Castle is probably the closest competitor Dregs has: both are developer-friendly, self-serve tools with published pricing, aimed at bots and account abuse rather than payments fraud. We respect their work, and they publish useful security research on bots and proxies. The products differ in a way that's easy to state and worth understanding before you pick: Castle scores requests and enforces policies in real time; Dregs scores identities over their whole history and explains every score.
| Dregs | Castle | |
|---|---|---|
| Built for | SaaS teams fighting fake accounts, free trial abuse, and multi-accounting | Teams fighting bots, fake accounts, and account takeover with real-time policies |
| Approach | Continuous identity scoring — each account judged over its accumulated events, devices, and relationships | Real-time risk scores per request, with a no-code policy engine returning allow/challenge/deny |
| Scores | Four per-identity dimensions: Humanity, Authenticity, Uniqueness, Behavior | Three per-threat scores: Account Abuse, Account Takeover, Bot |
| Scoring transparency | Scores are composed directly from named observations, each with a value, confidence, and explanation | ML scores with correlated signals alongside; Castle's docs note signals don't deterministically explain the score |
| Data retention | 90 days of event history on the $17 Starter plan, up to 365 days on Advanced | 3 days on Free, 7 days on Pro; up to 18 months on Enterprise |
| Account takeover | Not a dedicated focus | First-class: dedicated ATO score and signals |
| Pricing | Published, from $17/month per active identity | Published, free tier; Pro $200/month per API call; Enterprise from $4,000/month |
Castle's developer experience is strong: self-serve signup, a no-code Cloudflare deployment path, good docs, and a mature policy engine with custom aggregations, rate limiters, and — notably — backtesting of rules against historical data before you enforce them. Its three risk scores (account abuse, account takeover, bot) return in real time with signals attached, and account takeover is a first-class concern in a way it isn't for Dregs. Their research team also publishes useful public work, including a fraudulent email domain tracker and a free proxy-IP database.
The abuse that hurts SaaS businesses most rarely announces itself in a single request. A freeloader's fourth trial account looks unremarkable per-request; it's damning in context — same device as three prior accounts, same unnaturally efficient first session, a disposable email this time. Dregs keeps that context: every account is scored across Humanity, Authenticity, Uniqueness, and Behavior using its accumulated events and devices, re-scored within seconds of new activity. Retention makes this concrete: Castle's published plans keep 3 days of data on Free and 7 days on Pro (18 months is an Enterprise feature, from $4,000/month), while Dregs' $17 Starter plan keeps 90 days of event history and Advanced keeps a year. Longstanding abuse patterns simply aren't visible in a 7-day window.
Castle attaches named signals to its scores, which is genuinely useful. However, its own documentation notes that signals "do not deterministically predict the numerical risk score"; they're correlated evidence beside an ML score. Dregs is built the other way around: each score is the weighted composition of its analyzer observations, so every number decomposes exactly into the observations that produced it, each with a value, confidence, and plain-English explanation. When you're deciding whether to shadow-ban a paying customer's account, "the score is high and here are some correlated signals" and "here are the four observations that made the score high" are different levels of confidence. Connecting the signals to the score is how you keep false positives from turning into support fires.
Castle documents multi-accounting detection through shared artifacts: same device, same IP, same payment method. Dregs links identities through those same artifacts and through similarity — similar names, similar email patterns, shared sessions, and behavioral resemblance — with every link labeled by the signal that made it. Serial abusers rotate devices and IPs; their habits are harder to rotate.
The metering models suit different shapes of traffic: Castle charges per API call, Dregs per active identity with unlimited events per identity. If your users generate many tracked events per session, per-identity pricing tends to be the more predictable bill; if you only score a handful of critical moments per user, per-call can be cheaper. Run both calculators against your real traffic.
This is the rare comparison where "both are good" is just true. Castle is a strong choice for real-time policy enforcement and account takeover. Dregs is the stronger choice for catching fake and duplicate accounts over time, with scores you can open up and months of history on every plan — the shape of problems like free trial abuse and duplicate accounts. If you're also weighing the enterprise platforms, see Dregs vs Sift and Dregs vs SEON.
A: They're the two most directly comparable tools on this site, and both are self-serve with published pricing. Castle is stronger if account takeover protection and inline allow/challenge/deny policy decisions are your priority. Dregs is stronger if you want transparent, explainable identity scoring over months of account history — especially for slow-burn abuse like trial cycling and multi-accounting.
A: As of July 2026, Castle has a free tier (1,000 API calls/month with 3-day data retention), a Pro plan at $200/month for 100,000 API calls (7-day retention), and Enterprise plans starting around $4,000/month. Dregs starts at $17/month with 90-day event history included.
A: Both detect bots and account abuse. Castle is request-oriented: score this request now, apply a policy, return allow/challenge/deny. Dregs is identity-oriented: accumulate everything an account does over weeks or months, score it on four dimensions within seconds of new activity, and show the exact observations behind every score. Castle's self-serve plans keep 3–7 days of data; Dregs' cheapest plan keeps 90 days.
A: Account takeover isn't Dregs' focus. Dregs detects credential-stuffing patterns as part of its behavioral analysis, but it has no dedicated ATO score. If ATO is your primary threat, Castle is the better fit; if fake and duplicate accounts are, Dregs is.
Install Dregs in minutes and get transparent Humanity, Authenticity, Uniqueness, and Behavior scores on every account — with 90 days of event history from the cheapest plan. 14-day free trial, no credit card.
Schedule a Demo