LocalCan
LocalCan is a behavioral bot-detection system for web forms that skips puzzles and instead analyzes how visitors interact with sign-up fields. It collects pointer movement, typing rhythm, focus transitions, and button-press timing, then converts these signals into plain-English session descriptions. An AI model called Jev reads these descriptions and classifies submissions as human or automated. Agencies embed a lightweight JavaScript collector in client forms and call LocalCan's API to score submissions in real time. Scoring takes about a third of a second and costs less than a hundredth of a cent per check.
LocalCan is a behavioral bot-detection system for web forms, priced at $8 a month on the Solo plan, integrating with OpenRouter, Vercel AI Gateway, Cloudflare Workers AI and TypeSafe. InnovaAI rates it 4 of 10 for agency adoption, best for Project Manager, Developer and Account Executive roles.
Agency Audit
LocalCan protects agency client sign-up and waitlist forms by analyzing behavioral signals (pointer movement, typing rhythm, button press patterns) instead of requiring users to solve puzzles. It converts these signals into plain-English session descriptions, then uses the Jev AI model to classify submissions as human or automated. Agencies adopt it to block bot registrations on client landing pages without degrading user experience. Best fit for teams managing multiple client forms or building custom bot-protection layers into their own products.
3recommended
36/mo
$2,692/mo
Moderate
Illustrative scenario. Not a guarantee. Net capacity is the value of reclaimed time at $75/hr, less the lowest verified paid base plan (flat plan cost is shared). Hours saved come from the service estimate; implementation, taxes, and unprovided usage charges are excluded.
- Project Manager handling bot-spam triage and form resets
- Developer handling client sign-up form protection
- Account Executive handling lead-list quality assurance
- Your agency does not control the HTML or backend of client forms and cannot embed JavaScript collectors or call APIs. LocalCan requires code-level integration; it is not a plug-and-play SaaS dashboard for non-technical users.
- Your team has fewer than 3 client projects with public sign-up forms, or bot spam is not a measurable operational cost. The seat cost and integration effort do not justify adoption for light usage.
- Your clients demand HIPAA, SOC 2, or other compliance certifications that LocalCan does not publicly document. Behavioral data collection and AI scoring may not meet your compliance requirements.
Internal Adoption Path
$8/mo
$8/mo flat plan
36 hr/mo
3 seats × 12 hr each
$2,700/mo
modeled at $75/hr labor rate
$2,692/mo
value − subscription cost
In this model, 3 seats reclaim 36 hours of team time each month. Valued at $75/hr that is $2,700/mo, and after the $8/mo subscription it leaves $2,692/mo of capacity for billable client work.
Illustrative scenario. Not a guarantee. Uses the lowest verified paid base plan. Implementation, taxes, and unprovided usage charges are excluded.
Platform Features
Core capabilities of LocalCan
Behavioral signal collection
Captures pointer movement, typing rhythm, focus transitions, and button-press timing from form interactions without storing user input. Developers embed a lightweight collector in sign-up forms; all behavioral data stays on the client's device until submission.
Plain-English session narratives
Converts raw behavioral measurements into readable descriptions (e.g., 'User moved mouse 47 times, typed at 65 WPM, focused field 3 times'). Jev reads these narratives instead of raw numbers, reducing the risk of adversarial input manipulation.
Jev AI classification model
Scores each session as human or automated based on behavioral patterns. Agencies set confidence thresholds to pass, challenge, or block submissions without requiring users to solve puzzles or complete additional steps.
Proof-of-work fallback for ambiguous sessions
When confidence is borderline, LocalCan can serve a lightweight computational challenge instead of a puzzle. Users see minimal friction; bots face computational cost. Useful for high-value sign-ups where false positives are costly.
Accessible by design
No visual puzzles, no audio challenges, no interaction requirements for users with assistive technology. Screen readers and keyboard-only navigation work without triggering false blocks, improving form completion rates for all users.
