The short answer
Castle tells your app a signup looks risky. DataCops makes sure your ads never learn from it, and keeps the ad click on the real ones.
DataCops is a tool for the ad side of signup fraud: it gives every visit a bot verdict, checks each signup email, keeps flagged signups from reaching your ad platforms, sends the real sale back to the click, and lets you warm up new campaigns with your existing customers.
How DataCops does it:
- Real people only. Every visit gets a bot verdict against 360+ billion IPs and 350+ monitoring points, with a Real people only switch per ad platform, off by default. Every form email is checked for disposable providers, domains with no mail server and an email risk score.
- The sale after the form. HighLevel natively (lead, booked, showed, won with value, paid), any CRM by webhook, Shopify through the DataCops Shopify app, all matched to the click by click ID or hashed email and phone, and sent to Meta, Google Ads, TikTok and LinkedIn.
- Ads Warmup. Upload your existing customers (up to 20,000 rows), see a 0 to 10 match score per person, and send them to Meta, Google Ads and TikTok so new campaigns start warm.
- First-party collection, no extra tool. One script and one DNS record put collection on your own subdomain; with your DNS on Cloudflare, the free Worker reads the click at the edge before the page loads. Click IDs are kept on the server for up to 90 days.
- Consent, memory and proof. A TCF 2.2 consent banner from your domain with Google Consent Mode v2 on by default, a server-set cookie up to 400 days where enabled, and a delivery log row for every send, counted once against the pixel.
Best for: ad-funded SaaS and lead gen teams, agencies, and anyone whose signups come from paid campaigns and whose fakes are polluting the ads.
The alternatives at a glance:
- DataCops: best for teams whose ad data is being wrecked by fake signups. SignupCops holds risky signups back from the ad platforms and keeps the ad click through Sign in with Google.
- Rupt: best like-for-like swap for account sharing and takeover.
- Fingerprint: best for a raw device ID you build your own rules on.
- SEON: best for a full fraud and AML suite.
- Cloudflare Turnstile: best for a free bot check on a form.
Most people look for a Castle alternative because of the price jump.
The bigger one is where the score goes. Castle is a security tool. It answers "is this signup risky?" and stops. Whether that fake signup still reaches Meta as a conversion, and teaches Meta to find more like it, is not its job. For anyone paying for ads, that is the job that costs money.
A score is not a fix
Here is how a signup fraud API works. A visitor signs up. Your backend calls the API. The API returns a number. Then you decide what to do with it, in your own code, for every place that number matters.
Blocking the account is one place. Your ad data is another, and most teams forget it. The pixel already fired on the thank-you page. Meta already counted the signup. The score came back risky, and the conversion went out anyway.
So you paid per call to learn a signup was fake, and your ads still learned from it. Next week Meta finds you more of the same people.
That is the category gap. A fraud API is built for one moment: the check. It is priced per check, and its job ends when the score comes back. Your ad account lives after that moment, in the tracking, and no fraud API touches it.
DataCops starts from the other end. It is the tracking, so the fraud decision sits inside the send. A risky signup is held back before any ad platform hears about it. A real signup keeps its ad click, even through Sign in with Google. With Real people only on, the ads learn from real users.
A fraud API
- Scores the signup, per call.
- Returns the number to your backend.
- Stops there.
SignupCops
- Checks every visit for bots, datacenter traffic, VPNs and proxies.
- Holds risky signups back from the ad platforms.
- Keeps the ad click through Sign in with Google, so real signups are credited.
Castle protects your app. Nobody is protecting your ad account.
The real difference: what your ads learn
Here is what that means in practice, one job at a time.
Risky signups never reach the ads
Castle gives Bot, Abuse and ATO scores and lets you write policies and webhooks on them. That is strong, and it lives in your backend. Keeping a risky signup out of Meta is a separate thing you build.
DataCops puts a verdict on every visit: bot, datacenter, VPN or proxy. Switch on Real people only for a platform and flagged visits never reach it. With it on, about 99% of bots are kept out. It is off by default, so you choose where it applies. SignupCops holds risky signups back the same way.
The ad click survives Sign in with Google
When someone clicks your ad and signs up with Google, they leave your site and come back. The click ID often gets lost on the way. The signup is real, but no ad gets the credit.
Castle scores that signup. We found nothing on its site that links it to the ad click. SignupCops keeps the click through the Google sign-in, so the real signup is credited to the ad that brought it.
