
Device, Email, IP and Behavioral Intelligence to Stop Bots and Account Abuse
Operating as a developer-facing trust layer, Castle sells infrastructure that stops bots, fake accounts, multi-accounting and account takeover for consumer platforms, marketplaces, gaming studios and SaaS products. The company took seed funding from Y Combinator's W16 batch and First Round Capital, followed by a Series A led by Index Ventures, and today describes itself as profitable and product-led. Named customers on its site include Atlassian, Rockstar Games, Rakuten, Canva, Framer, Sinch, GoTo and DailyPay.
Detection runs through a single API rather than a stack of point tools. A client SDK collects a device fingerprint the vendor claims is 99.5% accurate, and each login, registration, password reset or transaction is posted to the risk endpoint, which returns enriched device, IP, email and user context alongside separate bot, account-abuse and account-takeover scores. Teams layer their own velocity checks, rate limiters and custom metrics on top, and a rules engine resolves every event to allow, challenge or deny.
What distinguishes the approach is that verdicts feed state rather than ending at a score: rules write users, devices and IPs into trust, block and review lists that later evaluations read back, and can fire webhooks or Slack alerts into downstream workflows. Analysts get up to 18 months of enriched history for pattern exploration, network analysis and rule backtesting before changes reach production. The platform advertises roughly 100ms responses across billions of monthly requests, SOC 2 Type II certification and GDPR readiness.



