, verifies decisions on the server, and keeps customer and platform access explicitly separated.

Trust architecture

Bound tokens

Verification tokens are short-lived and bound to site, hostname, action, version, and challenge context.

  • Authenticated envelopes
  • Clock-skew checks
  • Atomic replay claims

Trust architecture

Protected credentials

Site secrets are displayed once, stored as hashes, rotated with controlled grace periods, and revocable.

  • No plaintext secret storage
  • Key rotation
  • Least-privilege access

Trust architecture

Fail-safe controls

Unavailable replay or rate-limit stores fail closed at public verification boundaries, while analytics remain off the critical path.

  • Layered rate limits
  • Server authorization
  • Redacted diagnostics

Build a safer user journey.

Register a hostname and choose the amount of verification friction each action deserves.

Create account