Protect your data from scraping, sharing, and abuse.

Detect shared accounts, resale operations, scrapers and AI agents pulling your dataset, and free plans farmed by the same person, without bothering paying users.

CrexiHouzz ProManatalVyondAgorapulseSmartScoutBreaking Into Wall Streetiwd.ioSketchyTettraDesignfilesPrep101Cheddar UpNorth DataStealthWriterPharmAchieve
CrexiHouzz ProManatalVyondAgorapulseSmartScoutBreaking Into Wall Streetiwd.ioSketchyTettraDesignfilesPrep101Cheddar UpNorth DataStealthWriterPharmAchieve

Data platforms protecting their business with Rupt.

One enterprise seat turned out to be 41 people, 227 IP addresses and a resale operation. Crexi found sharing across its paid seats within days.

Trust booster #004

One enterprise seat, 41 people, scraped and resold

227

IP addresses on one login

Read the story Data platform

How Crexi stopped sharing without the friction it feared

“They saw it as a feature, not friction.”

Read the story Data & Marketplaces

How Agorapulse uncovered $1M+ in ARR lost to account sharing

$1M+

ARR found in shared seats

Read the story SaaS
Trust booster #001

One device opened 400 accounts in 30 days

400

Accounts from one fingerprint

Read the story SaaS platform

Coverage

One platform, full fraud engine, with an AI to keep your platform safe.

Sharing, scraping, free plan farming, takeover and more, all handled for you, end-to-end. Set policies and let our agents monitor and keep your platform safe.

Seat sharing

Detect account sharing and convert it into revenue.

  • Detect shared seats, and how many people share them.
  • Detect group buy operations and resale attempts.
  • Gently nudge sharers without disrupting legitimate users.
  • Grow revenue by turning sharers into happy, paying users.

Crexi uncovered thousands of product abuse instances within days and converted shared accounts into paid seats.

Read the Crexi story
More on account sharing
Accounts /ana@acme.com
Live

Sessions

MacBook ProChrome 141Berlin, DE
iPhone 15 ProSafari 18Berlin, DE
Windows 11Chrome 141Likely used by a separate personSão Paulo, BR
Galaxy Tab S9Chrome 141Likely used by a separate personManila, PH

Signals

Impossible travel
Concurrency
Device limit
Then Challenge and cap devices
People detected
3 people
Devices
4 devices
Confidence
97% confidence

Anti scraping

Stop scrapers that already have a login.

  • Classify every request as human, declared agent or undeclared automation.
  • Catch headless Chrome, automation frameworks and AI agents behind a valid login.
  • No captcha in front of your subscribers.

One enterprise seat was shared with 41 people across 227 IPs, then scraped headlessly and resold. Sharing was the signal that uncovered the scraping.

Read the breakdown
More on bot detection
Traffic /GET /api/export
Live

Request teardown

Browser engineChrome 141, headless
Automation driverPlaywright
Network originDatacenter range
Canvas and WebGLSpoofed
Input timingNo human variance
Session historyFirst contact
Then Automated

Automation seen today

GPTBotAI crawlerDeclared
GooglebotSearch crawlerDeclared
Uptime monitorHealth checkDeclared
Headless ChromeScraperUndeclared
Selenium gridCredential stuffingUndeclared

Detection catalog

AddedAgent signature, new assistant2h ago
UpdatedHeadless markers, Chrome 1411d ago
AddedResidential proxy ranges2d ago
UpdatedCanvas spoofing technique4d ago
AddedAutomation framework build6d ago
surfaces checked
40+ surfaces checked
to classify
<20ms to classify
confidence
99% confidence

Free plan farming

Catch multiple signups by the same person.

  • Link signups by device, not by cookie, email or card.
  • Survives cleared cookies, new emails and incognito.
  • Cut off repeat free plans without questioning first-time signups.

One actor opened about 400 accounts in 30 days. Every one shared a device.

