Castle
Last verified 2026-08-21 · Reviewed by guptadeepak
Editorial verdict
Castle is a risk and abuse detection layer that sits beside a CIAM, not inside one. It is the right buy when account takeover, fake signups, or multi-accounting are costing real money and your identity provider's built-in protections are either weak or locked behind an enterprise tier. The device fingerprinting and the backtestable rules engine are the two things hardest to replicate in-house. Budget carefully: consumption pricing means the attack you are defending against also generates the invoice, and the product only earns its cost if you instrument more of the journey than the login page.
Last verified by @guptadeepak on 2026-08-21.
At a glance
- Best for
- Consumer platforms fighting credential stuffing and account takeover at scale
- Pricing
- consumption
- Free tier
- Unlimited
- Deployment
- cloud-saas
- SOC 2 Type II
- Yes
- Passkeys
- No
- Self-host
- No
- Open source
- No
Funding & business
- Funding model
- Venture-backed
- Total raised
- Undisclosed
- Latest round
- Series A · $9.2M · 2019
- Years in business
- 11 yrs
- Round led by
- Index Ventures
- Profitable
- Not disclosed
Founded 2015 by Sebastian Wallin and Johan Brissmyr. The company announced a $9.2M Series A led by Index Ventures in January 2019, putting total funding at $11.6M at that point. Later aggregate figures differ across trackers ($13.7M and $18.2M both appear), so no current total is recorded here.
Funding data from primary source. See also the CIAM investor landscape.
Strengths
- Device fingerprinting that survives storage resets and privacy extensions, which is the signal most homegrown risk engines lack.
- Purpose-built scores for the three abuse shapes CIAM teams actually field: account takeover, fake registration, and bot traffic, each 0 to 100 and directly usable in policy.
- Rules engine with backtesting against historical events, so a policy change can be evaluated before it starts blocking real users.
- Behavioural detection rather than challenges, so there is no CAPTCHA tax on legitimate users.
- Broad SDK coverage across server languages plus iOS, Android, React Native, and Flutter, and a Cloudflare edge integration for blocking before origin.
Limitations
- Not a CIAM and not an authentication product. Castle scores events; your identity provider still owns login, MFA, and the user record.
- Consumption pricing means an attack raises your bill. Bot floods are billable request volume until a policy blocks them upstream.
- Published compliance footprint is SOC 2 Type II and GDPR readiness. ISO 27001, HIPAA, PCI DSS, and documented EU data residency are not publicly stated.
- Effectiveness depends on how much of the user journey you instrument. A login-only integration sees a fraction of the signal the product is designed around.
- Device and behavioural telemetry is personal data in most jurisdictions, so it adds a processor to your privacy review rather than reducing scope.
Capability matrix
Every vendor scored on the same axes. See the methodology for criteria.
