CAPTCHA V1
Classic challenges, made accessible.
Offer image, text, audio, and puzzle challenges with accessible alternatives and one-time verification.
Explore V1Privacy-first human verification
GIWS CAPTCHA protects websites and applications with accessible challenges, adaptive verification, explainable risk scoring, and replay-safe tokens—through one developer-friendly platform.
Illustrative response—not live customer data.
DESIGNED AROUND TRUST
Minimize collection, keep decisions explainable, and give legitimate visitors a clear path through verification.
ONE PLATFORM · THREE EXPERIENCES
Start with the user experience your flow needs. Every version shares the same server-owned security foundation.
CAPTCHA V1
Offer image, text, audio, and puzzle challenges with accessible alternatives and one-time verification.
Explore V1CAPTCHA V2
Use a lightweight checkbox or invisible flow that escalates to proof of work or a challenge based on risk.
Explore V2CAPTCHA V3
Make action-aware server decisions using an explainable score from 0.00 to 1.00 and configurable thresholds.
Explore V3BUILT FOR SECURITY TEAMS AND DEVELOPERS
GIWS CAPTCHA binds each verification to the right site, hostname, action, and version. The server remains the source of truth from token issuance to final decision.
Review the security architectureSite, hostname, action, and CAPTCHA version travel together through verification.
Tokens are consumed once, with explicit expiry and fail-closed replay protection.
Versioned risk and decision policies make behavior inspectable and auditable.
Security events and analytics reflect actual traffic—never fabricated activity.
// Verify the token on your server
$response = Http::asForm()
->post('https://captcha.giws.us/api/siteverify', [
'secret' => config('services.giws.secret'),
'response' => $request->string('captcha_token'),
]);
if ($response->json('success')) {
// Continue the protected action
}
DEVELOPER-FIRST INTEGRATION
Use familiar web primitives, framework packages, and a documented verification endpoint. Keep secrets on the server and adopt the experience that fits your stack.
A BETTER VERIFICATION EXPERIENCE
Security, privacy, and accessibility are designed as one system—not treated as competing requirements.
Multiple challenge modes and keyboard-friendly interactions provide practical alternatives.
Assess abuse without building advertising identities or cross-site behavioral profiles.
Low-risk requests take a quiet path, while stronger checks appear only when warranted.
Versioned policies, key rotation, and real event data keep teams in control.
COMMON QUESTIONS
Find implementation details in the documentation or compare the platform capabilities before choosing a version.
Compare all featuresUse V1 for an explicit challenge, V2 for adaptive managed verification, or V3 when your server needs an action-aware risk score.
Yes. The platform provides multiple verification paths, including audio and accessible text alternatives where interactive challenges are used.
Always verify tokens on your server. Keep the secret key private, validate the expected hostname and action, and treat the server response as authoritative.
BUILD A SAFER USER JOURNEY
Start with documented, privacy-first human verification and choose the amount of friction each action deserves.