Shape Security emerged from about two years in stealth in January 2014 with ShapeShifter, a 1U network-security appliance aimed at making automated attacks on websites harder to carry out. Its central idea was to change the web interface elements scripts depended on, rather than rely only on identifying traffic already classified as malicious. That was Shape’s launch-era description of its design—not an independently verified performance result. F5 completed its acquisition of Shape Security in January 2020.
What was Shape Security?
Shape Security was a cybersecurity company that launched publicly in January 2014 after roughly two years in stealth, according to SecurityWeek’s launch coverage and Shape’s announcement. Its first product, ShapeShifter, was presented as enterprise website protection, not a consumer security device.
SecurityWeek reported that Shape had about 60 employees and was based in Mountain View, California, at launch. Shape’s January 21, 2014 announcement named Derek Smith as CEO and said the company had raised $26 million across Series A and B rounds from Kleiner Perkins Caufield & Byers, Venrock, Google Ventures, Wing Venture Partners, Allegis Capital, TomorrowVentures, and individual investor Enrique Salem. The $26 million figure is the amount in that launch announcement, not a current valuation or a lifetime funding total.
What was ShapeShifter, and how did it aim to stop bots?
Shape described ShapeShifter as a 1U network-security appliance that used “real-time polymorphism”: dynamically changing application code and fixed interface elements that automated tools might rely on. The company’s premise was that legitimate visitors would continue to see and use the familiar site while automated attackers encountered a changing target.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
The distinction from conventional detection is useful: detection tries to recognize suspicious or known-bad traffic, while Shape said its approach would deflect automation by disrupting the assumptions scripts used to interact with a site. CEO Derek Smith summarized the positioning in the launch announcement: “The ShapeShifter focuses on deflection, not detection.” That is a description of the product’s intended strategy, not proof that it prevented attacks in practice.
Shape positioned the appliance against malware, bots, scripts, account takeover, application-layer denial of service, Man-in-the-Browser activity, and some automated abuse of business logic. The launch sources describe intended use cases and company claims; they do not establish universal protection or provide independent product testing. Contemporary Dark Reading coverage added the rationale that making automated attacks more expensive to develop could benefit defenders. Shuman Ghosemajumder made that argument, while Robert Lentz characterized user interfaces as a security layer vulnerable to malware, bots, and scripts; these were attributed views, not validation of ShapeShifter’s effectiveness.
Rank #2
What threats and figures did the launch coverage discuss?
SecurityWeek’s January 2014 story supplied historical context for the company’s focus, including figures it attributed to earlier sources. These numbers describe past reports, not current threat rates:
- SecurityWeek reported that a 2012 Silver Tail Systems study found 88 percent of respondents considered business-logic abuse equally or more important than other security issues. The underlying study was not separately reviewed here.
- The same coverage cited an Imperva report from July 2011 estimating about 27 web-application probes or attacks per hour. This is a dated estimate reported in 2014, not a present-day rate.
Shape’s launch release also included endorsements that should be read in their promotional context. Bob Blakley, then director of security innovation at Citigroup, said, “By taking a technique — polymorphic code — out of the attackers’ own playbook, Shape turns the cost equation back around in the defender’s favor.” Robert Lentz, described in the release as a former chief information security officer of the United States Department of Defense and a FireEye board member, said Shape was operating on a previously inaccessible security layer: “the fact that everyone has a user interface, but user interfaces are inherently vulnerable to attacks from malware, bots and scripts.” Ted Schlein, managing partner at Kleiner Perkins Caufield & Byers, called for “a botwall” as a new tier of security architecture. These are launch-release opinions, not independent test findings.
Free tools Windows power users keep installed
One-click scans. No signup required.
What deployment plans and evidence were described?
The 2014 launch coverage centered on the 1U appliance. SecurityWeek also mentioned a cloud-based option as a planned direction; that does not establish that a cloud version was generally available at launch. The available launch reports describe Shape’s design claims and product positioning, but do not offer independent measurements of efficacy, deployment outcomes, or comparative performance against detection-based tools.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What happened to Shape Security after the launch?
F5 announced on January 24, 2020, that it had completed its acquisition of Shape Security. F5 said the deal added protection from automated attacks, botnets, and targeted fraud to its application-services portfolio, describing Shape as a leader in online fraud and abuse prevention. F5 also said Shape had insight from mitigating one billion application attacks per day; that figure is F5’s acquisition-announcement claim, not an independently audited current rate.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

