Dregs vs Castle

Castle is probably the closest competitor Dregs has: both are developer-friendly, self-serve tools with published pricing, aimed at bots and account abuse rather than payments fraud. We respect their work, and they publish useful security research on bots and proxies. The products differ in a way that's easy to state and worth understanding before you pick: Castle scores requests and enforces policies in real time; Dregs scores identities over their whole history and explains every score.

Choose Castle if…

  • You want inline allow/challenge/deny verdicts in the request path, including a real-time ATO score you can enforce on the login itself, with a no-code policy engine
  • You want to backtest a rule against historical data before you enforce it
  • You want edge blocking via their Cloudflare integration, before traffic hits your app
  • You want a permanent free tier to experiment on

Choose Dregs if…

  • Your problem is slow-burn abuse: trial cycling, duplicate accounts, fake users that look fine per-request
  • You want suspected takeovers escalated automatically with the evidence attached, without writing a policy first
  • You want months of account history behind every score, not days (90 days on the cheapest plan)
  • You want to see exactly why an account scored the way it did before acting on it
  • You want identity linking that goes beyond shared artifacts, to similar names, emails, and behavior

At a glance

Dregs Castle
Built for SaaS teams fighting fake accounts, free trial abuse, and multi-accounting Teams fighting bots, fake accounts, and account takeover with real-time policies
Approach Continuous identity scoring: each account judged over its accumulated events, devices, and relationships Real-time risk scores per request, with a no-code policy engine returning allow/challenge/deny
Scores Four per-identity dimensions: Humanity, Authenticity, Uniqueness, Behavior Three per-threat scores: Account Abuse, Account Takeover, Bot
Scoring transparency Scores are composed directly from named observations, each with a value, confidence, and explanation ML scores with correlated signals alongside; Castle's docs note signals don't deterministically explain the score
Data retention 90 days of event history on the $17 Starter plan, up to 365 days on Advanced 3 days on Free, 7 days on Pro; up to 18 months on Enterprise
Account takeover Detected from evidence: new device plus unusual context plus credential changes raises a badge and a critical escalation, on by default First-class: dedicated ATO score returned inline, enforceable in the request path
Pricing Published, from $17/month per active identity Published, free tier; Pro $200/month per API call; Enterprise from $4,000/month

What Castle does well

Castle's developer experience is strong: self-serve signup, a no-code Cloudflare deployment path, good docs, and a mature policy engine with custom aggregations, rate limiters, and, notably, backtesting of rules against historical data before you enforce them. Its three risk scores (account abuse, account takeover, bot) return in real time with signals attached, and the ATO score is enforceable inline in a way Dregs's is not: Dregs raises a takeover escalation from accumulated evidence rather than a verdict on the request in front of you. Their research team also publishes useful public work, including a fraudulent email domain tracker and a free proxy-IP database.

Where Dregs takes a different approach

Identity history, not request snapshots

The abuse that hurts SaaS businesses most rarely announces itself in a single request. A freeloader's fourth trial account looks unremarkable per-request; it's damning in context: same device as three prior accounts, same unnaturally efficient first session, a disposable email this time. Dregs keeps that context: every account is scored across Humanity, Authenticity, Uniqueness, and Behavior using its accumulated events and devices, re-scored moments after new activity. Retention makes this concrete: Castle's published plans keep 3 days of data on Free and 7 days on Pro (18 months is an Enterprise feature, from $4,000/month), while Dregs' $17 Starter plan keeps 90 days of event history and Advanced keeps a year. Longstanding abuse patterns simply aren't visible in a 7-day window.

Scores that explain themselves

Castle attaches named signals to its scores, which is genuinely useful. However, its own documentation notes that signals "do not deterministically predict the numerical risk score"; they're correlated evidence beside an ML score. Dregs is built the other way around: each score is the weighted composition of its analyzer observations, so every number decomposes exactly into the observations that produced it, each with a value, confidence, and plain-English explanation. When you're deciding whether to shadow-ban a paying customer's account, "the score is high and here are some correlated signals" and "here are the four observations that made the score high" are different levels of confidence. Connecting the signals to the score is how you keep false positives from turning into support fires, and how you end up doing less manual review.

