Listing Thumbnail

    DataDome Bot Protect

     Info
    Sold by: DataDome 
    Deployed on AWS
    Free Trial
    Vendor Insights
    AWS Free Tier
    DataDome stops cyberfraud and bots in real time using AI-powered detection, analyzing 5 trillion signals daily to protect websites, mobile apps, and APIs, without compromising performance.
    4.7

    Overview

    Play video

    DataDome protects businesses from cyberfraud and bots in real time, securing websites, mobile apps, ads, and APIs. Named a Leader in The Forrester Wave™ Bot Management 2024, DataDome is trusted by leading brands like Foot Locker, Tripadvisor, and SoundCloud. Its AI-powered Cyberfraud Protection Platform processes 5 trillion signals daily without compromising performance. Backed by DataDome Advanced Threat Research, the platform stays ahead of emerging threats and autonomously stops over 350 billion attacks annually. With 50+ integrations and 24/7 SOC coverage, DataDome has record-fast time to value. Recognized as a G2 Leader and one of G2 Best Security Products of 2024, DataDome delivers protection that outperforms.

    DataDome leverages AWS autoscaling to multiply our compute capacity x200 in 90s, to run bot detection ML at the edge in 30+ PoPs. An early adopter of Lambda@Edge, DataDome is an ISV Accelerate and AWS Marketplace-friendly partner. DataDome has obtained AWS Security and Retail Software Competencies and is Amazon CloudFront and AWS WAF Ready.

    Highlights

    • Instant bot protection: DataDome is the only SaaS-based bot protection solution. Requires no architecture changes or DNS rerouting. Deploys in minutes on AWS Cloudfront using a Lambda@Edge.
    • Real-time bot detection: DataDome analyzes every request to your mobile app, website, and/or API in under 2 milliseconds. Uses an expert-supervised ML engine that leverages over 5 trillion data points per day.
    • Discover the solution recognized as a Leader in The Forrester Wave™: Bot Management Software, Q3 2024, receiving the highest score possible in nine criteria, including detection models, partner ecosystem, and more.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (2)

    Pricing

    Free trial

    Try this product free according to the free trial terms set by the vendor.

    DataDome Bot Protect

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (4)

     Info
    Dimension
    Description
    Cost/12 months
    Overage cost
    Essentials
    up to 100M requests per month
    $45,960.00
    Advanced
    up to 200M requests per month
    $104,040.00
    Premium
    up to 300M requests per month
    $121,920.00
    Enterprise
    up to 500M requests per month
    $159,240.00

    Vendor refund policy

    Long term contract cancellations or downgrades are not supported. If you need help with or want to upgrade your subscriptions, please contact us.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Media & Entertainment
    Top
    100
    In Monitoring

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    6 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    AI-Powered Threat Detection
    Analyzes 5 trillion signals daily using expert-supervised machine learning engine to identify and stop cyberfraud and bot attacks in real time
    Edge Computing Architecture
    Runs bot detection ML at the edge across 30+ points of presence with AWS autoscaling capability to multiply compute capacity 200x in 90 seconds
    Sub-Millisecond Request Analysis
    Processes every request to websites, mobile apps, and APIs in under 2 milliseconds without compromising performance
    Serverless Deployment Integration
    Deploys as a SaaS solution using Lambda@Edge on AWS CloudFront without requiring architecture changes or DNS rerouting
    Autonomous Threat Prevention
    Autonomously stops over 350 billion attacks annually with 24/7 SOC coverage and Advanced Threat Research capabilities
    AI-Powered Threat Detection
    Patented AI-powered platform that detects, traps, and neutralizes bots and bad actors before they can impact genuine users
    Real-Time Threat Intelligence
    Tracks and shares real-time, global threat intelligence with customers to provide proactive threat awareness
    AWS Ecosystem Integration
    100% compatible with AWS Services including CloudFront and WAFv2 Classic with no-code deployment offering low latency, high stability, and scalability
    Multi-Vector Attack Protection
    Protects against account registration fraud, login attacks, business model abuse, in-platform abuse, and phishing attacks including credential stuffing, account takeover, web scraping, API abuse, and man-in-the-middle attacks
    Service Level Agreement Guarantee
    Offers 100% SLA guarantee with commercial protection against automated attacks and rapid deployment within three weeks
    Multi-Channel Bot Detection
    Detection and mitigation of automated threats across web, mobile, and API channels including Account Takeover, Credential Stuffing, Scraping, Carding, Cracking, Checkout Abuse, Inventory Denial, and Application DDoS attacks.
    Behavioral Analysis Engine
    Evidence-based detection utilizing behavioral data from interactions with billions of bots, inspecting all client requests for definitive traces of automation.
    CAPTCHA-Free Authentication
    Invisible next-generation defenses that eliminate the need for CAPTCHAs while maintaining frictionless user experience.
    Cloud-Native Integration
    Scalable cloud service with quick integration capabilities for AWS and Amazon CloudFront environments.
    Threat Intelligence and Adaptive Defense
    Access to threat intelligence team and world-class engineers providing proactive threat anticipation and adaptive defenses resilient to adversarial retooling and reverse engineering.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.7
    227 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    86%
    13%
    1%
    0%
    0%
    2 AWS reviews
    |
    225 external reviews
    External reviews are from G2  and PeerSpot .
    Harshal Deore

