Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

HUMAN Security and PerimeterX announced a merger in July 2022. The combined business operates under the HUMAN Security name and describes its product direction as a Human Defense Platform. HUMAN brought bot mitigation, media security and fraud detection; PerimeterX added application-layer account protection and automated-fraud defenses. The result is a broader platform aimed at attacks that look like ordinary customer activity rather than obvious malicious traffic.

This matters to enterprises because the merger can consolidate bot, account and transaction defenses, but it may also overlap with tools already deployed in a security, fraud, identity, WAF or CDN stack.

What happened when HUMAN Security merged with PerimeterX?

HUMAN Security announced that it was joining with PerimeterX in July 2022 to accelerate a Human Defense Platform and combine the companies’ teams and technology. The combined company kept the HUMAN Security name, according to the official merger announcement and contemporaneous Dark Reading coverage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

At the time of the announcement, Dark Reading reported more than 500 customers and more than $100 million in annual recurring revenue. Financial terms were not disclosed.

#1 Best Overall
Fortinet Web Application Firewall - Virtual Appliance for All Supported Platforms. Supports up to 2 x vCPU core FWB-VM02
  • Fortinet Web Application Firewall - virtual appliance for all supported platforms. Supports up to 2 x vCPU core
  • Fortinet HW FWB-VM02
  • Manufacturer Part: FWB-VM02

What each company contributed

Area HUMAN Security PerimeterX Combined direction
Primary contribution Bot mitigation, media security and fraud detection Application-layer account protection and automated-fraud defense Broader defense against automated abuse across the customer journey
Typical security focus Detecting and disrupting non-human traffic and advertising or media fraud Protecting applications, accounts and transactions from automated attacks Connecting traffic, device, behavior, account and transaction signals
Business rationale Reduce malicious automation and improve trust in digital interactions Stop abuse that can pass as a normal application request One vendor relationship and a wider signal set

How does PerimeterX fit into HUMAN Security?

PerimeterX is best understood as the application-protection and automated-fraud portion of the combined portfolio. Its capabilities address abuse at login, registration, account and transaction flows, where an attacker may use valid credentials, a real browser or a distributed device network.

That complements HUMAN’s earlier emphasis on bot mitigation, media security and fraud detection. Rather than treating bot management as only a traffic-filtering problem, the combined approach is intended to identify how automation affects a business process: creating accounts, taking over existing accounts, scraping data, reserving scarce inventory or abusing a promotion.

HUMAN co-founder and CEO Tamer Hassan described the merged teams and products as a force against cybercriminals. PerimeterX co-founder and CEO Omri Iluz said the merger was intended to accelerate the Human Defense Platform and address major internet-security challenges; both quotations appear in the company’s announcement.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Fortinet Web Application Firewall - Virtual Appliance for All Supported Platforms. Supports up to 4 x vCPU core FWB-VM04
  • Fortinet Web Application Firewall - virtual appliance for all supported platforms. Supports up to 4 x vCPU core
  • Fortinet HW FWB-VM04
  • Manufacturer Part: FWB-VM04

What attacks does the combined HUMAN platform target?

The central problem is business-logic abuse: requests that are technically valid and can resemble legitimate user activity, yet exploit the way a site, app or transaction process works. Dark Reading notes that a conventional web application firewall may not identify these actions because the request itself can look normal.

Account and identity abuse

  • Credential stuffing: automated login attempts using username-and-password combinations stolen elsewhere.
  • Account takeover: gaining control of an existing customer account and then using its stored value, privileges or personal data.
  • Fake-account creation: registering large numbers of accounts to obtain incentives, hide activity or manipulate a service.
  • PII harvesting: automating flows to collect personally identifiable information.

Commerce and promotion abuse

  • Carding: testing stolen payment cards or gift cards against a merchant.
  • Promotion abuse: repeatedly exploiting coupons, referral credits or other incentives.
  • Denial of inventory: tying up products or reservations so legitimate customers cannot buy them.
  • Scalping: using automation to acquire scarce goods or tickets for resale.

Data, content and client-side attacks

  • Web scraping: extracting prices, listings, content or other data at a scale that harms the service or creates competitive risk.
  • Digital skimming: stealing payment or checkout data through malicious client-side code.
  • Client-side supply-chain attacks: abusing scripts and third-party components running in a customer’s browser.
  • Automated engagement or ad fraud: fabricating views, clicks or other signals that distort media and marketing performance.

HUMAN’s enterprise-security use-case list includes account takeover, fake accounts, carding, client-side supply-chain attacks, credential stuffing, denial of inventory, digital skimming, PII harvesting, scalping and web scraping. See the HUMAN merger page for the company’s list.

Is HUMAN Security a bot-management, fraud or account-protection company?

After the merger, it is not accurate to place HUMAN in only one category. Its portfolio spans all three:

Rank #3
Fortinet Web Application Firewall - Virtual Appliance for All Supported Platforms. Supports up to 8 x vCPU core FWB-VM08
  • Fortinet Web Application Firewall - virtual appliance for all supported platforms. Supports up to 8 x vCPU core
  • Fortinet HW FWB-VM08
  • Manufacturer Part: FWB-VM08
  • Bot management: identifying, monitoring and controlling automated traffic.
  • Fraud prevention: detecting payment, promotion, media and other abuse patterns.
  • Account protection: defending login, registration, recovery and post-login activity against takeover and automated misuse.

The practical distinction is where controls are applied and what context they use. A bot control may score a request using device, browser and network evidence. Account protection adds identity and session history. Fraud controls add transaction, payment and promotion context. Enterprises should therefore evaluate the platform as a risk and enforcement layer across multiple workflows, not as a replacement label for a single product category.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why enterprises considered the merger attractive

Broader signals

Combining traffic, device, browser, behavioral, account and transaction information can make it easier to distinguish a genuine customer from automation that imitates one. A login attempt, for example, can be assessed in relation to the device, session behavior and subsequent account or payment activity instead of in isolation.

