Skip to content

Castle

Last verified 2026-08-21 · Reviewed by guptadeepak

b2cb2b-saasenterprisecloud-saasconsumption

Editorial verdict

Castle is a risk and abuse detection layer that sits beside a CIAM, not inside one. It is the right buy when account takeover, fake signups, or multi-accounting are costing real money and your identity provider's built-in protections are either weak or locked behind an enterprise tier. The device fingerprinting and the backtestable rules engine are the two things hardest to replicate in-house. Budget carefully: consumption pricing means the attack you are defending against also generates the invoice, and the product only earns its cost if you instrument more of the journey than the login page.

Last verified by @guptadeepak on 2026-08-21.

At a glance

Best for
Consumer platforms fighting credential stuffing and account takeover at scale
Pricing
consumption
Free tier
Unlimited
Deployment
cloud-saas
SOC 2 Type II
Yes
Passkeys
No
Self-host
No
Open source
No

Funding & business

Funding model
Venture-backed
Total raised
Undisclosed
Latest round
Series A · $9.2M · 2019
Years in business
11 yrs
Round led by
Index Ventures
Profitable
Not disclosed

Founded 2015 by Sebastian Wallin and Johan Brissmyr. The company announced a $9.2M Series A led by Index Ventures in January 2019, putting total funding at $11.6M at that point. Later aggregate figures differ across trackers ($13.7M and $18.2M both appear), so no current total is recorded here.

Funding data from primary source. See also the CIAM investor landscape.

Strengths

  • Device fingerprinting that survives storage resets and privacy extensions, which is the signal most homegrown risk engines lack.
  • Purpose-built scores for the three abuse shapes CIAM teams actually field: account takeover, fake registration, and bot traffic, each 0 to 100 and directly usable in policy.
  • Rules engine with backtesting against historical events, so a policy change can be evaluated before it starts blocking real users.
  • Behavioural detection rather than challenges, so there is no CAPTCHA tax on legitimate users.
  • Broad SDK coverage across server languages plus iOS, Android, React Native, and Flutter, and a Cloudflare edge integration for blocking before origin.

Limitations

  • Not a CIAM and not an authentication product. Castle scores events; your identity provider still owns login, MFA, and the user record.
  • Consumption pricing means an attack raises your bill. Bot floods are billable request volume until a policy blocks them upstream.
  • Published compliance footprint is SOC 2 Type II and GDPR readiness. ISO 27001, HIPAA, PCI DSS, and documented EU data residency are not publicly stated.
  • Effectiveness depends on how much of the user journey you instrument. A login-only integration sees a fraction of the signal the product is designed around.
  • Device and behavioural telemetry is personal data in most jurisdictions, so it adds a processor to your privacy review rather than reducing scope.

Capability matrix

Every vendor scored on the same axes. See the methodology for criteria.

Authentication
Password authentication No
Social login No
Magic links No
SMS OTP No
Email OTP No
TOTP (authenticator app) No
Push MFA No
WebAuthn / passkeys No
Biometric No
Hardware security keys No
SAML SSO No
OIDC SSO No
OAuth 2.0 SSO No
Enterprise federation No
Passwordless-only flows No
Adaptive MFA Partial
Step-up auth Partial
Swipe table horizontally →
Authorization
RBAC No
ABAC No
ReBAC No
FGA engine No
API authorization No
Fine-grained permissions No
Swipe table horizontally →
User management
Self-service registration No
Progressive profiling No
Self-service account No
Bulk user import No
Admin user search Partial
Custom user metadata Yes
Organizations / tenants No
Multi-tenancy No
SCIM provisioning No
Swipe table horizontally →
Developer experience
REST API Yes
GraphQL API No
SDKsJavaScript (browser), Node, Ruby, Python, PHP, Java, .NET, iOS, Android, React Native, Flutter
CLI No
Terraform provider No
Local emulator No
Extension modelPolicy and rules engine with backtesting against historical events, webhooks, Slack notifications, and a Cloudflare edge integration
Swipe table horizontally →
Security
Bot detection Yes
Breached password detection No
Brute-force protection Yes
Anomaly detection Yes
Log streams Yes
Audit logs Yes
GDPR data export No
PII minimization No
Post-quantum roadmap No
Swipe table horizontally →
Agentic identity
MCP support No
OAuth 2.1 No
Dynamic client registration No
Agent vs human token separation No
Web Bot Auth No
Swipe table horizontally →
Compliance
SOC 2 Type II Yes
ISO 27001 No
ISO 27018 No
HIPAA No
PCI DSS No
GDPR Yes
CCPA No
FedRAMP No
EU data residency No
Swipe table horizontally →
Consent & privacy
Consent management No
Preference center No
Purpose-specific consent No
Integrates with CMPsn/a
Swipe table horizontally →
Scalability & regions
Multi-region deployment Partial
Data residency control No
Proven at high scale (1M+ MAU) Yes
Swipe table horizontally →
Enterprise operations
Password-hash import No
Lazy / just-in-time migration No
Account linking & dedup No
Custom domains per brand No
Per-brand theming of all flows No
Per-brand consent partitioning No
Deletion webhooks / cascade No
Event streaming / webhooks Yes
Documented rate limits Partial
Swipe table horizontally →

Developer experience & lock-in

Editorial 1–5 scores and migration effort, scored on the same axes for every vendor. See the methodology for how these are graded.

Developer experience

DX overall4/5
Docs quality4/5
Passkey orchestration1/5
Community
Small

Migration & lock-in

Low lock-in
Migrating inEasy

Effort to adopt this platform

Migrating outEasy

Effort to leave later (your exit cost)

Higher exit effort means more switching cost. Ask about bulk user export (including password hashes) before you commit.