Tracking is included, not bolted on
Castle is not a tracking tool, so you still need one. DataCops is the tracking solution for ad-funded businesses: it keeps bots out of what your ads learn from and sends the sale that happens after the form to Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X. One script and one DNS record, server-side and first-party from your own subdomain. Conversions go to Meta, Google Ads, TikTok and LinkedIn. Every ad click is in the click log in first-party analytics.
Longer memory
Castle keeps data 3 days on Free and 7 on Pro. That is fine for a login check. It is too short for a signup that pays three weeks later. DataCops keeps click IDs 90 days and remembers the visitor up to 400 days. In the EU that cookie still needs consent.
Consent is built in
We found no consent manager on Castle's site. It is not that kind of tool. DataCops includes a first-party consent manager built to the IAB TCF v2.2 standard. Google Consent Mode v2 is on by default, the banner shows in Europe by default, and the server checks consent again before every send.
You can see why each event was sent
DataCops writes every conversion as a row per platform, sent, held, skipped or failed, with the reason next to it. When a signup was held back, you see that it was and why. Each event carries one event ID, so a signup seen by the browser and the server is counted once.
On the Organization plan, two more tools work on paid clicks. Cloudflare edge blocking stops flagged traffic before it loads your page, and Google refund evidence exports the last 60 days of invalid clicks as a CSV for Google's Click Quality Form. Google decides the refund.
Privacy and deletion are built in
Visitors can ask for deletion through a form on your privacy page. They confirm by email, their session is anonymised, and a status page shows what was done. Deletion requests from Meta, TikTok and LinkedIn are handled automatically. Google Ads deletions are a manual step. Click IDs, sessions and the click log are deleted after 90 days, and the identity store holds hashed email and phone only. Castle's site lists no self-serve deletion form. We did not check its docs.
Castle asks "is this user risky?" DataCops asks "should my ads learn from this user?"
The real cost of a cheap tool
Answer these with your own numbers.
How many hours will it take to build your Castle integration, signup policies and the code that keeps risky signups out of your ad data before the first sale is tracked?
How many hours a month will someone spend keeping it working when Meta, Google or TikTok change something?
If a tag breaks quietly for a week, how many leads never reach your ads? And what is one lead worth to you?
How many sales a month close in your CRM that your ads never hear about?
The last question matters most. When fake signups reach your ads, the ads learn to find more fake signups. Cost per signup looks fine. Cost per paying customer climbs. Nothing in Castle's dashboard tells you why.
A fake signup costs you twice: once for the click, and again when your ads go looking for more.
Every feature, side by side
| Fraud and risk | ||
|---|---|---|
| Bots on signups | Verdict per visit, SignupCops holds risky signups back from ads | Bot and Abuse scores to your backend |
| Identity | First-party cookie from your subdomain, up to 400 days | Web and mobile device identification |
| Ads and tracking | ||
| Send to ad platforms | Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest, X | Not built in |
| Real people only per platform | Yes, off by default | Not built in |
| Ad click through Sign in with Google | SignupCops keeps it | Not built in |
| Server-side tracking | First-party from your subdomain | Not built in |
| Click log | In first-party analytics | Not built in |
| Beyond the signup | ||
| CRM stages to ads | HighLevel native, any CRM by webhook | Not built in |
| Upload past customers | Ads Warmup, up to 20,000 rows | Not built in |
| Meta health restrictions | Health mode | Not built in |
| Privacy and data | ||
| Consent manager | Built in, IAB TCF v2.2 | Not built in |
| Visitor deletion requests | Self-serve form, confirmed by email, status page | None listed on its site |
| How long data is kept | Click IDs 90 days, visitor up to 400 days | 3 days Free, 7 days Pro, up to 18 months on Enterprise |
| Running it | ||
| Why each event was sent or held | Per-row delivery log with the reason | Not built in for ad sends |
| Agencies with many clients | Agency board | Not built in |
Different units. A DataCops session is one visit, like Google Analytics. Castle counts API calls. Castle column checked on castle.io/pricing, 2 October 2026. "Not built in" means we found no Castle feature for it on its pricing and feature pages.
The 5 Castle alternatives compared
| Best for | Login risk | Sends to ads | |
|---|---|---|---|
| Clean ad data from signups | No | Yes, 8 platforms | |
Rupt | Account sharing and takeover | Yes | Not stated |
Fingerprint | Raw device ID | You build it | Not stated |
SEON | Fraud and AML suite | Yes | Not stated |
Turnstile | Free form bot check | No | No |
1. DataCops: best if fake signups wreck your ads
DataCops is the tracking, with fraud built into the send. Every visit gets a verdict. Risky signups are held back from the ad platforms. Real signups keep their ad click, even through Sign in with Google. And the moments that pay, from trial to paid, go back to the ads by webhook.