Read the breakdown
More on multi-accounting
Signups /k.rivera@proton.me
Live

This signup

Emailk.rivera@proton.me
Password and card hashesNever seen before
Browser profileNew, private window
IP addressVPN, new country
Device signatureSeen 2 times before

Same device

j.reyes@gmail.comTrial ended Mar 2
jreyes.dev@outlook.comTrial ended Mar 16
k.rivera@proton.meSigning up now

Reset on every attempt

Email aliasNew address
Password and card hashesNo match
IP addressNew country
Cookies and storageCleared

Same on every attempt

Canvas and WebGL8 of 8 match
System fonts and screen14 of 14 match
CPU and hardware profile6 of 6 match
Math and CSS behavior11 of 11 match

Verify this phone number

Confirm a phone number to finish creating your account.

+1 415 555 0182 On 2 accounts

Challenges today

k.rivera@proton.meNumber already on 2 accounts
t.okafor@gmail.comVerified a new number
sam.q+9@mail.coLeft without verifying
d.lang@northwind.coVerified a new number
accounts linked
3 accounts linked
free trial
3rd free trial
confidence
99% confidence

Account takeover

Keep stolen credentials out of high-value seats.

  • Learn the devices and networks each seat really signs in from.
  • Challenge unknown logins with a hosted email or SMS check.
  • Deny credential stuffing before a code is ever sent.

A correct password on a device the seat has never used, from a network it has never touched, is the signature of a takeover. Rupt reads all three.

Read the guide
More on account takeover
Logins /user_8fa2
Live

Trusted for this account

MacBook Pro, ChromeSeattle · 41 logins
iPhone 15, SafariSeattle · 12 logins
24.18.44.x, ComcastSeattle · Home network
172.58.x.x, T-MobileSeattle · Mobile network

Just now

Windows, Chrome 141Frankfurt · VPN

New device, new network, impossible travel

Then Challenge

Challenge, run by Rupt

Owner asked to verifyEmail and SMS
Ownership provenNever completed
Automation on the formPlaywright
Attempts from this device47 in 6 min
Accounts it tried12
Real ownerNever interrupted
Then Denied

Your policy

Whenlogin

impossible_travel is true

oris_new_fingerprint and is_new_ip

orip_is_vpn is true

Thenchallenge via email, sms

Signals it can draw on

Device intelligenceIP intelligenceBehaviorEmailAccount history
trusted devices
2 trusted devices
trusted networks
2 trusted networks
login flagged
1 login flagged

Integration

Ridiculously simple to integrate.

Install the SDK and call a function on the action you want protected, or call the API from your server. Everything after that is configurable via AI or the policy editor, with no release from you.

1import Rupt from "@ruptjs/client";
2
3const rupt = new Rupt({
4  clientId: "your_client_id",
5  on_logout: () => signOut(),
6});
7
8await rupt.evaluate.access({
9  user: user.id,
10  email: user.email,
11  phone: user.phone,
12});
ReactNext.jsVueNuxtiOSAndroid Read the quick start

Revenue impact

How much is abuse costing your data platform?

Move the sliders to your own numbers. Shared seats, scrapers behind a login and farmed free plans each turn into paid seats or API plans once Rupt catches them.

10,000
$99

Seat sharing

15%

Extra people per seat

Conversion when nudged

Scraping

5%
$499

Scrapers who move to an API plan

Free plan farming

2,000
15%

Free to paid conversion

Added ARR*

+$1,742,820

~$145,235 / month

Seat sharing
+$118,800/ month
Scrapers moved to API plans
+$24,950/ month
Repeat free plans
+$1,485/ month
Converted users
1,265+
ARR uplift
+13%

*Estimated from your inputs. The defaults are customer averages. Send us yours and we will work out a custom estimate.

Book a demo

Get this report by email

We will send you this estimate with the numbers you set.

Questions data platforms ask before turning Rupt on:

Find out how many people are really on each seat.

Rupt measures from the first session. Crexi had a full diagnosis within a couple of days of installing, long before it challenged or capped a single login.