Integrations with AI gateways and edge compute
Works with OpenRouter, Vercel AI Gateway, Cloudflare Workers AI, and TypeSafe. Agencies can run Jev scoring at the edge, reducing latency and keeping behavioral data within their infrastructure.
What Makes LocalCan Different
Unique advantages vs similar tools in this niche
Behavioral analysis replaces puzzles, so users never solve challenges
vs Traditional CAPTCHAs like reCAPTCHA that require clicking images or checkboxesThe system measures how a form is filled in, not whether a user can complete a task.
Plain-English stories prevent prompt injection by not passing user-typed content to the AI
vs Other AI-based CAPTCHAs that send raw data to models, risking manipulationThe visitor never writes a word Jev reads; numbers become words from code tables.
Latest Updates
Recent releases and improvements for LocalCan
LocalCan App Release 3.2.0, Introducing Comments
New2026-09-07Snapshots can now collect feedback via pinned comments on any protected Public URL. Includes a new Comments inbox in the app, email notifications, MCP server tools for agents to read and act on feedback, and virtual host target support.
CLI Release 1.2.0, Comments, MCP, and Virtual Host Targets
New2026-09-07CLI gains commands for managing Snapshot comments (list, show, reply, resolve, reopen), new MCP tools for agent-driven review loops, and virtual host header options for quick tunnel commands.
LocalCan App Release 3.1.0, Snapshots on Every Plan
Improvement2026-08-12Snapshots are now available on the Free plan. Snapshot count limits removed; plans now include storage quotas (Free: 150 MB, Solo: 1 GB, Pro: 2 GB, Teams).
Value Equation
Outcome-likelihood-time-effort assessment for LocalCan
Limited agency channel
LocalCan scored below the agency-resellability threshold (agency_fit_score < 50). The Value Equation projects agency-side outcomes, which don't apply to tools without a clear resell pathway.
Contact LocalCanPricing
LocalCan platform cost to your agency
Starts at $8/mo (Solo), scales to $99 one-time (Lifetime License)
Free
- Desktop app + CLI (Mac / Windows / Linux)
- 1 live Public URL (60-min sessions, 1 GB/month)
- Snapshots (150 MB) with Always-on Public URL
- MCP server for AI agents
Solo
- 1 user, 1 device (Mac / Windows / Linux)
- 5 live Public URLs (HTTPS / TCP)
- Snapshots (1 GB) with Always-on Public URL and comments
- Access control (Password, secret link, IP rules)
Pro
- 1 user, 2 devices (Mac / Windows / Linux)
- 10 live Public URLs (HTTPS / TCP)
- Snapshots (2 GB) with Always-on Public URL and comments
- Access control (Password, secret link, IP rules)
Teams
- 3 seats included
- Unlimited Public URLs and team members
- Snapshots (10 GB) with Always-on Public URL and comments
- Team access policies and RBAC user roles
Lifetime License
- License never expires
- 1 device
- 5 Public URLs
- 2 custom domains
Add-ons
Optional extras priced on top of any main plan
No verified white-label program for LocalCan: client-facing delivery runs under the platform's native branding.
Market Intelligence
Offer + scale economics for LocalCan
Limited agency channel
LocalCan scored below the agency-resellability threshold (agency_fit_score < 50). It's a useful tool but not designed for white-labeled or retainer-based reselling, so we don't publish productized offer economics for it.
Contact LocalCanInvestment Decision Framework
Strategic vetting analysis for LocalCan
Situational Fit
Fit depends on your client mix
Buy If
4Your Project Managers or Account Executives report that client sign-up forms are being hammered by automated registrations, inflating lead counts and breaking downstream workflows. Behavioral analysis catches most bots before they reach your CRM.
Your team manages sign-up forms for 5+ client projects per quarter and currently loses 10+ hours per month to manual bot-spam triage or form-reset work. LocalCan's behavioral scoring reduces false-positive blocks that frustrate legitimate users.
Your developers build custom web applications or landing pages and need accessible bot protection without CAPTCHA puzzles. LocalCan integrates with TypeScript, Vercel AI Gateway, and Cloudflare Workers, so it fits existing deployment pipelines.