    Automated bot protection has reduced fraud and now lets our teams focus on real incidents

    Reviewed on Jun 01, 2026
    Review provided by PeerSpot

    What is our primary use case?

    DataDome  has been used primarily for real-time bot protection and fraud prevention. It secures login pages, checkout flows, and API endpoints against automated attacks such as credential stuffing, scraping, and account takeover attempts.

    The main workflow involves reviewing today's traffic and block charts to quickly understand if anything unusual is happening. After that initial check, we drill into attack types, scraping, fraud attempts, review flagged IPs, sessions, check false positives, and validate recent rule changes for model updates. The first action is essentially to determine whether we are under attack and whether DataDome  is blocking correctly.

    What is most valuable?

    The core capabilities we rely on every day are real-time bot detection and automatic traffic blocking. The real-time dashboard and threat visibility are the features we use most frequently. The automatic bot mitigation engine handles most of the protection without manual intervention. We also frequently use traffic analysis and reporting, especially when investigating incidents such as scraping attempts or credential stuffing attacks. The most valuable aspect for the team is that DataDome operates mostly in a set it and monitor it mode where the system actively protects applications while we primarily focus on reviewing exceptions and tuning when needed.

    After implementing DataDome, the biggest impact we observed was a reduction in automated abuse and stabilization of traffic patterns across our applications. Before implementation, we dealt with frequent spikes from scraping bots and login abuse attempts. Once it was fully in place, we saw clear improvement in application stability and backend server efficiency. On the security side, we improved our overall posture against credential stuffing and scraping attacks, which reduced the number of manual incident investigations the team had to handle. In terms of operational benefits, the team now spends less time analyzing traffic anomalies and more time focusing on actual application issues. It also improved confidence during high-traffic events since we know a significant portion of automated traffic is being handled in real time. The main improvements have been better protection, reduced operational noise, improved system stability, and lower manual effort in handling bot-related incidents.

    What needs improvement?

    There are some features in DataDome that we do not actively use anymore in day-to-day work. One example is the more fine-grained manual rule tuning and the custom challenge configurations during onboarding. We spent time experimenting with these to understand how different rules would impact traffic, but once the system was properly tuned, we rarely needed to adjust them manually anymore because the automated detection handled most scenarios effectively. Another feature we initially explored was the deep investigative drill-down for individual sessions and advanced forensic analysis. While it is powerful, we found that we only use it occasionally during specific security incidents rather than as part of regular monitoring. We also experimented early on with some advanced reporting and segmentation views, but over time, the team standardized on a smaller set of dashboards that provide the key metrics we need, so the more detailed views are used less frequently. Most of the unused features are not problematic; they are just more situational. As the system matured in our environment, we naturally shifted toward the core features such as real-time blocking, high-level dashboards, and automated protection.

