Privacy-first human verification

Block automated abuse.
Keep the web human.

GIWS CAPTCHA protects websites and applications with accessible challenges, adaptive verification, explainable risk scoring, and replay-safe tokens—through one developer-friendly platform.

  • No advertising profiles
  • Accessible verification paths
  • Server-side decisions
Live verification Protected
Request verifiedNo challenge required
Action
sign_up
Decision
allow
Token
one-time

Illustrative response—not live customer data.

Security signals without surveillance.

Minimize collection, keep decisions explainable, and give legitimate visitors a clear path through verification.

  • Privacy-first
  • Accessible
  • Explainable

Use the right level of friction.

Start with the user experience your flow needs. Every version shares the same server-owned security foundation.

Control at every boundary.
Clarity at every decision.

GIWS CAPTCHA binds each verification to the right site, hostname, action, and version. The server remains the source of truth from token issuance to final decision.

Review the security architecture
  1. 01

    Bound by context

    Site, hostname, action, and CAPTCHA version travel together through verification.

  2. 02

    Replay-safe by design

    Tokens are consumed once, with explicit expiry and fail-closed replay protection.

  3. 03

    Policies you can explain

    Versioned risk and decision policies make behavior inspectable and auditable.

  4. 04

    Real operational evidence

    Security events and analytics reflect actual traffic—never fabricated activity.

server.phpPHP
// Verify the token on your server
$response = Http::asForm()
    ->post('https://captcha.giws.us/api/siteverify', [
        'secret'   => config('services.giws.secret'),
        'response' => $request->string('captcha_token'),
    ]);

if ($response->json('success')) {
    // Continue the protected action
}
Server-side verificationSecret stays private

A small client change.
A strong server boundary.

Use familiar web primitives, framework packages, and a documented verification endpoint. Keep secrets on the server and adopt the experience that fits your stack.

  • JavaScript SDKProgressive enhancement for any website
  • React and VueComponents for modern application stacks
  • PHP and LaravelServer verification with typed responses

Protection should not punish people.

Security, privacy, and accessibility are designed as one system—not treated as competing requirements.

Accessible by design

Multiple challenge modes and keyboard-friendly interactions provide practical alternatives.

Privacy as a default

Assess abuse without building advertising identities or cross-site behavioral profiles.

Performance-aware

Low-risk requests take a quiet path, while stronger checks appear only when warranted.

Clear operational control

Versioned policies, key rotation, and real event data keep teams in control.

What teams need to know.

Find implementation details in the documentation or compare the platform capabilities before choosing a version.

Compare all features
Which CAPTCHA version should I use?

Use V1 for an explicit challenge, V2 for adaptive managed verification, or V3 when your server needs an action-aware risk score.

Does GIWS CAPTCHA support accessible verification?

Yes. The platform provides multiple verification paths, including audio and accessible text alternatives where interactive challenges are used.

Where should token verification happen?

Always verify tokens on your server. Keep the secret key private, validate the expected hostname and action, and treat the server response as authoritative.

Stop the bots.
Welcome the humans.

Start with documented, privacy-first human verification and choose the amount of friction each action deserves.