Dregs vs Castle

Castle is probably the closest competitor Dregs has: both are developer-friendly, self-serve tools with published pricing, aimed at bots and account abuse rather than payments fraud. We respect their work, and they publish useful security research on bots and proxies. The products differ in a way that's easy to state and worth understanding before you pick: Castle scores requests and enforces policies in real time; Dregs scores identities over their whole history and explains every score.

Choose Castle if…

  • Account takeover is a primary threat — Castle has a dedicated ATO score and signals
  • You want inline allow/challenge/deny verdicts in the request path, with a no-code policy engine
  • You want edge blocking via their Cloudflare integration, before traffic hits your app
  • You want a permanent free tier to experiment on

Choose Dregs if…

  • Your problem is slow-burn abuse: trial cycling, duplicate accounts, fake users that look fine per-request
  • You want months of account history behind every score, not days — 90 days on the cheapest plan
  • You want to see exactly why an account scored the way it did before acting on it
  • You want identity linking that goes beyond shared artifacts, to similar names, emails, and behavior

At a glance

Dregs Castle
Built for SaaS teams fighting fake accounts, free trial abuse, and multi-accounting Teams fighting bots, fake accounts, and account takeover with real-time policies
Approach Continuous identity scoring — each account judged over its accumulated events, devices, and relationships Real-time risk scores per request, with a no-code policy engine returning allow/challenge/deny
Scores Four per-identity dimensions: Humanity, Authenticity, Uniqueness, Behavior Three per-threat scores: Account Abuse, Account Takeover, Bot
Scoring transparency Scores are composed directly from named observations, each with a value, confidence, and explanation ML scores with correlated signals alongside; Castle's docs note signals don't deterministically explain the score
Data retention 90 days of event history on the $17 Starter plan, up to 365 days on Advanced 3 days on Free, 7 days on Pro; up to 18 months on Enterprise
Account takeover Not a dedicated focus First-class: dedicated ATO score and signals
Pricing Published, from $17/month per active identity Published, free tier; Pro $200/month per API call; Enterprise from $4,000/month

What Castle does well

Castle's developer experience is strong: self-serve signup, a no-code Cloudflare deployment path, good docs, and a mature policy engine with custom aggregations, rate limiters, and — notably — backtesting of rules against historical data before you enforce them. Its three risk scores (account abuse, account takeover, bot) return in real time with signals attached, and account takeover is a first-class concern in a way it isn't for Dregs. Their research team also publishes useful public work, including a fraudulent email domain tracker and a free proxy-IP database.

Where Dregs takes a different approach

Identity history, not request snapshots

The abuse that hurts SaaS businesses most rarely announces itself in a single request. A freeloader's fourth trial account looks unremarkable per-request; it's damning in context — same device as three prior accounts, same unnaturally efficient first session, a disposable email this time. Dregs keeps that context: every account is scored across Humanity, Authenticity, Uniqueness, and Behavior using its accumulated events and devices, re-scored within seconds of new activity. Retention makes this concrete: Castle's published plans keep 3 days of data on Free and 7 days on Pro (18 months is an Enterprise feature, from $4,000/month), while Dregs' $17 Starter plan keeps 90 days of event history and Advanced keeps a year. Longstanding abuse patterns simply aren't visible in a 7-day window.

Scores that explain themselves

Castle attaches named signals to its scores, which is genuinely useful. However, its own documentation notes that signals "do not deterministically predict the numerical risk score"; they're correlated evidence beside an ML score. Dregs is built the other way around: each score is the weighted composition of its analyzer observations, so every number decomposes exactly into the observations that produced it, each with a value, confidence, and plain-English explanation. When you're deciding whether to shadow-ban a paying customer's account, "the score is high and here are some correlated signals" and "here are the four observations that made the score high" are different levels of confidence. Connecting the signals to the score is how you keep false positives from turning into support fires.

Linking beyond shared artifacts

Castle documents multi-accounting detection through shared artifacts: same device, same IP, same payment method. Dregs links identities through those same artifacts and through similarity — similar names, similar email patterns, shared sessions, and behavioral resemblance — with every link labeled by the signal that made it. Serial abusers rotate devices and IPs; their habits are harder to rotate.

Castle pricing vs Dregs pricing

Dregs pricing

Entry plan
$17/month (100 active identities)
Mid tier
$177/month (5,000 identities)
Top published tier
$377/month (10,000 identities)
Event history
90–365 days, by plan
Metering
Per active identity
Free trial
14 days, no credit card

Castle pricing

Free tier
$0 (1,000 API calls, 3-day retention)
Pro plan
$200/month (100k calls, then $0.002/call)
Pro data retention
7 days
Enterprise
From $4,000/month (up to 18-month retention)
Metering
Per API call
Free trial
Permanent free tier

Castle pricing facts checked July 23, 2026 against https://castle.io/pricing. Dregs pricing is current at dregs.com/pricing. If you spot something out of date, email dregs@dregs.com and we'll correct it.

The metering models suit different shapes of traffic: Castle charges per API call, Dregs per active identity with unlimited events per identity. If your users generate many tracked events per session, per-identity pricing tends to be the more predictable bill; if you only score a handful of critical moments per user, per-call can be cheaper. Run both calculators against your real traffic.

The bottom line

This is the rare comparison where "both are good" is just true. Castle is a strong choice for real-time policy enforcement and account takeover. Dregs is the stronger choice for catching fake and duplicate accounts over time, with scores you can open up and months of history on every plan — the shape of problems like free trial abuse and duplicate accounts. If you're also weighing the enterprise platforms, see Dregs vs Sift and Dregs vs SEON.

Frequently Asked Questions

Q: Is Dregs a good Castle alternative?

A: They're the two most directly comparable tools on this site, and both are self-serve with published pricing. Castle is stronger if account takeover protection and inline allow/challenge/deny policy decisions are your priority. Dregs is stronger if you want transparent, explainable identity scoring over months of account history — especially for slow-burn abuse like trial cycling and multi-accounting.

Q: How much does Castle cost?

A: As of July 2026, Castle has a free tier (1,000 API calls/month with 3-day data retention), a Pro plan at $200/month for 100,000 API calls (7-day retention), and Enterprise plans starting around $4,000/month. Dregs starts at $17/month with 90-day event history included.

Q: What is the main difference between Dregs and Castle?

A: Both detect bots and account abuse. Castle is request-oriented: score this request now, apply a policy, return allow/challenge/deny. Dregs is identity-oriented: accumulate everything an account does over weeks or months, score it on four dimensions within seconds of new activity, and show the exact observations behind every score. Castle's self-serve plans keep 3–7 days of data; Dregs' cheapest plan keeps 90 days.

Q: Does Dregs protect against account takeover like Castle?

A: Account takeover isn't Dregs' focus. Dregs detects credential-stuffing patterns as part of its behavioral analysis, but it has no dedicated ATO score. If ATO is your primary threat, Castle is the better fit; if fake and duplicate accounts are, Dregs is.

Judge accounts on their history, not one request.

Install Dregs in minutes and get transparent Humanity, Authenticity, Uniqueness, and Behavior scores on every account — with 90 days of event history from the cheapest plan. 14-day free trial, no credit card.

Schedule a Demo