As MCP and agentic commerce go live, new capabilities deliver behavioral detection and friction-free human verification across web, mobile, API, and agentic AI channels
SANTA CLARA, Calif. — June 23, 2026 — Cequence Security, a pioneer in application security, today announced the launch of Intent Graph and Biometric Check, two new capabilities that extend the behavioral architecture Cequence has built on since inception. Together, they give enterprises bot defense that works across web, mobile, API, and agentic AI traffic, without depending on the client-side signals that sophisticated bots have learned to defeat.
The architectural divide in bot defense is now unavoidable. While traditional bot defense relies on browser signals such as CAPTCHAs, JavaScript puzzles, device and machine fingerprints, and TLS characteristics, attackers have industrialized workarounds. Modern proxy providers now run real browsers that solve CAPTCHAs, pass puzzle runtimes, and present clean fingerprints at scale, making adversarial automation indistinguishable from real customer sessions.
The agentic shift has made this client-side approach structurally unworkable for several reasons: AI agents operating on behalf of real customers often run in headless environments where puzzle runtimes don’t execute at all; MCP-based agents don’t use browsers, so client-side signals are simply absent; and fast-moving AI-forward companies ship products daily or weekly and can’t afford the time and resource penalty imposed by SDK instrumentation.
Automated traffic now accounts for more than half of all web requests globally, according to Cloudflare, and native agentic commerce is already live across ChatGPT, Amazon, Google's Agent E-commerce Protocol, Visa's agentic commerce standard, and Stripe's payment primitives.
“Client-side bot protection wasn't architected for AI-driven traffic, and enterprises are already feeling the consequences of this as automated traffic exceeds that from humans,” said Ameya Talwalkar, CEO and Co-Founder of Cequence.
Intent Graph: Behavioral detection across every channel
Intent Graph builds a behavioral model specific to each application, not a generic fingerprint, but a living map of how real users navigate that particular flow. Because the model is application-specific and behavior travels with the client, one detection layer covers the full surface across web, mobile, API, and agentic AI including MCP.
What makes Intent Graph different from behavioral fingerprinting is what happens when the model needs to change. Security teams can adjust which behavioral vectors feed into detection and ultimately into mitigation without a code change or a ticket to engineering. When an attack emerges or the traffic profile shifts, the algorithm updates in minutes.
In one recent enterprise deployment, adversaries retooled their attack more than ten times over two days using virtual browsers and rotating proxy networks. Cequence’s Intent Graph blocked every iteration, without any CAPTCHA, puzzle, or client challenge being shown to legitimate customers.
Biometric Check: Secure verification that users are already familiar with
Biometric Check replaces CAPTCHAs, puzzles, SMS codes, and email verification with hardware-bound cryptographic attestation via a device’s Secure Enclave. When bot detection flags a session outside a configurable, application-specific confidence threshold, the user completes a familiar biometric interaction — Touch ID, Face ID, Windows Hello — and the device returns signed proof that a real person on a registered device completed the action.
The same checkpoint logic extends to AI agents. For low-risk actions, agents operate freely. For high-stakes, irreversible actions such as wire transfers, record retrievals, or contract modifications, Biometric Check inserts a human-in-the-loop gate at the time of the action rather than at the front door.
Intent Graph and Biometric Check are immediately available to Cequence customers as part of the Cequence platform.
About Cequence Security
Cequence protects the applications and data that power enterprises in the agentic era. More than a decade of bot defense and API security experience has established Cequence as the leader of safe and secure agentic AI adoption. The Cequence platform delivers deep insight into user, entity, and agent behavior, enabling organizations to secure and control agentic AI interactions while protecting against bad actors and rogue agents. Cequence delivers value in minutes rather than days or weeks with a highly scalable, no-code approach. Trusted by the largest and most demanding private and public sector organizations, Cequence protects more than 10 billion daily API interactions and 4 billion user accounts. To learn more, visit
www.cequence.ai.
Media Contacts
Katrina Porter
Corporate Communications
press@cequence.ai
ICR for Cequence Security
Cequence@icrinc.com