Enterprise readiness

Gaps remain · 26/100

A computed read of how ready this vendor is to sell into the enterprise, derived from the capability matrix. See the enterprise-ready pillars.

  • Enterprise SSO

    0
  • Directory sync (SCIM)

    0
  • Organizations & tenancy

    0
  • RBAC & custom roles

    0
  • Audit logs & streaming

    Audit logs · Log streaming

    100
  • Compliance certifications

    SOC 2 Type II

    50
  • Security posture

    Anomaly detection · Brute-force protection · Adaptive / step-up auth (partial)

    65

Scored from our capability review; confirm the exact plan tier and SCIM scope with the vendor before you commit.

Pricing

Estimated monthly cost (USD)
10,000 MAUQuote required
100,000 MAUQuote required
500,000 MAUQuote required
1,000,000 MAUQuote required
Swipe table horizontally →
  • Priced on API request volume, not monthly active users, so cost tracks traffic including bot traffic you have not yet blocked
  • Every protected surface you instrument (login, registration, checkout, password reset) adds request volume
  • Historical event retention for backtesting is part of the plan tier rather than a separate line

Estimates use the standard assumptions in our methodology. Always confirm with the vendor.

Best for

  • Consumer platforms fighting credential stuffing and account takeover at scale
  • Marketplaces and freemium products losing money to multi-accounting and trial farming
  • Teams whose CIAM has weak or enterprise-gated bot and anomaly detection
  • Products that want risk signals feeding their own step-up logic rather than a vendor's fixed flow

Not for

  • Teams shopping for a CIAM or an authentication platform
  • Low-traffic B2B apps where account abuse is not a live problem
  • Buyers who need documented data residency or ISO 27001 from the risk vendor

Solves for

Enterprise pain points this vendor covers on the mapped capabilities. See all pain points.

FAQ

Does Castle replace my identity provider?
No. Castle never handles credentials, sessions, or the user record. It ingests events from your application (login attempt, registration, transaction), returns risk scores and signals, and optionally fires webhooks. Your CIAM still authenticates the user, and your code decides what a high score should trigger: a step-up challenge, a review queue, or a block.
How does Castle differ from the bot protection my CIAM already includes?
Coverage and control. Most CIAM bot defence protects the auth endpoints and exposes limited tuning, often only on higher tiers. Castle is designed to score any event you send it across the whole journey, including registration, checkout, and content posting, and its rules are yours to write and backtest. If your CIAM's built-in protection is adequate for your abuse profile, the honest answer is that you do not need a second vendor.
What does Castle actually cost?
Pricing is consumption-based on API requests rather than monthly active users, with a free tier and published plans. There is no meaningful MAU-based estimate to quote, because two products with identical user counts can differ by an order of magnitude in request volume depending on how many surfaces they instrument and how much bot traffic reaches them.
Is Castle a privacy problem?
It is a privacy consideration, not automatically a problem. Castle collects device and behavioural telemetry, which is personal data under GDPR, so it enters your processing records and your DPA set as a processor. The company states SOC 2 Type II certification and GDPR readiness. If you need documented EU-only data residency, confirm it directly rather than assuming it.

Sources

Where to next


What Castle is

Castle is fraud and abuse detection sold as an API. Your application sends it events, it returns risk scores for account takeover, account abuse, and bot activity, and you decide what to do with them. Founded in 2015 in San Francisco, it sits in the same slot as an anti-fraud layer rather than an identity platform, and its published customer list (Atlassian, Canva, Rockstar Games, Rakuten) skews toward consumer-scale products with real abuse economics.

The mental model that matters: Castle is an input to your auth decisions, not the place those decisions live.

Where Castle wins

Device intelligence is the differentiator. Persistent fingerprinting that survives storage clearing and privacy plugins is the piece teams consistently fail to build well in-house, and it is what separates "this is a new device" from "this is the same attacker on a new device."

The rules engine is the second reason to buy. Policies can be backtested against stored historical events before they go live, which turns a risky tuning exercise into a measurable one. Most homegrown risk logic ships blind and gets rolled back after it blocks real customers.

Third, the integration surface is wide: server SDKs across the common languages, mobile and cross-platform SDKs, webhooks, and a Cloudflare edge integration for stopping traffic before it reaches origin.

Where Castle hurts

The pricing model deserves scrutiny. Consumption billing on request volume means a credential-stuffing campaign is both the problem and a cost driver, at least until an upstream policy sheds the traffic. Model this against your worst month, not your average one.

Coverage is proportional to instrumentation. A team that wires up only the login endpoint gets a fraction of the value, because the product is built around seeing the whole journey.

The published compliance set is narrower than an enterprise CIAM's. SOC 2 Type II and GDPR readiness are stated; ISO 27001, HIPAA, PCI DSS, and specific EU data residency commitments are not publicly documented, so regulated buyers should confirm before assuming.

How Castle compares

Castle is a complement to everything else in this index rather than a substitute. The closest overlap is with vendors whose own risk tooling is a headline feature: Transmit Security and Authsignal both cover risk and orchestration territory, and buying Castle alongside either is usually redundant. Against a platform whose bot defence is thin or enterprise-gated, Castle is the standard bolt-on.

For the decision of whether you need a separate risk vendor at all, see bot defence and ITDR: identity threat detection and response. For the step-up logic that consumes these signals, see adaptive and risk-based authentication.

Editorial changelog (1 entry)
  1. Profile added. Capabilities, SDK coverage, compliance claims, and funding history verified against Castle's site, documentation, GitHub organisation, and funding announcement.

Last verified by @guptadeepak on 2026-08-21.