Why people switch to it
- Fake signups never teach the ads
- Ad click kept through Google sign-in
- Tracking, consent and deletion included
- Lower entry price than Castle Pro
Worth knowing
- Real people only is off until you switch it on
- Edge blocking and refund evidence are on Organization
Best for: teams whose fake signups damage their ad account.

2. Rupt: best for account sharing and takeover
Rupt is the closest swap for Castle. About the same price, the same per-evaluation overage, and the same focus: account sharing, takeover, fake accounts and bots. Premium adds SMS and email challenges and keeps data 30 days, longer than Castle Pro's 7.
Enterprise is custom, with up to 18 months retention. Like Castle, we found no ad platform sends on its site.
Why people switch to it
- Same job, similar price
- 30-day retention on Premium
- Built-in challenges
Worth knowing
- Still a developer integration
- Ad data is still your job
Best for: keeping Castle's job with longer retention at the same price.

3. Fingerprint: best for a raw device ID
Fingerprint gives you a stable device ID and Smart Signals for web, Android and iOS. It does not make decisions. You build the rules. That makes it a strong building block for teams with engineers, and more work for everyone else.
The free plan covers 1,000 calls a month plus a 14-day Pro Plus trial. Enterprise is custom with a 99.9% SLA.
Why people switch to it
- Cheaper entry than Castle Pro
- Strong device ID across web and mobile
Worth knowing
- Signals, not decisions
- No ad sends
Best for: teams that want the raw signal and will write the rules themselves.

4. SEON: best for a full fraud and AML suite
SEON is bigger than Castle. It claims over 1,000 signals, case management and AML on Premium, and 5,000+ organizations. Starter includes 10 users and 50 custom rules. It suits fintech, gaming and anyone with a fraud team and payment risk.
It is also the most expensive entry here, and like the others, it is not built to feed your ad platforms.
Why people switch to it
- Case management and AML
- Deep signal coverage
Worth knowing
- Built for fraud teams, not marketers
Best for: teams with a fraud team and payment risk to manage.

5. Cloudflare Turnstile: best for a free form check
Turnstile is a free, low-friction check you put on a signup form. It stops simple bots at the door. There is no risk engine, no account takeover scoring and no link to your ads.
For a small product with a bot problem and no budget, it is a sensible first step. It is not built for humans on VPNs or fake signups that pass the check.
Why people switch to it
- Free
- Minutes to add
Worth knowing
- A gate, not a risk score
- Nothing reaches your ads
Best for: keeping simple bots off one form.
How to choose a Castle alternative
- Name the risk. Stolen accounts? Rupt or Castle. Fake signups poisoning ads? DataCops. Payment fraud? SEON.
- Check if you pay for ads. If you do, a fraud score that never reaches the ad platforms leaves half the problem.
- Count your engineers. Castle, Rupt and Fingerprint need code. DataCops is switches.
- Know where you will be next year.
Pick DataCops if
- You pay for Meta, Google Ads, TikTok or LinkedIn ads that drive signups.
- Fake signups are teaching your ads the wrong people.
- Real signups via Sign in with Google lose their ad credit.
Also compared: Arkose, SEON, Sift, Verisoul, IPQualityScore, reCAPTCHA, FingerprintJS and Rupt alternatives.
When not to use DataCops
- Castle keeps the lead on logins. Its Bot, Abuse and account takeover scores, device checks and policies are built to guard accounts after signup. If login abuse is your main risk, keep Castle there and move only the signup and ad side.
- You need to judge accounts inside your product. Account takeover, payment fraud, multi-accounting and manual review are what fraud and identity tools are built for. DataCops does none of that.
- You do not run paid ads. If fakes are not reaching an ad platform, an account-fraud tool alone may be all you need.
What's your actual goal?
Nobody wants a risk score for its own sake. If you run paid ads to a signup, you want four things:
- Real people only, in your product and in your ad data.
- Every real signup credited to its ad, including the ones who use Sign in with Google.
- The later moments sent too, like trial, qualified lead and paid.
- Stay compliant, with consent checked and data deleted on request.
Castle helps with the first half of the first one. Here is the whole goal, done both ways.
