2026-04-19 · Security
Homegrown bot protection on the Contact Widget
- 4-layer bot check replaces external CAPTCHA dependency: honeypot field, minimum fill time, HMAC-signed challenge, behavioral signals.
- No per-hostname registration overhead — the widget works on any customer site out of the box.
- All failures collapse to a single generic error so attackers can't probe for which layer caught them.