    If there is one thing I could change about DataDome, it would be to improve the transparency and explainability of detection decisions, specifically making it easier to understand why a request was classified as a bot or triggered a block in a more intuitive way. Currently, the system is very effective, but when something gets flagged, we sometimes need to dig through multiple dashboards and logs to fully understand the reasoning behind the decision. A clearer, more unified explanation layer would have a direct impact on workflow. Overall, it would make day-to-day operations smoother by turning an investigation from a multi-step analysis process into something more immediate and self-explanatory.

    For how long have I used the solution?

    I have been familiar with DataDome for the past six to seven months.

    Which solution did I use previously and why did I switch?

    Before DataDome, we were not using any other solution. We were completely focused on DataDome itself.

    How was the initial setup?

    The initial setup to get DataDome in front of our key endpoints such as login and checkout was relatively straightforward. However, getting it fully production ready took longer. The first one to two weeks were mostly about tuning, adjusting rules, reviewing false positives, and making sure legitimate users were not being impacted. We also spent time validating traffic behavior across different regions and user patterns. Overall, it was fairly quick to get live and protecting traffic, but it took closer to a few weeks to reach a stable, well-tuned state that we were confident running at scale in production.

    What about the implementation team?

    DataDome is not used single-handedly; it is a team workflow. With DataDome, we were able to start using it fairly quickly. Without formal training for the entire team, the initial onboarding was straightforward, and the basic dashboard and alerts were intuitive enough that we could begin monitoring traffic almost immediately. That said, a small core group, mainly from Security and DevOps, did spend some time diving into more advanced parts, such as tuning detection rules, reviewing false positives, and understanding how the scoring and blocking decisions work. In practice, most of the team did not need dedicated training sessions, but a few key engineers did a deeper dive to make sure we were using it effectively and safely in production.

    Which other solutions did I evaluate?

    We were focused on DataDome, so there were no other options considered.

    What other advice do I have?

    On the traffic side, we observed a reduction of roughly 70% to 90% in malicious bot traffic reaching our applications. From an operational perspective, the number of bot-related security incidents dropped by around 60% to 75%. We also saw improvement in incident response efficiency, with roughly 30% to 40% less time spent per security investigation. Overall, the biggest measurable benefit was not just fewer attacks getting through, but also the reduction in noise, meaning the team could focus on real issues instead of constantly reacting to bot-driven alerts.

    Collaboration definitely changed after adopting DataDome. Before, bot-related issues were mostly handled in a reactive way where security, DevOps, and application teams would jump in only after an incident was reported. That often led to a lot of back-and-forth during active issues. After implementation, collaboration became more structured and proactive. The security platform team now primarily owns the configuration and monitoring of DataDome. We also saw better alignment between teams during incidents. Instead of debating whether traffic was legitimate or malicious, everyone refers to the same dashboards and threat data. Overall, it shifted collaboration from reactive firefighting to a more centralized, data-driven, and preventive model with clearer ownership and faster alignment during incidents.

    With DataDome, the biggest friction points we experienced were mostly around tuning and visibility during the early phase. Initially, one challenge was false positives, where some legitimate traffic, especially from unusual user behavior patterns, corporate networks, or certain geographies was occasionally flagged as suspicious. It required careful tuning and coordination between security and application teams to strike the right balance between protection and user experience. Another friction point was the learning curve around rule behavior and detection logic. While the platform is easy to start with, understanding why certain traffic is blocked and how scoring decisions are made took time for the team to fully get comfortable. We also noticed that debugging edge cases can sometimes take effort, especially when trying to trace why a specific session was challenged or blocked. Finally, during the early rollout, there was some coordination overhead between teams, since security owned the configuration, but application teams were impacted when legitimate traffic needed adjustments. That improved over time, but it was a noticeable friction point during onboarding. Overall, most of these issues reduced significantly after the initial tuning phase, and once the system stabilized, day-to-day friction became much lower.

