bleap.
HOW THE ESTIMATES WORK

Show us the clues.

Bleap measures interactions from browsers that load its script and allow collection. It looks for combinations of behavior that may suggest automated control. It does not identify the person behind a session or prove which model they use.

Three separate questions

MeasureWhat it means
Automation estimateA heuristic estimate of automated browser control. Ordinary scripts and testing tools count as automation.
AI estimateAn experimental estimate of AI involvement from the available signals. It is not calibrated against a representative population.
Verified AI identityNo agent identity verification is currently implemented. A behavioral estimate never becomes verified identity.

Signals are shown with their explanations

Repeated straight pointer paths, clicks near the center of targets, unusually regular timing, and browser automation indicators can support an automation assessment. Curved, varied pointer movement can support a human-like assessment. The rules require sufficient samples and combine related signals conservatively.

A pasted field is context only. Touch, keyboard navigation, assistive technology, and missing mouse events are not proof of AI. An agent-like user-agent string is an unverified declaration and can be imitated.

What the percentages mean

The engine starts with heuristic assumptions and adjusts separate automation and AI odds using observed signals. It caps confidence and avoids counting several related signals as independent evidence. These choices make the score inspectable; they do not establish measured accuracy.

Estimated AI share is the average AI score among scored sessions in the selected period. Coverage tells you what fraction had enough evidence to receive a score. Unscored visits are excluded from that estimate and remain visible in the session totals. This number is not the proven share of all your website traffic.

What remains unknown

Many agents can use the same browser executor, and one model can operate through several executors. A movement pattern may identify an implementation detail rather than Claude or Codex. Bleap therefore does not assign a verified provider from behavior.

Agents that use APIs, fetch pages without running JavaScript, disable telemetry, or never reach your site are outside this measurement. Browser extensions, remote desktops, network delays, website layouts, and accessibility tools may affect the observed patterns.

How to use the results

Compare observed session cohorts, inspect surprising patterns, and investigate where automated browsing encounters friction. Treat individual scores as clues for analysis. Do not use them to make access, fraud, employment, credit, or other consequential decisions about people.

The score version is included with each session. Validation must hold out complete websites, devices, tasks, and agent executors; random event splits would overstate generalization. Until a representative evaluation is published, we make no detection-accuracy or provider-attribution guarantee.

Found a misleading signal?

Send us a report with the score version, signal, and a description of the interaction. Avoid sharing personal visitor data. We can investigate the rule; no automatic provider attribution or appeal outcome is promised.