Skip to content

Stop bots, fakes, and free-tier drain. Make bans stick.

Fingerprints, IP checks, and captchas only guesswho's real — so attackers tune right past them, and the signal resets the moment someone clears their cookies. Root Herald has the device prove itself with the security chip in virtually every modern laptop, tied to a stable, anonymous ID. One machine can't fake a crowd, farm your free tier, or shake a ban by starting over.

  • No client keys
  • No CAPTCHA
  • No personal data

How it works

Three steps: your app collects proof, we check it, you get a yes/no.

Your app gathers a fresh proof from the device's security chip; your server sends it to Root Herald (a challenge, then a verify) and gets an answer back. Nothing exotic to trust, and no security code for you to write.

1Device

Collects the proof

The device's security chip signs a fresh proof over a one-time challenge code. Your app just gathers it and hands it to your server. It holds no keys and makes no decision.

device proof
2Root Herald

Checks it

Your server sends that proof to Root Herald to verify. We confirm the chip is genuine, replay the device's boot record, and apply your rule for how strict to be.

answer
3Your backend

Gets the answer

The call returns a plain pass, warn, or fail, plus a stable, anonymous ID for the device. No security-chip code to write on your side.

answer from POST /api/v1/attestations/verify

Start free: 10,000 device checks a month, no card.

Wire up your first check in an afternoon. Upgrade in the dashboard when you outgrow it.

Sign-up is for developers and organizations creating a Root Herald tenant, not for your end-users.