    In terms of its main capabilities such as real-time bot detection, traffic reporting, and dashboards, the evolution is less about features being set and more about progression toward automation and simplification, where the platform requires fewer manual interventions and more managed, intelligence-driven protection. I would rate this review as an 8.

    Arka Sarkar

    Real-time bot defense has protected telecom APIs and now keeps customer logins secure

    Reviewed on May 22, 2026
    Review from a verified AWS customer

    What is our primary use case?

    In my organization, the primary use case of DataDome  is end-to-end observability across telecom applications and infrastructure, especially for real-time network services and customer-facing systems. In our domain, we use DataDome  APM  to monitor microservices handling telecom workflows, such as call and session management systems, IMS  components, charging and billing gateways, and API gateways handling subscriber requests. If a subscriber experiences a delay in call setup or data session activation, we trace the request across microservices and quickly identify which service is slow and whether it is a database latency issue or downstream dependency.

    In one of our day-to-day use cases, we use DataDome to secure the customer login portals, recharge and payment pages, and self-care mobile and web applications. These often face credential stuffing attacks, which we received in earlier days. There was a major outage due to these credential stuffing attacks on one of the Bharti servers in the North India circle. Fake login attempts were also detected. Using DataDome, we secured our servers and all nodes, and we stopped the account takeover attempts. In our system, we expose multiple APIs for balance check, recharge, SIM activation, and plan browsing. Different bots always try to scrape plans and pricing data, abuse recharge APIs, and flood APIs. DataDome helps us by identifying those non-human traffic patterns, blocking malicious API calls, and ensuring service availability for real customers.

    In our organization, particularly in our product, multiple teams interact with DataDome regularly, mainly security, NOC, and application teams. The security team uses DataDome on a daily basis to monitor bot traffic trends and malicious traffic trends, and they review block requests and attack patterns. They fine-tune protection policies, including CAPTCHA, block, and allow rules. In one practical scenario, there was a spike in login failures, and the security team checked the DataDome dashboard to confirm if it was a credential stuffing attack, then they tightened rules accordingly. The NOC team uses this for monitoring traffic anomalies, checking if bot traffic is impacting system performance, and coordinating during incidents. The application team and charging team also interact with DataDome to address legitimate users being mistakenly blocked and to handle new APIs or endpoints introduced. We also coordinate with the security team to whitelist trusted traffic and adjust rules to avoid user impact.

    What is most valuable?

    For my particular domain in charging, DataDome offers several strong features, but a few stand out as especially valuable for telecom use cases in our situation. The most critical feature of DataDome is that it detects and blocks bots in real-time without noticeable latency. It uses different behavioral analysis instead of just IP-based blocking. This matters for our case because it prevents credential stuffing on login portals, stops API abuse, and ensures genuine users are not impacted. This directly protects customer experience, which is directly proportional to revenue and helps us to onboard more customers overall. The advanced bot identification is another key point of using DataDome, as it identifies bots even if they rotate IPs or mimic human behavior. It uses device fingerprinting and request pattern analysis. The API protection is another key point as it protects backend APIs from abuse and overuse and detects abnormal request patterns. Low false positives indicate that legitimate users are rarely blocked.

    DataDome has a significant positive impact on both our security posture and business performance. The first point is reducing fraud and account takeovers. Before implementing DataDome, we observed repeated credential stuffing attempts on customer login systems. After implementation, these attacks get blocked in real-time. The impact is a significant reduction in account takeover incidents and improved customer trust in security. The second point is improving API stability and performance. Our telecom charging APIs, including recharges, balance checks, and plan browsing, are frequent bot targets. It filters out malicious traffic before it reaches the backend system, which directly contributes to reducing unnecessary load on APIs and more stable performance, especially during peak hours. The better customer experience is another benefit since DataDome has low false positives. Genuine users are rarely blocked, and intelligent CAPTCHA is only applied when needed, which is directly proportional to smooth login and transaction experiences and fewer customer complaints related to access issues.