Coverage across digital surfaces

The intended scope includes websites, APIs, mobile applications, login and registration, search, checkout and account recovery. That allows a security team to address a sequence of related actions rather than deploy unrelated controls for every endpoint.

Rank #4
Cisco Meraki MX100 Security Appliance, Firewall, GigE, 1U, Rack-Mountable
  • Meraki MX100: A building block for SASE in a rack-mountable form factor. Medium- to large-branch security and SD-WAN appliance for up to 500 users.
  • WAN: 1 x GbE RJ45, 1 x USB (cellular failover), Dual-purpose: 1 x GbE RJ45 +++ LAN: 8 x GbE RJ45, 2 x GbE SFP
  • Stateful firewall throughput: 750 Mbps +++ 500 Mbps site-to-site VPN throughput
  • Unified management for security, SD-WAN, Wi-Fi, switching, MDM, and IoT +++ Centralized management via web-based dashboard or API
  • True zero-touch provisioning +++ Smartphone-like firmware updates

Vendor consolidation

A single relationship for advertising, marketing, e-commerce and cybersecurity use cases can reduce the number of products and operational handoffs. It may also simplify policy ownership and escalation when an attack crosses from traffic abuse into account or transaction fraud.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should an enterprise evaluate before consolidating defenses?

Consolidation is a design decision, not an automatic benefit. Use the following evaluation framework in a proof of concept and require evidence for each workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. Map attack coverage to business flows

  • Test credential stuffing, account takeover, fake accounts, scraping, scalping, carding and promotion abuse.
  • Include both obvious automation and low-and-slow activity that resembles normal customers.
  • Check whether the same policy can follow a user from login through checkout or account recovery.

2. Verify the signal breadth

Ask which device, browser, network, behavioral, account and transaction signals are available, how quickly they are calculated and whether analysts can inspect the reason for a decision. A broad signal list is useful only if it is accessible to policy authors and investigators.

Best Value
UDPTCP Firewall, Intelligent Soft Routing Micro Appliance/Fanless Mini PC • Celeron N2840, 2 x RJ45(1000M), USB 3.0,HDMI,VGA,NO RAM NO mSATA SSD (8GB RAM 256GB SSD)
  • ◆Powerful Celeron N2840 Processor: N2840 Processor, 2 Cores 2 Threads, 1M Cache, Max Turbo Frequency 2.58 GHz, TDP 7.5 W. Whether you need a robust home server, a versatile tool for school education, seamless web browsing, or even efficient business office or industrial tasks, providing efficient performance for everyday tasks.
  • ◆Dual 1000M LAN: Mini Router PC with 2*Realtek RTL8111H network card chip full UDE 1000M with filter connector.Soft Router can monitor network data, improve network security, powerful and widely used.
  • ◆DDR3L Memory & Large Storage Capacity: Firewall box computer with 1 x DDR3L SO-DIMM memory 1333/1600MHz, 1xMSATA3.0 SSD.
  • ◆UHD Graphics & 4K Dual Screen Display: N2840 processor integrated UHD Graphics, HD and VGA dual display interfaces support 4K@60Hz. 
  • ◆Versatile Connections ports: 2 x1000M Realtek RTL8111H-LAN,2 xUSB3.0, 4 xUSB2.0, HDMI,VGA,AUDIO supports data storage and system boot.Mini desktop computer with WIFI dual antenna, which providing high-speed transmission and reliable connectivity. Support Dual Band Wifi, Internet, streaming media and audio can be used perfectly without interrupting the connection. Enjoy faster file transfers and smoother online experiences.

3. Examine enforcement choices

Confirm that policies can allow, monitor, challenge, throttle or block according to risk. Require graduated actions for uncertain cases so a suspicious session can be challenged or rate-limited instead of immediately rejected.

4. Check every required surface

Validate integrations for the actual architecture: web pages, APIs, native mobile apps, identity providers, login, registration, search, checkout and account recovery. A platform that protects only the front door may leave the highest-value workflow exposed.

5. Measure operational and business effects

  • False-positive rate for known customers and legitimate automation.
  • Added latency at login, search and checkout.
  • Challenge completion and conversion impact.
  • Analyst workflow, alert quality and SIEM or case-management integration.
  • Policy portability during an outage or vendor transition.

6. Identify overlap before retiring products

Compare the proposed deployment with existing WAF, CDN, identity, fraud, SIEM and application-security controls. The merger’s broader portfolio can reduce vendor count, but it can also create duplicated capabilities, new integration work and resistance to buying a full suite. Retire a control only after the replacement covers its detections, response actions, logging and service-level requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical takeaway

The HUMAN–PerimeterX merger joined bot and media-security capabilities with application-layer account and automated-fraud protection. Its value is greatest for organizations facing abuse that crosses boundaries—such as a bot that logs in with stolen credentials, creates accounts, consumes inventory and completes a fraudulent transaction. Enterprises should judge the platform on measurable attack coverage, signal quality, enforcement flexibility, integration effort and customer impact rather than on whether it is labeled bot management or fraud prevention.

Quick Recap

Bestseller No. 4
Cisco Meraki MX100 Security Appliance, Firewall, GigE, 1U, Rack-Mountable
Cisco Meraki MX100 Security Appliance, Firewall, GigE, 1U, Rack-Mountable
Stateful firewall throughput: 750 Mbps +++ 500 Mbps site-to-site VPN throughput; True zero-touch provisioning +++ Smartphone-like firmware updates
$344.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.