The traditional way, with Castle
- Add the Castle SDK to your web app and mobile apps.
- Call the Risk API from your backend on every signup.
- Write policies for what each score means.
- Write code so risky signups do not fire the pixel or the server event.
- Build click ID capture that survives the Google sign-in redirect.
- Buy a tracking tool and a consent banner, and wire both in.
- Send trial and paid events to each ad platform yourself.
- Watch your API calls, and keep all of it working.
With DataCops
- Add one script and one DNS record.
- Connect each ad platform with one click.
- Switch on SignupCops and Real people only.
- Switch on the consent manager.
- Post later stages to your webhook, or connect HighLevel.
Then run your business. The click, the verdict and the send are handled for you.
Castle gives you a number. DataCops gives your ads clean data, so you can focus on growth.
Why people leave Castle
Castle is good at what it does. People leave for reasons around it.
- There is nothing in between.
- Short memory. Data is kept 3 days on Free and 7 days on Pro. Longer needs Enterprise.
- Rate limits. 1 request per second on Free and 5 on Pro.
- It is a developer tool. Every decision is a policy or code you write and maintain.
- The ads never hear about it. A risky signup can still be counted as a conversion by Meta and Google.
After the signup: the moments that pay
A signup is not a sale. The money comes later, and that later moment is what your ads should learn from. Castle does not send it anywhere. DataCops does, by webhook from any CRM or app, directly or through Zapier, Make or n8n.
| Business | What the pixel sees | What DataCops adds |
|---|---|---|
| SaaS and apps | Signup | Trial started, paid, by webhook |
| B2B | Demo request | Qualified lead, deal won with its value |
| Marketplaces | Account created | First real order, by webhook |
| Agencies on HighLevel | Form fills per client | Booked, showed, won and paid |
Cancellations, no-shows and lost deals are never sent from HighLevel.
See offline conversions for the full picture.
Ads Warmup: tell the ads who pays
Castle scores accounts and visitors inside your product. It does not tell the ad platforms which people are real customers, so new campaigns learn from scratch. The customers you already have are the best description of who to find.
Ads Warmup, DataCops' flagship feature, sends them to your ad platforms before a campaign spends:
- Upload a customer list. A CSV of past buyers, old leads or booked calls. DataCops reads your columns; only email is required.
- See a match score for every person. An estimate from 0 to 10 from email, phone, name, location, click ID and customer ID, before anything is sent.
- Pick the event. Purchase, Lead, Complete registration, Add to cart or Schedule.
- Send server-side. Up to 20,000 people per upload to Meta, Google Ads and TikTok, with a sent, skipped or failed result per person. Google Ads credits only people who clicked a Google ad.
Each row is dated when you press send, not with the old sale date, so it gives a new campaign real customers to learn from on day one. Preview is free; sending needs a paid plan.
What else a fraud API never does
- Capture at the edge. With DNS on Cloudflare, the free, optional DataCops Cloudflare Worker reads click IDs and UTMs off the first request, before the page or any script runs. It captures; it does not block.
- Keep the click on the server. gclid, wbraid, gbraid, fbclid, ttclid and li_fat_id are stored for up to 90 days, so a deal that closes weeks later still finds its click. A signed server-set cookie lasts up to 400 days where enabled.
- Check the lead's email. Fixed rules, not guesses: disposable providers, domains with no mail server and an email risk score. With LeadCops (Business and up), a lead that fails is held and never billed.
- Install on Shopify. The DataCops Shopify app adds a web pixel and a theme app embed, so every paid order reaches your ads, express checkouts included. See Shopify Conversions API.
- Hand evidence to Google. On the Organization plan, the fraud refund report exports bot-flagged Google Ads clicks in the format Google's Click Quality form asks for. You attach it; Google decides.
Setup, step by step, side by side
Same job, both ways. Castle steps follow its developer model. DataCops steps are what you do in the dashboard.
| The job | ||
|---|---|---|
| Get started | Add the SDK, call the Risk API from your backend on each signup. | Add one script and one DNS record. |
| Decide what is risky | Write policies on Bot, Abuse and ATO scores. | Every visit gets a verdict: bot, datacenter, VPN or proxy. |
| Keep fake signups out of ads | Write code so risky signups skip the pixel and server events. | Switch on Real people only per platform. |
| Credit Sign in with Google signups | Not built in. Custom work in your app. | SignupCops keeps the ad click. |
| Send trial and paid | Not built in. A separate tracking tool. | Post to your webhook, or connect HighLevel. |
| Handle consent | Not built in. A separate consent tool. | Switch on the built-in consent manager. |
Castle is built for developers and every step is doable. The question is who writes it and who keeps it working.