You operate a design or development agency and want to offer bot protection as a standard feature on client sites without adding third-party puzzle widgets that slow page load or hurt accessibility scores.
Skip If
4Your agency does not control the HTML or backend of client forms and cannot embed JavaScript collectors or call APIs. LocalCan requires code-level integration; it is not a plug-and-play SaaS dashboard for non-technical users.
Your team has fewer than 3 client projects with public sign-up forms, or bot spam is not a measurable operational cost. The seat cost and integration effort do not justify adoption for light usage.
Your clients demand HIPAA, SOC 2, or other compliance certifications that LocalCan does not publicly document. Behavioral data collection and AI scoring may not meet your compliance requirements.
You need real-time alerting or detailed bot-attack dashboards. LocalCan focuses on form-submission classification, not security monitoring or incident response workflows.
Bottom Line
LocalCan protects agency client sign-up and waitlist forms by analyzing behavioral signals (pointer movement, typing rhythm, button press patterns) instead of requiring users to solve puzzles. It converts these signals into plain-English session descriptions, then uses the Jev AI model to classify submissions as human or automated. Agencies adopt it to block bot registrations on client landing pages without degrading user experience. Best fit for teams managing multiple client forms or building custom bot-protection layers into their own products.
Reality Check
LocalCan is a detection layer, not an impenetrable wall; sophisticated bots designed to mimic human behavior may still pass. Implementation requires backend integration (TypeScript or API calls) and assumes your agency controls the form code or has developer bandwidth to embed behavioral collectors.
High effort: requires technical configuration and team training
Academy for LocalCan
Work through it in order: the course for this service first, then the modules behind it.
Course for this service
LocalCan Agency Implementation, Monetizing Bot Detection for Client Forms
Learn how to embed LocalCan's behavioral bot detection into client sign-up and waitlist forms, configure confidence thresholds for pass/challenge/block decisions, and build recurring revenue by managing form security as a retainer service. This course covers API integration, Jev model tuning, and productizing bot detection across multiple client accounts.
Open the courseNo Academy modules are published for this service yet. Browse the full Academy
Why this category matters
The commercial case before the tooling.
Core concepts
The mental model you need to price and scope the work.
- Liability Ceiling FrameworkConcept
Every security retainer carries an implicit liability ceiling: the gap between what an agency promises and what an attack surface can actually guarantee. Agencies that sell "we will keep you secure" absorb unlimited downside; agencies that sell defined detection, response, and remediation scopes cap their exposure while still charging recurring fees. The framework asks three questions before signing: what specific asset is protected, what detection window is promised, and who owns the residual risk when a novel attack path emerges. Cogent's VR-1 model maps attack paths across enterprise infrastructure, which reframes the deliverable from "prevention" to "path visibility," a bounded promise. Sentrint grades repository security and generates fix prompts, giving clients a measurable artifact rather than an assurance. Vaultak monitors and rolls back AI agent actions in production, another bounded scope. California SB 813 and AB 1405, signed September 9, 2026, formalize third-party AI audit expectations, which pushes agencies toward documented, auditable scopes instead of blanket guarantees.
- Blast Radius BudgetingConcept
Blast Radius Budgeting treats security scope as a function of how much damage a single compromised asset can cause, not how many assets exist. An agency protecting a 40-person client with one shared drive has a smaller blast radius than a 12-person client whose AI agents hold production database credentials. The framework asks three questions per engagement: what can be reached from the weakest credential, how fast can it be revoked, and who eats the loss if it is not. That third question is the pricing lever. Runtime governance layers such as Vaultak intercept agent actions and roll them back automatically, which shrinks the radius and justifies a lower liability premium; frontier reasoning models like Cogent map attack paths across the same infrastructure, which expands the billable discovery phase. California SB 813 and AB 1405, signed September 9, 2026, now formalize third-party audit expectations, so documented radius estimates become client-facing evidence rather than internal notes.