Linking beyond shared artifacts

Castle documents multi-accounting detection through shared artifacts: same device, same IP, same payment method. Dregs links identities through those same artifacts and through similarity (similar names, similar email patterns, shared sessions, and behavioral resemblance), with every link labeled by the signal that made it. Serial abusers rotate devices and IPs; their habits are harder to rotate.

Castle pricing vs Dregs pricing

Dregs pricing

Entry plan
$17/month (100 active identities)
Mid tier
$177/month (5,000 identities)
Top published tier
$377/month (10,000 identities)
Event history
90–365 days, by plan
Metering
Per active identity
Free trial
14 days, no credit card

Castle pricing

Free tier
$0 (1,000 API calls, 3-day retention)
Pro plan
$200/month (100k calls, then $0.002/call)
Pro data retention
7 days
Enterprise
From $4,000/month (up to 18-month retention)
Metering
Per API call
Free trial
Permanent free tier

Castle pricing facts checked July 23, 2026 against https://castle.io/pricing. Dregs pricing is current at dregs.com/pricing. If you spot something out of date, email dregs@dregs.com and we'll correct it.

The metering models suit different shapes of traffic: Castle charges per API call, Dregs per active identity with unlimited events per identity. If your users generate many tracked events per session, per-identity pricing tends to be the more predictable bill; if you only score a handful of critical moments per user, per-call can be cheaper. Run both calculators against your real traffic.

The bottom line

This is the rare comparison where "both are good" is just true. Castle is a strong choice for real-time policy enforcement and for stopping a suspicious login in the request path. Dregs is the stronger choice for catching fake and duplicate accounts over time, and for account takeovers surfaced from accumulated evidence, with scores you can open up and months of history on every plan. That's the shape of problems like free trial abuse and duplicate accounts. If you're also weighing the enterprise platforms, see Dregs vs Sift and Dregs vs SEON.

Frequently Asked Questions

Q: Is Dregs a good Castle alternative?

A: They're the two most directly comparable tools on this site, and both are self-serve with published pricing. Castle is stronger if you need inline allow/challenge/deny policy decisions, including blocking a suspicious login in the request path. Dregs is stronger if you want transparent, explainable identity scoring over months of account history, especially for slow-burn abuse like trial cycling and multi-accounting. Both detect account takeover; they differ on whether the verdict lands in the request or as an escalation with the evidence attached.

Q: How much does Castle cost?

A: As of July 2026, Castle has a free tier (1,000 API calls/month with 3-day data retention), a Pro plan at $200/month for 100,000 API calls (7-day retention), and Enterprise plans starting around $4,000/month. Dregs starts at $17/month with 90-day event history included.

Q: What is the main difference between Dregs and Castle?

A: Both detect bots and account abuse. Castle is request-oriented: score this request now, apply a policy, return allow/challenge/deny. Dregs is identity-oriented: accumulate everything an account does over weeks or months, score it on four dimensions almost instantly after new activity, and show the exact observations behind every score. Castle's self-serve plans keep 3–7 days of data; Dregs' cheapest plan keeps 90 days.

Q: Does Dregs protect against account takeover like Castle?

A: Both do, at different moments. Castle scores ATO risk inline on the request, so its policy engine can challenge or deny the login before a session exists. Dregs watches what happens around and after the login: a device the account has never used, unusual network and geolocation context, and credential changes close together raise an "Account Takeover Suspected" badge and open a critical escalation with the evidence attached, on by default for every customer. If you need to block the login itself in the request path, Castle is built for that. If you want takeovers caught from accumulated evidence and escalated to your team or your webhook, Dregs does that without configuration.

Judge accounts on their history, not one request.

Install Dregs in minutes and get transparent Humanity, Authenticity, Uniqueness, and Behavior scores on every account, with 90 days of event history from the cheapest plan. 14-day free trial, no credit card.

Schedule a Demo