Fraud, Bot & Spam Prevention

Grow provides a multi-layered approach to fraud prevention. It combines rate limiting, identity resolution, access controls, and secure reward handling to deliver an enterprise-ready solution.

Entry controls and rate limiting

Grow allows you to control how many times a participant can enter an experience, either by limiting entries per user or by setting a global cap on total entries. This helps prevent duplicate submissions and limits exposure to large-scale abuse.

Grow enforces IP-based rate limiting by default, restricting the number of requests from a single IP address (typically 1 request per second and 5 per minute). These thresholds help mitigate high-volume automated attacks and spam submissions and can be adjusted on a per-account basis, if required.

IP blocking and monitoring

If suspicious activity is identified, specific IP addresses can be blocked at the account level. Blocked IP addresses may still be able to access or view an experience, but they will be prevented from submitting entries. This helps stop repeated fraudulent participation while maintaining control over campaign entry eligibility.

Country-level IP blocking

Grow supports geo-based access controls, allowing you to restrict or block participation from specific countries based on IP address. This helps reduce exposure to regions associated with high levels of fraudulent or automated activity, and ensures campaigns are limited to intended geographic audiences.

Bot protection (CAPTCHA)

Grow supports CAPTCHA challenges to prevent automated bot submissions. Customers can configure CAPTCHA in two ways:

  • Challenge all users

  • Trigger challenges only when suspicious activity is detected (recommended)

This provides a balance between user experience and security.

Domain and embed protection

To prevent unauthorised distribution of experiences (e.g. embedding on coupon or affiliate sites), Grow supports security headers that restrict which domains can host an iFramed experience. This ensures campaigns are only accessible from approved environments.

Pre-entry validation

For additional control, Grow supports pre-entry validation via integrations. This allows you to restrict participation to known users by validating identifiers such as email addresses or loyalty IDs against an approved dataset before allowing entry.

Access control and PII protection

Grow includes role-based access capabalities to manage who can access Personally Identifiable Information (PII). Permissions can be configured to ensure that only authorised users can view or handle sensitive data, supporting internal security and compliance requirements.

For more information, you can see our guide on User Roles & Capabilities.

Secure prize distribution

To reduce the risk of reward abuse:

  • Coupon codes can be hidden from on-screen confirmation pages and instead delivered via email.

  • Fraudulent or suspicious entries can be invalidated to prevent reward redemption.

  • Limits can be set on total rewards and redemption frequency (e.g. hourly/daily caps or win-based limits).

Additionally, Grow recommends using unique, single-use codes rather than batch codes, which are more susceptible to sharing and misuse.

Together, these controls provide defense against common fraud vectors including bot attacks, duplicate entries, identity masking, and reward abuse.