not.bot Verify

AI can fake anyone. not.bot Verify proves your users are real.

not.bot™ Verify separates the real users from the bots and the burner accounts, and can check age thresholds. Users prove they are human once, then can easily re-confirm in every session. More conversions, fewer bots.

Plans from $9.99/mo · self-hosted, open SDK

One response, every time

Ask for proof. Get back a signature.

Whatever you need to know about a person comes back the same way: a signature from that verified human. Proof you can verify, then keep as a record, or publish.

  • A real human

    A passport-verified person, on their own phone, confirming with Face ID, Touch ID, or a passcode the moment you ask.

  • The same human

    A Site Pass: the same person across every alias they use on your site.

  • Age and attributes

    Over 18, over 21, an age range, nationality, name — only the items you ask for, returned only when the user agrees, and never shared with Julia Social.

  • Your content

    Ask a verified human to sign a specific piece of text. They read the exact words, pick the alias to sign with, and consent before anything is signed.

verified human · unique · 18+
message
“Unique human check · acme.com”
alias_did
did:julia:7f3a…c12
site_pass
0xc2a7…6a7
age_over_18
true
signed
2026-07-16
presentation
0x3082…a91f

message is the text the user agreed to. presentation is the one signature that binds it all together — re-checkable by anyone you choose to show.

Keep the signature

Most signatures stay between the user and your server — a private record that this human passed, there if you ever need to show your work.

Publish the signature

Others are made to go public: a signed review, a verified post, a badge a visitor can scan as a QR code and check for themselves. Same signature, on display.

For engineers: every response is a signed W3C verifiable presentation, and the request is also a signed presentation. See the SDK reference

Use cases

Human-only experiences, on top of the site you already run.

You do not gate the whole site. You open specific experiences to verified humans and leave the normal path for everyone else.

A badge that means human.

Members sign in with not.bot and wear a verified-human mark, so the room can see who is real.

Reviews you can trust.

Each rating comes from one unique verified person, so a rating means what it used to.

One account per person.

A Site Pass ties each account to one human, so a single paid login shared across a crowd stops working.

Effective bans.

A removed person cannot walk back in under a fresh account, because you can detect the same human, regardless of alias.

A head start for humans.

Put a news drop or earnings release behind a verified-human window for its first hours, so people read it before bots trade on it.

Honest ad metrics.

Pay for confidence your ads reached real people in the age group you wanted, not a bot farm inflating the count.

Why it matters

The bots are winning, and the usual fixes cost you real users.

53%
of web traffic in 2025 came from bots — more than from people.Web-security bot-traffic report, 2026
8–12¢
buys one fake account past the SMS check that guards most signups.Science, Dec 2025
$40B
projected US fraud losses from generative AI by 2027, up from $12.3B in 2023.Deloitte Center for Financial Services, 2024

A not.bot Verify identity check happens once — so your site collects no documents, stores no identity, and gets back a signature no bot can fake.

How it works

not.bot Verify runs in your infrastructure, not ours.

not.bot Verify is software you host. It installs into your own cloud and sits behind your existing security, so not.bot is never in the path of your traffic and your data never leaves your infrastructure.

  1. Your site shows a tap-to-verify link on a phone, or a QR code on a desktop.

  2. The link opens the not.bot app. It shows your site’s name and what you asked for, and the user approves or declines.

  3. Approval takes a Face ID, Touch ID, or passcode check. Your site gets back a signature for exactly what it asked.

Your cloud. Your users’ data never leaves your infrastructure, which is what regulated buyers need and what shortens a security review. An engineer, or a coding agent, can have it live in about half a day.

Why not.bot Verify

Adds trust without adding risk.

not.bot Verify gives you a stronger signal about who is real, without the liabilities that usually arrive with identity.

One fewer vendor to breach.

not.bot Verify runs entirely in your own infrastructure. No user data reaches not.bot — the only things we receive are two hourly numbers: how many users you verified, and how many verifications succeeded. No user identifiers, no request details — two integers. Adopting it doesn’t hand a new vendor a database to lose on your behalf, and there’s no BAA to negotiate. Your security review gets shorter, not longer.