- Trust Premium StackConcept
The Trust Premium Stack treats security capability as a pricing lever rather than a cost center. Each layer an agency can credibly demonstrate (device policy enforcement, code scanning, runtime agent governance, incident response) raises the ceiling on what a client will pay for the same deliverable, because the buyer is pricing risk transfer, not hours. The stack only works when every layer is evidenced: a claim without a scan report or a policy dashboard is a discount waiting to happen. Consider the governance gap now opening around AI agents. Vaultak intercepts and can roll back agent actions in production, which gives an agency a concrete artifact to show a client whose automation touches customer data. Pair that with a repository scanner such as Sentrint producing a graded report, and the retainer conversation shifts from rate card to risk coverage. The ceiling is real but finite: no layer justifies promising absolute security.
Decision and risk
How to judge the fit, and the ways it goes wrong.
- Security Tools Rule: Price the Liability Before You Price the RetainerEvaluation Rule
Scope every security engagement as detection, evidence, and response support, and never contract for absolute protection.
- When Client AI Agents Touch Production Systems, Gate Every Action Before You ShipEvaluation Rule
Buy the enforcement layer before the detection layer whenever an agent holds write access to a client system.
- The Absolute-Security Trap: Why Security Tools Collapse Under Agency Retainer PromisesFailure Pattern
- The Scan-Only Trap: Why Security Tools Stall in Agency Delivery After the First ReportFailure Pattern
8 modules selected for LocalCan
Frequently Asked Questions
Answers about pricing, setup, implementation
LocalCan detects bots on web forms by analyzing how visitors interact with them, not by asking them to solve puzzles. It measures pointer movement, typing speed, focus behavior, and button presses, then converts these signals into plain-English descriptions. An AI model called Jev reads these descriptions and decides whether the submission is human or automated. Agencies use it to protect client sign-up and waitlist forms without degrading user experience.
LocalCan offers a free tier with 1 live public URL and 1 GB/month snapshots. Paid plans start at $8/month (Solo, 1 user, 5 public URLs) and scale to $12/month (Pro, 2 devices, 10 public URLs) or $45/month (Teams, 3 seats included, unlimited public URLs and team members). Additional seats cost $15/month each. A one-time Lifetime License is available for $99 USD.
Project Managers reduce time spent triaging spam registrations and resetting compromised sign-up forms. Developers integrate behavioral collection into client landing pages and own the Jev scoring logic. Account Executives report cleaner lead lists and higher form-completion rates to clients. Founders of agencies building custom web applications can offer bot protection as a built-in feature, differentiating their work.
For a Project Manager managing 5+ client forms, LocalCan typically saves 2-4 hours per week by eliminating manual bot-spam triage and form resets. For developers, integration takes 1-2 hours per form, then requires minimal ongoing maintenance. Savings compound as the number of protected forms grows; a team with 10+ active client forms may reclaim 6-8 hours per week.
Integration typically takes 1-2 hours for a developer familiar with TypeScript and backend APIs. LocalCan provides a demo repository and documentation for common frameworks. Once integrated, behavioral collection runs automatically on form submission; no ongoing configuration is needed unless you adjust confidence thresholds or add new forms.
LocalCan integrates with Vercel AI Gateway, Cloudflare Workers AI, OpenRouter, and TypeSafe. It works with any backend that can call an API or run JavaScript. If your agency uses a custom form builder or CMS, you will need developer time to embed the behavioral collector and call the Jev scoring endpoint.
Behavioral data is collected and scored in real time; LocalCan does not store historical session records by default. Once you cancel, new form submissions will not be scored. Existing client forms will need alternative bot protection or will accept all submissions. Check LocalCan's data retention policy for any snapshots or logs you may have enabled.
LocalCan catches most automated scripts and simple bots, but sophisticated bots engineered to replicate human pointer movement and typing patterns may still pass. It is one layer of protection, not a complete barrier. For high-value sign-ups, you can configure LocalCan to serve a proof-of-work challenge for borderline sessions instead of blocking outright.