"15 minutes to get server-side tracking live. After 3 days failing with another app and a DIY server-side Google Tag Manager, that alone sold me. Then support jumped on a Google Meet with me on a Sunday afternoon to finish the job."Andrew Forsyth, Chief Executive Officer, Zeald
What to know before you switch
- Castle keeps the lead on logins. Its Bot, Abuse and account takeover scores, device checks and policies are built to guard accounts after signup. If login abuse is your main risk, keep Castle there and move only the signup and ad side.
- Watch the held signups for a week. Castle shows a score; DataCops shows what each ad platform was told. After you switch on SignupCops and Real people only (both off until you turn them on), read the delivery log to see which signups were held and why.
Moving from Castle
- Decide what Castle does for you. If it guards logins, keep it. If it only screens signups, DataCops can take that job.
- Add DataCops. One script and one DNS record. Connect your ad accounts with one click each.
- Switch on SignupCops and Real people only for each platform, and check the delivery log for held signups.
- Send later stages by webhook, so the ads learn from trials and payments, not just signups.
- Remove the Castle calls from your signup flow when the numbers look right.
Every DataCops product mentioned here
- SignupCops and click fraud protection.
- Server-side tracking and first-party analytics.
- Meta Conversions API, Google Ads conversion tracking, TikTok Events API, LinkedIn Conversions API.
- Offline conversions, HighLevel conversion tracking and DataCops for agencies.
- Consent manager, Ads Warmup and health mode.
Castle alternatives: FAQ
Can I warm up a new campaign with my existing customers?
Yes, with DataCops Ads Warmup. Upload a CSV of past buyers, old leads or booked calls (only email is required, up to 20,000 rows), see a match score from 0 to 10 for every person, and send them to Meta, Google Ads and TikTok as fresh signal, dated when you send. Google Ads credits only people who clicked a Google ad. Preview is free; sending needs a paid plan.
When should I keep Castle instead of switching?
Castle keeps the lead on logins. Its Bot, Abuse and account takeover scores, device checks and policies are built to guard accounts after signup. If login abuse is your main risk, keep Castle there and move only the signup and ad side.
What is the best Castle alternative?
DataCops, for most ad-funded businesses. It replaces Castle and the rest of the stack: one script, a bot verdict on every visit, a built-in consent manager, server-side sends to 8 ad platforms, and your CRM sales matched to the ad click. Other picks depend on the job. If you need login and account takeover protection, Rupt is the closest swap at about the same price. If your real problem is fake signups teaching your ads the wrong people, DataCops fixes that end: SignupCops holds risky signups back from Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X and keeps the ad click through Sign in with Google.
How long does Castle keep data?
Three days on Free and 7 days on Pro. Enterprise keeps data up to 18 months. DataCops keeps click IDs, sessions and the click log for 90 days, and the visitor cookie lasts up to 400 days (it needs consent in the EU).
Does Castle send conversions to Meta or Google Ads?
We found no ad platform sends on its pricing or feature pages. Castle returns a risk score to your backend. What happens next, including keeping fake signups out of your ad data, is code you write. DataCops sends to Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X, with a Real people only switch per platform.
Does DataCops protect logins from account takeover?
No. DataCops does not score logins. If account takeover is your main risk, keep Castle or pick Rupt. DataCops works on the signup and ad side: it keeps fake signups out of your ad platforms and keeps the ad click on real ones.
How does DataCops recognise a returning visitor?
With a first-party cookie set from your own subdomain. It lasts up to 400 days and needs consent in the EU. On top of that, every visit gets a bot verdict that checks for bots, datacenter traffic, VPNs and proxies.
Can I use Castle and DataCops together?
Yes. They do different jobs. Castle guards your logins and in-app actions. DataCops tracks the ad click, keeps bots out of your ad platforms and sends the sales that come later. Many teams will want both.
Which ad platforms does DataCops send to?
Eight: Meta, Google Ads, TikTok, LinkedIn, Microsoft Ads, Reddit, Pinterest and X. Meta, Google Ads, TikTok, LinkedIn and X connect with one click. Microsoft Ads, Reddit and Pinterest connect with an API key. Microsoft Ads uses its UET Conversions API, which Microsoft runs as a pilot, so ask your Microsoft account manager to turn it on.