    After implementing DataDome, we observed measurable improvements across security, performance, and user experience. The reduction in bot traffic has also decreased significantly. Earlier, around 25 to 30 percent of our incoming traffic on customer-facing portals was bot-driven. After DataDome, we are able to block 90 to 95 percent of malicious bot traffic. The impact is cleaner traffic reaching backend systems and better reliability of analytics and monitoring. There is also a drop in credential stuffing. We used to see thousands of failed login attempts per minute during attack peaks. Post-DataDome, these attacks get blocked at the edge before reaching the application, resulting in a 70 to 80 percent reduction in suspicious login attempts reaching the backend and a significant drop in account takeover incidents. The API load reduction is significant as APIs like recharge and balance check were heavily targeted. Before, there was a high spike in API calls during bot attacks leading to performance degradation during peak hours, and after using DataDome, we observe around 20 to 30 percent reduction in unnecessary API traffic. The impact is quite clear with improved API response time and a more stable system during high traffic.

    What needs improvement?

    While DataDome performs very well overall, there are a few areas where improvements would make it even more effective in a telecom environment. One point is better handling of false positives. Although it is generally very accurate, in some cases, legitimate users or internal systems get flagged, especially corporate VPN users, internal testing tools, and partner integrations. The improvement would be a more granular and easier whitelisting mechanism and better transparency on why a request was blocked. Another point is more detailed analytics and custom reporting. The current dashboards are good, but sometimes detailed analysis is limited. Custom reporting options are not very flexible. As part of improvement, more customizable dashboards can be made, along with the ability to create business-specific reports, for each API and per region. Better visibility for API-level protection can also be developed. The protection works well, but debugging blocked API requests can take time and is not always easy to trace the exact reason for blocking, thus requiring more detailed logs and traceability for API traffic, along with easier correlation with backend systems. The integration with the existing security ecosystem can also be improved.

    For how long have I used the solution?

    I have been using DataDome for about 4.5 years.

    What other advice do I have?

    I believe I have added enough information. The most valuable feature for our organization is DataDome's real-time bot detection and mitigation. Since our applications like login and recharge APIs are frequent targets of automated attacks, the ability to block malicious traffic instantly is very critical. It helps us prevent fraud, maintain API performance, and ensure a seamless experience for genuine users.

    In our project, we mainly work with hybrid infrastructure, but for cloud environments, we commonly use Amazon Web Services  and sometimes Microsoft Azure , depending on the customer requirement and region. This is because it integrates very smoothly with AWS  services including EC2 , EKS Kubernetes  clusters, and Lambda. We use these integrations for real-time infrastructure monitoring, application performance monitoring, and log analytics.

    For some customer environments, the subscription and integrations are managed through the AWS marketplace because it simplifies procurement, billing, and enterprise account management. For larger portions, this is convenient because cloud spending and monitoring costs can be consolidated under the same AWS commercial agreement. It also makes deployment faster since integrations with AWS services are already streamlined. However, the procurement model can vary depending on different customers. Some sub-organizations use direct enterprise licensing with DataDome, especially when they need custom pricing, advanced support, security modules, and multi-region enterprise agreements. The procurement model varies from customer to customer.

    The integration of DataDome with our existing systems was relatively smooth compared to many traditional monitoring tools. One major advantage is that it already provides built-in integration for public cloud platforms, Kubernetes , Linux servers, databases, messaging systems, CI/CD pipelines, and logging tools. For most components, we mainly needed agent deployment and API-based integration and configuration rather than heavy custom development. In our environment, we integrated DataDome with clusters, application servers, API gateways, and cloud infrastructure for centralized logging systems. It fits well into our existing DevOps and NOC workflows because alerts can be connected to ticketing and incident management platforms.

    I would rate this review as a 9 out of 10.

    Information Services

    Reliable Protection with Strong Support and Smooth Performance

    Reviewed on May 04, 2026
    Review provided by G2
    What do you like best about the product?
    DataDome is a highly effective bot protection solution that delivers strong, real-time security with low false-positive rate without disrupting legitimate users, which has been critical for maintaining both security and a smooth customer experience.

    The intuitive dashboard provides clear visibility into traffic and threats, making monitoring and reporting straightforward.

