Everything TrueVisit does today
Five groups, in the order a new site actually needs them. Every line below is something a signed-up site can use right now; what is not live yet is on the roadmap further down, clearly marked.
Verify every visit
Four independent layers score every visit and land it in one of three classes, never a silent yes or no.
About 120 signatures, updated weekly
The user agent is checked against a signature list covering AI crawlers, search engines, SEO tools, monitoring services, HTTP libraries, headless browsers, social preview bots, and security scanners, plus a referrer spam blocklist.
Roughly 13,500 data center IP ranges
Crawler claims are checked against published ranges from OpenAI, Google, Microsoft, Perplexity, and DuckDuckGo, plus around 13,500 data center ranges. A Googlebot user agent from an address Google does not own is impersonation, and the reason string says so.
In-browser behavior
Whether a pointer ever moved, whether a real viewport exists, whether the automation flag is announced, and whether the tracker ran at all.
Session and source shape
Instant bounces, one-page sessions, and request rates no person could produce, plus unusual geographic concentration or device mix per traffic source.
Three classes, every verdict with a reason
Human, suspected bot, or confirmed bot, never a flat filtered/not-filtered binary. Every verdict stores a plain-English reason and a machine-readable reason code, so a customer can group traffic by why it was flagged, not just that it was.
All / Humans only / Bots only
One toggle that changes what the underlying query ranks by, not just what is rendered, so a bots-only screen is never a top-fifty list wearing a different heading.
See what no JavaScript tracker can
GPTBot, ClaudeBot, and PerplexityBot never run a browser script. A JavaScript-only tracker cannot see them at all.
Server-side collection (Events API)
The only way to record a client that never runs JavaScript. A site pastes one API key and gets a step-by-step guide with WordPress, plain PHP, Node.js, Python, and curl snippets, plus a live install check.
AI referrals, kept separate on purpose
Humans arriving from ChatGPT, Gemini, Perplexity, Copilot, or Claude are detected and recovered (including referrer-less arrivals, labeled suspected rather than silently counted) across 11 assistants. An AI crawler reading a page and an AI sending a reader are different facts and never share a chart.
A warning when a cache is hiding data
If a site's server-side count runs suspiciously low against its browser pageviews, the dashboard says so and names both likely causes: a full-page cache, or a partial install. A JavaScript-only site is told separately that AI crawlers aren't being counted at all.
Attribute and act
Bad traffic gets an address, not a percentage.
Segmented by source, campaign, sub ID, placement, and creative
Every verdict is broken down by the fields a media buyer already tracks, with tracker tokens, sub IDs, and click IDs captured automatically for every common ad network alias.
A blacklist export per field, plus an evidence CSV
One plain list per field (zone, placement, sub ID, campaign, source) for pasting into an ad network block box, and a CSV carrying the evidence behind each verdict for a refund argument. Every identifier is judged on all of its traffic, never its worst row.
Traffic quality score per source, trended
A 0 to 100 score with confirmed bots at full weight and suspected at half, three bands rather than two, and a first-half against second-half trend. A source under 30 events is left unscored rather than given a number that cannot be defended.
GIVT / SIVT split and the publisher risk score
General and sophisticated invalid traffic reported separately, in the publisher's own vocabulary, plus a three-band IVT risk score driven by SIVT share alone, with an early warning from a rising trend even inside the low band.
Everyday reporting
The screens a site checks every day, not just the ones built for an argument with an ad network.
Realtime, sources, and geo
The last 30 minutes in the site’s own timezone, referrer and UTM sources with channel classification, and country-level geography.
Device, browser, and OS
Bots are reported as their own device type, so they can never skew the human mix.
Automatic outbound link and form events
Captured without any setup, since the two things this audience needs measured are the two they are least likely to instrument by hand. Opt out with one data attribute.
A per-site tracker file, toggled from the dashboard
Outbound clicks, form submits, SPA routing, the engagement heartbeat, and excluded paths are switched on or off without editing the site’s theme.
A proper timezone picker, and site lifecycle controls
All 418 IANA zones in a grouped dropdown, auto-detected and editable. Archiving a site is instant and reversible; deleting one erases every table it touched and asks for the domain to be typed first.
How billing works
Only the traffic a customer is paying to see counts toward the bill.
Google sign-in only
No password exists anywhere in the schema. A 30-day trial starts automatically on first sign-in, no credit card required.
Only human pageviews are billed
Bots and AI crawlers are detected, stored, and reported in full, and never counted toward the plan. A separate, clearly labeled ceiling on total events protects the infrastructure without ever forcing an upgrade because of a bot flood.
Total traffic and billable pageviews, side by side
The dashboard shows both numbers next to each other, so the difference between them is never hidden.
On the roadmap
Not live yet. "Built" means the code is deployed and only waiting on a credential; everything else is a proposed idea for the same two customers this product already serves, not started.
Bot-spike email alerts
A 15-minute worker check compares a site’s current hour to its own 7-day baseline and emails the owner when it spikes. Code-complete and deployed; silent until the Gmail SMTP credentials are filled in.
Weekly digest email
Pageviews, bot rate against last week, publisher risk, and the worst-scoring source, once a week, per site. Same status as the bot-spike alert: built, waiting on the same SMTP credential.
Revenue-weighted quality score
Connect a postback from the affiliate network or an AdSense revenue figure, so the existing quality score can say a zone is both bot-heavy and the one actually costing money, not bot share alone.
Direct ad-network blacklist push
One-click submission to networks with an API, so the evidence export becomes an already-blocked source instead of a list to paste by hand.
Slack and Telegram alerts
The same bot-spike and digest content, delivered where a media buyer actually watches for it, once email is live.
Custom domain proxy
A first-party subdomain for the tracker, so an ad blocker never sees a third-party request. Fathom’s signature feature, already on this product’s own roadmap.
Scheduled report export
CSV or PDF, emailed or webhooked on a cadence, for an agency reporting to a client or a publisher’s own recordkeeping ahead of an ad network audit.
A public "verified traffic" badge
An embeddable snippet showing a site’s real-vs-bot share without exposing the underlying data, a trust signal no competitor offers today.
Team seats
Invite an agency teammate or a publisher’s ops person into a site’s dashboard without sharing the Google login.
Natural-language questions over your data
"Which zone got worse this week?" answered in plain English, reasoning over the same attribution and quality data already on screen. Blocked only on an LLM API key.
Root-cause explanations
"Zone 4471 went 61 percent suspected bot on Tuesday" written automatically, tied to the exact attribution row that explains it.
Google Search Console integration
Pairs organic queries with the AI referral story: which of a site’s search clicks turned out to be real.
Zapier and Make integration
Push a blacklist event or a risk-score change into whatever workflow tool a buyer or agency already runs.
An MCP server and CLI
Read access to a site’s own verification data from Claude Code, Cursor, or any MCP-speaking agent, built on the Events API infrastructure that already exists.