| Password authentication | No |
|---|---|
| Social login | No |
| Magic links | No |
| SMS OTP | No |
| Email OTP | No |
| TOTP (authenticator app) | No |
| Push MFA | No |
| WebAuthn / passkeys | No |
| Biometric | No |
| Hardware security keys | No |
| SAML SSO | No |
| OIDC SSO | No |
| OAuth 2.0 SSO | No |
| Enterprise federation | No |
| Passwordless-only flows | No |
| Adaptive MFA | Partial |
| Step-up auth | Partial |
| RBAC | No |
|---|---|
| ABAC | No |
| ReBAC | No |
| FGA engine | No |
| API authorization | No |
| Fine-grained permissions | No |
| Self-service registration | No |
|---|---|
| Progressive profiling | No |
| Self-service account | No |
| Bulk user import | No |
| Admin user search | Partial |
| Custom user metadata | Yes |
| Organizations / tenants | No |
| Multi-tenancy | No |
| SCIM provisioning | No |
| REST API | Yes |
|---|---|
| GraphQL API | No |
| SDKs | JavaScript (browser), Node, Ruby, Python, PHP, Java, .NET, iOS, Android, React Native, Flutter |
| CLI | No |
| Terraform provider | No |
| Local emulator | No |
| Extension model | Policy and rules engine with backtesting against historical events, webhooks, Slack notifications, and a Cloudflare edge integration |
| Bot detection | Yes |
|---|---|
| Breached password detection | No |
| Brute-force protection | Yes |
| Anomaly detection | Yes |
| Log streams | Yes |
| Audit logs | Yes |
| GDPR data export | No |
| PII minimization | No |
| Post-quantum roadmap | No |
| MCP support | No |
|---|---|
| OAuth 2.1 | No |
| Dynamic client registration | No |
| Agent vs human token separation | No |
| Web Bot Auth | No |
| SOC 2 Type II | Yes |
|---|---|
| ISO 27001 | No |
| ISO 27018 | No |
| HIPAA | No |
| PCI DSS | No |
| GDPR | Yes |
| CCPA | No |
| FedRAMP | No |
| EU data residency | No |
| Consent management | No |
|---|---|
| Preference center | No |
| Purpose-specific consent | No |
| Integrates with CMPs | n/a |
| Multi-region deployment | Partial |
|---|---|
| Data residency control | No |
| Proven at high scale (1M+ MAU) | Yes |
| Password-hash import | No |
|---|---|
| Lazy / just-in-time migration | No |
| Account linking & dedup | No |
| Custom domains per brand | No |
| Per-brand theming of all flows | No |
| Per-brand consent partitioning | No |
| Deletion webhooks / cascade | No |
| Event streaming / webhooks | Yes |
| Documented rate limits | Partial |
Developer experience & lock-in
Editorial 1–5 scores and migration effort, scored on the same axes for every vendor. See the methodology for how these are graded.
Developer experience
- Community
- Small
Migration & lock-in
Low lock-inEffort to adopt this platform
Effort to leave later (your exit cost)
Higher exit effort means more switching cost. Ask about bulk user export (including password hashes) before you commit.
Enterprise readiness
Gaps remain · 26/100A computed read of how ready this vendor is to sell into the enterprise, derived from the capability matrix. See the enterprise-ready pillars.
- 0
Enterprise SSO
- 0
Directory sync (SCIM)
- 0
Organizations & tenancy
- 0
RBAC & custom roles
- 100
Audit logs & streaming
Audit logs · Log streaming
- 50
Compliance certifications
SOC 2 Type II
- 65
Security posture
Anomaly detection · Brute-force protection · Adaptive / step-up auth (partial)
Scored from our capability review; confirm the exact plan tier and SCIM scope with the vendor before you commit.
Pricing
| 10,000 MAU | Quote required |
|---|---|
| 100,000 MAU | Quote required |
| 500,000 MAU | Quote required |
| 1,000,000 MAU | Quote required |
- Priced on API request volume, not monthly active users, so cost tracks traffic including bot traffic you have not yet blocked
- Every protected surface you instrument (login, registration, checkout, password reset) adds request volume
- Historical event retention for backtesting is part of the plan tier rather than a separate line
Estimates use the standard assumptions in our methodology. Always confirm with the vendor.
Best for
- Consumer platforms fighting credential stuffing and account takeover at scale
- Marketplaces and freemium products losing money to multi-accounting and trial farming
- Teams whose CIAM has weak or enterprise-gated bot and anomaly detection
- Products that want risk signals feeding their own step-up logic rather than a vendor's fixed flow
Not for
- Teams shopping for a CIAM or an authentication platform
- Low-traffic B2B apps where account abuse is not a live problem
- Buyers who need documented data residency or ISO 27001 from the risk vendor
Solves for
Enterprise pain points this vendor covers on the mapped capabilities. See all pain points.
FAQ
- Does Castle replace my identity provider?
