A shoe goes on sale at noon. By 12:01, the sizes are gone. Some buyers never saw the page; some did, but were beaten by software that could check inventory and fill a cart faster than fingers could move. To the retailer, the site looks busy. To the disappointed customer, it looks unfair. To PerimeterX, it looked like a security problem with a surprisingly ordinary disguise: the shopper.
Founded in 2014 by Omri Iluz, Ido Safruti and Ophir Ashkenazi, PerimeterX built software to tell human activity from automated abuse on websites, mobile apps and APIs. Its first signature product, Bot Defender, watched patterns of behavior and assigned risk to requests. The aim was to interrupt card testing, account takeover, scraping and hoarding before a store mistook them for business as usual.
- PerimeterX sold application protection as a service to businesses with valuable online transactions.
- Bot Defender targeted automated abuse; Code Defender and Page Defender broadened the watch to the browser page itself.
- Retail was its core market, with financial services, travel and hospitality also in view.
- In 2022 it merged with HUMAN Security, which now carries the combined business.
A crowded store can still be empty
The particular insult of a bot attack is that it can imitate success. A login request may look like a customer returning. A checkout attempt may look like a purchase. Inventory can disappear into carts without a sale. Even analytics may flatter the business with traffic that has no intention of buying. PerimeterX sold a second opinion on that activity, using behavioral and device signals rather than relying only on blunt blocks of suspect addresses.
That distinction mattered most where a false positive has a price. Challenge every visitor and the good customers leave. Let every visitor through and the attackers set the terms. Bot Defender sat between those bad choices: collect signals, score the request, then allow, challenge or block according to risk. Its integrations reached applications and edge infrastructure; Fastly, for example, documented an integration that placed PerimeterX protection into a Fastly-served site.
Collect device, browser and request behavior around the app.
Look for automation where a human journey should be.
Allow, challenge or block according to the evidence.
By 2019 the company said Bot Defender was used by brands including Puma, Skyscanner, Zillow and Wix. These are different businesses, but each has something a script can exploit: scarce stock, accounts, listings or data. PerimeterX’s expertise lay in the messy middle between security and commerce, where protection has to preserve the transaction it exists to defend.
Then the page became the suspect
The first product solved only part of the problem. Iluz said customers who had adopted Bot Defender asked the company to protect them from other expanding threats. PerimeterX followed that demand into the browser. Code Defender addressed risky third-party JavaScript and digital skimming. In August 2019, PerimeterX bought the Israeli startup PageSeal and remade its browser-extension protection as Page Defender, which watched for unwanted changes such as ad injection and coupon overlays. The price of that acquisition was not disclosed. A checkout page can be perfectly legitimate when it leaves the server and still become a trap after outside code runs in a customer’s browser.

The change was a practical one, not a neat category exercise. Bot Defender examined who was using the store. Code Defender examined code running inside it. Page Defender examined what the customer actually saw. Together they made a fuller account of a digital visit. Bot scoring alone could not catch a malicious script already running in the customer’s browser; browser monitoring, in turn, could not replace checks on automated logins and inventory abuse. The company’s 2021 financing announcement named all three as service products, and described customers using them in combinations: a beauty retailer blocking carding with Bot Defender while using Code Defender against Magecart-style theft.
“After adopting PX Bot Defender ... our customers asked us to help secure their assets from additional expanding threats.”Omri Iluz, 2019
The numbers, properly counted
PerimeterX said that in 2020 its platform protected more than $100 billion in ecommerce revenue and processed more than two billion login requests a day. Those are company-reported operating measures, not money earned by PerimeterX. They convey the scale required of a product positioned in front of high-volume retail traffic. In February 2021, AllianceBernstein led a $57 million growth financing round. The company said it had raised $144 million in total and planned to expand beyond its retail base, particularly into financial services and markets in Europe and Asia-Pacific.
The first two figures were reported by PerimeterX for its platform; the third is its announced financing round.
The business model followed the enterprise security playbook: integrate the service into a site, app, API or edge stack, then pay for ongoing protection. A public Microsoft Marketplace listing describes Bot Defender as a contact-sales, private-offer purchase. That tells a buyer the commercial shape, though it gives no reliable sticker price. For a retailer, the real calculation would be how much account abuse, failed checkout traffic and friction imposed on legitimate shoppers the system could reduce.
Two maps of the same internet
In July 2022, PerimeterX merged with HUMAN Security, formerly White Ops. PerimeterX had focused heavily on ecommerce and account protection; HUMAN had deep exposure to advertising and media fraud. The companies described those specialisms as complementary. The combined business would operate under the HUMAN name, with Iluz becoming president and general manager of enterprise security. The merger terms were not disclosed.
The announcement put the combined company at more than 500 customers, more than 450 employees and over $100 million in annual recurring revenue. Those were merger totals, not a late-stage snapshot of PerimeterX alone. It is an important distinction: the numbers describe what the two maps looked like laid over one another.
Forrester’s 2022 assessment captured the fit in plainer terms: PerimeterX suited ecommerce, travel, hospitality and financial-services buyers, while HUMAN offered strength in both marketing and security bot attacks. A retailer may care about a stolen account and a fake ad click for different reasons. The attacker, however, can move between both. The merger made a bet that defenses would be better with a wider view of that journey.
There is a useful lesson in PerimeterX’s path. Start with one expensive, visible problem; put the product in the flow where it happens; listen when customers point to the next failure nearby. Bot defense opened the door. Browser-side threats changed the brief. The company that began by asking whether the shopper was real ended by asking whether the whole shopping experience was.