Bot Protection for your website
Optional, off-by-default bot protection for your website's forms, bookings, and lead capture. Turn it on per site and see exactly which surfaces it covers.
Bot Protection stops spam bots from submitting your website's forms. It's optional and off by default — you turn it on per website, and you can see exactly which parts of your site it covers.
Turning it on
Open your website from https://app.trustpager.com/growth/websites and find the Bot Protection band, then open it to reach the settings page. The main switch is the master control: turning it on protects every “widget-capable” surface on that site at once. That's the normal choice for a new site.
Deploying a site sets Bot Protection up in advance but leaves it off, so your forms are never accidentally blocked. Nothing is challenged until you flip the switch on.
What each part of your site gets
The settings page shows a coverage panel so there's no guessing:
- Forms — Protected. Public form submissions require a quick bot check.
- Scheduling — Protected. Public booking requests require the check.
- Lead Form — Protected. Website lead capture (email, SMS, voice, chat) requires the check, satisfied with a single challenge even though it does several things at once.
- Checkout — Payment-gated. Store and order payments aren't given a bot check because the payment provider already screens out bots. Adding one here would only create friction, so it's intentionally left off.
- Webhooks & Integrations — Rate-limited. Incoming webhooks and connected apps aren't a place a person clicks, so instead of a challenge they're protected by request limits.
If you'd rather not challenge a particular surface (for example, keep Forms and Scheduling protected but let the Lead Form through), each widget-capable surface has its own toggle on that page. The badge next to it always reflects what's actually happening.
Custom-built websites: wire the widget in first
If your site was built for you inside TrustPager, Bot Protection works as soon as you turn it on. If your site is custom-built (its own code), it needs the bot-protection widget added to that code, or its forms will be rejected once you turn protection on. The settings page includes a copy-paste Installation instructions block (pre-filled with your site's key) that you can hand straight to your web developer or their AI assistant. Ship that snippet first, then turn Bot Protection on.
Turning it off
Flip the master switch off on the same page to stop challenging visitors, or use Remove bot protection to delete the setup entirely. Either way, your forms keep working — they simply stop being verified.
If a form stops accepting submissions
The usual cause is Bot Protection being on for a custom-built site whose code doesn't yet render the widget. Either add the widget using the installation instructions, or turn Bot Protection off until it's wired in.