- No. Castle never handles credentials, sessions, or the user record. It ingests events from your application (login attempt, registration, transaction), returns risk scores and signals, and optionally fires webhooks. Your CIAM still authenticates the user, and your code decides what a high score should trigger: a step-up challenge, a review queue, or a block.
- How does Castle differ from the bot protection my CIAM already includes?
- Coverage and control. Most CIAM bot defence protects the auth endpoints and exposes limited tuning, often only on higher tiers. Castle is designed to score any event you send it across the whole journey, including registration, checkout, and content posting, and its rules are yours to write and backtest. If your CIAM's built-in protection is adequate for your abuse profile, the honest answer is that you do not need a second vendor.
- What does Castle actually cost?
- Pricing is consumption-based on API requests rather than monthly active users, with a free tier and published plans. There is no meaningful MAU-based estimate to quote, because two products with identical user counts can differ by an order of magnitude in request volume depending on how many surfaces they instrument and how much bot traffic reaches them.
- Is Castle a privacy problem?
- It is a privacy consideration, not automatically a problem. Castle collects device and behavioural telemetry, which is personal data under GDPR, so it enters your processing records and your DPA set as a processor. The company states SOC 2 Type II certification and GDPR readiness. If you need documented EU-only data residency, confirm it directly rather than assuming it.
Sources
- Castle: Stop bots and account abuse at scaleaccessed 2026-08-21
- Castle Documentationaccessed 2026-08-21
- Castle bot detection documentationaccessed 2026-08-21
- Castle raises $9.2 million led by Index Venturesaccessed 2026-08-21
Where to next
What Castle is
Castle is fraud and abuse detection sold as an API. Your application sends it events, it returns risk scores for account takeover, account abuse, and bot activity, and you decide what to do with them. Founded in 2015 in San Francisco, it sits in the same slot as an anti-fraud layer rather than an identity platform, and its published customer list (Atlassian, Canva, Rockstar Games, Rakuten) skews toward consumer-scale products with real abuse economics.
The mental model that matters: Castle is an input to your auth decisions, not the place those decisions live.
Where Castle wins
Device intelligence is the differentiator. Persistent fingerprinting that survives storage clearing and privacy plugins is the piece teams consistently fail to build well in-house, and it is what separates "this is a new device" from "this is the same attacker on a new device."
The rules engine is the second reason to buy. Policies can be backtested against stored historical events before they go live, which turns a risky tuning exercise into a measurable one. Most homegrown risk logic ships blind and gets rolled back after it blocks real customers.
Third, the integration surface is wide: server SDKs across the common languages, mobile and cross-platform SDKs, webhooks, and a Cloudflare edge integration for stopping traffic before it reaches origin.
Where Castle hurts
The pricing model deserves scrutiny. Consumption billing on request volume means a credential-stuffing campaign is both the problem and a cost driver, at least until an upstream policy sheds the traffic. Model this against your worst month, not your average one.
Coverage is proportional to instrumentation. A team that wires up only the login endpoint gets a fraction of the value, because the product is built around seeing the whole journey.
The published compliance set is narrower than an enterprise CIAM's. SOC 2 Type II and GDPR readiness are stated; ISO 27001, HIPAA, PCI DSS, and specific EU data residency commitments are not publicly documented, so regulated buyers should confirm before assuming.
How Castle compares
Castle is a complement to everything else in this index rather than a substitute. The closest overlap is with vendors whose own risk tooling is a headline feature: Transmit Security and Authsignal both cover risk and orchestration territory, and buying Castle alongside either is usually redundant. Against a platform whose bot defence is thin or enterprise-gated, Castle is the standard bolt-on.
For the decision of whether you need a separate risk vendor at all, see bot defence and ITDR: identity threat detection and response. For the step-up logic that consumes these signals, see adaptive and risk-based authentication.
Editorial changelog (1 entry)
Profile added. Capabilities, SDK coverage, compliance claims, and funding history verified against Castle's site, documentation, GitHub organisation, and funding announcement.