Credible neutrality.

not.bot can’t see which sites a person verifies on, and your site can’t see who they are anywhere else. No party assembles a profile across the two, and Julia Social holds none of your users’ personal data. You add human verification without taking on a tracking problem of your own.

Built for people to actually use.

A user confirms in an app they control, sees exactly what you asked for, and agrees before anything is shared — no document, no selfie, no biometric scan. The only check is the Face ID or passcode already on their phone, which not.bot never sees. A check people will finish is the only kind that protects anything. Why it’s safe →

Built by Julia Social

Inspect it before you trust it.

not.bot Verify is built to be read, not taken on faith. The protocol code is open, the foundations are independently certified, and the hardest cryptography was built with people who do this for a living.

Open-source SDK.

The SDK your team integrates is open source — your engineers read every line before it ships. View the SDK →

Published, not promised.

The Chialisp that implements not.bot is public, and the architecture and security model are documented in full — not described, shown.

Certified foundations.

The identity proofing and record escrow behind a not.bot human run through independently certified providers — ISO 27001, eIDAS, SOC 2.

Multiparty computation, with Galois.

The cryptography that checks age and attributes without revealing them was co-developed with Galois, Inc., a specialist in high-assurance software.

No token, no NFTs.

No wallet, no token, no NFTs, all fees in USD. The cryptography is plumbing you and your users never touch.

No forced enrollment.

You open human-only features to the people who want them. Everyone else uses your site the way they do today.

Special launch pricing

Pick a plan. Pay for the humans you verify.

Every plan is the exact same self-hosted software and open SDK — the plan sets price and support. A MAU is one unique not.bot alias that interacts with your deployment during the month. These are introductory launch rates.

Start here

Sandbox

$9.99/month

Coming soon

Stand it up and get a feel for not.bot Verify before a full deployment.

  • 10 MAUs included
  • $0.99 per additional MAU
  • Community support (Discord)

Advanced

$1,999/month

Coming soon

For high volume, where the lowest per-MAU rate pays off — every MAU metered at the same low rate.

  • 0 MAUs included
  • $0.20 per MAU
  • Priority support (email, priority response)

Enterprise

Let’s talk

Book a call · soon

Custom terms, scale, and a dedicated contact.

  • Volume pricing
  • Dedicated support
  • Deployment and procurement support

Monthly billing · cancel anytime · change plans anytime.

Checkout opens at our terms page, then Stripe; you’ll be returned here. You pay your plan price plus any MAUs above what it includes, at your plan’s rate — never for the servers or blockchain nodes you run, only the humans you verify.

Before you subscribe

FAQ

What counts as a MAU, and could my bill spike?

A MAU is one unique not.bot alias that interacts with your deployment in a calendar month, counted the same way whether or not you use Site Passes. You pay your plan price plus any MAUs above what the plan includes, at your plan’s per-MAU rate. There are no hidden multipliers.

What do I need to deploy it, and how long does it take?

You host it in your own Kubernetes cluster, with PostgreSQL 14+ and Keycloak 22+. An operator comfortable with Kubernetes, or a coding agent following our checklists, can have it running in about half a day, plus a one-time blockchain sync that can finish overnight.

Do my users need a passport, and is that a barrier?

Enrolling in not.bot takes a U.S. passport today; passport coverage is expanding and in-person enrollment locations are planned. Anyone already enrolled can verify from anywhere, on any site. You don’t need everyone enrolled to start: because you open specific human-only experiences rather than gating your whole site, the verified humans you have add value now, and your reachable audience grows as enrollment widens.

What happens if not.bot’s servers go down?

Your verifications keep working. not.bot Verify runs in your own infrastructure and stays out of your traffic path; a running deployment does not depend on not.bot for day-to-day operation.

Is the Sandbox for production?

It can be — every plan runs the exact same software. Sandbox is simply where most teams stand it up and get comfortable before a full rollout, and its per-MAU rate suits small or early traffic. Once you have real volume, Basic and up cost less per MAU, and you change plans anytime on the same deployment.

Can I cancel anytime?

Yes. Billing is monthly, and you can cancel at any time.

Real users in. Bots out.

Start with Sandbox to evaluate, or talk to us about Enterprise.

See plans

not.bot Verify · plans from $9.99/mo

See plans