    We highly appreciate the attentive and knowledgeable Datadome team. From setup to ongoing questions, their responsiveness and support have been top-tier.
    What do you dislike about the product?
    If we had to mention one downside, it would be that the initial setup and fine-tuning can take a bit of effort, especially for more complex environments. However, once everything is properly configured, the platform runs smoothly and requires minimal ongoing maintenance.
    What problems is the product solving and how is that benefiting you?
    Protects from malicious automated traffic and unauthorized scraping, which has been greatly reduced after implementing Datadome solutions.
    reviewer2817090

    Automated bot detection has protected logins and preserved accurate analytics insights

    Reviewed on Apr 30, 2026
    Review from a verified AWS customer

    What is our primary use case?

    DataDome  protects websites and apps from bots and online fraud by serving as bot protection and fraud prevention. It stops bad bots, allows good bots, and guards against fake account creation, ticket or product holding, payment fraud, and data scraping. Our product pages were aggressively scraped by bots, and login endpoints faced credential stuffing. I integrated DataDome  at the edge in front of our sites, which started analyzing incoming traffic in real-time, automatically blocking and challenging suspicious requests. As a result, scraping traffic dropped significantly, and login attack attempts were filtered before reaching our back end, resulting in fewer fake accounts and customer complaints about account takeovers. DataDome's dashboard allows us to check the bots versus human traffic breakdown and review blocked requests, eliminating the need for manual investigation of traffic spikes.

    What is most valuable?

    The best features in DataDome include AI-powered bot detection, which is crucial for real-time protection and high accuracy with low friction. It offers protection against multiple attack types, full visibility, and an analytics dashboard that supports scalability and performance.

    The AI-powered real-time bot detection feature is relied upon daily as it eliminates the need for constant manual intervention, saving us from manually digging through logs and writing custom rules to address sudden traffic spikes, login failures, and slower response times. With fewer security incidents, reduced infrastructure load, and cleaner analytics, I noticed an improved user experience and time saved across teams during high-risk times.

    What needs improvement?

    Needed improvements could focus on specific aspects that impact my workflow, enabling even more streamlined processes. To rate DataDome a ten, it would need to improve in certain areas or add features that enhance its efficiency and usability even further.

    For how long have I used the solution?

    I have been using DataDome for the last three years.

    What do I think about the stability of the solution?

    The biggest positive impact of using DataDome has been stability, efficiency, and trust in our traffic all at the same time.

    What was our ROI?

    Reduced infrastructure load, fewer security incidents, cleaner and more reliable analytics, improved user experience, and time saved across teams.

    What other advice do I have?

    For those looking into using DataDome, my advice is to start with the highest risk endpoint first, which is the login. I would rate DataDome an eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    David F.

    Excellent Bot Protection with Personalized Support

    Reviewed on Apr 29, 2026
    Review provided by G2
    What do you like best about the product?
    I like that DataDome does a good job preventing DDOS and scraping attacks on our website, and I was impressed with how well their models detect malicious traffic. I appreciate the three bot prevention mechanisms, which are less to more invasive depending on the threat levels, and the really nice bot protection experiences like interstitial, slide captchas, and hard blocks. The onboarding process was very nice, and our customer support rep is diligent in getting things up and running. Tuning alerts is something they've been very helpful with. The initial setup was very straightforward, and they came up with a custom solution to transfer from one vendor to another without dropping bot protection.
    What do you dislike about the product?
    We tried their other products, such as Login Protect, and found it did not do a great job with our company's use case. For Bot Protect, while they do a good job with general traffic, there was at least a month or two where we had to comb our own traffic and find spikes, and inform them about it. Ultimately, they don't really understand your traffic, or how people use your website and need a lot of guidance and personal investment to make sure it's working well, but it's generally worth the effort.
    What problems is the product solving and how is that benefiting you?
    I find DataDome effectively prevents DDOS and scraping attacks on our website. Their models detect malicious traffic well, providing user-friendly bot protection like interstitials and captchas. Tuning alerts has been straightforward with their diligent support.
    View all reviews