VASTlint
Back to blog

HUMAN vs CHEQ lines up a click check and a 17.9% fake-visit share

An accreditation scope, a platform click result, two growth rates, and a visit share sit together here and do not share a scale.

FirmFigureUnitPopulationSurfaceDate
HUMANAd Fraud Defense and Ad Fraud Sensor accredited for GIVT and SIVTAccreditation scopePre-bid requests and post-serve impressions in desktop, mobile web, in-app, CTVProgrammaticApril 4, 2025
HUMANNearly half a billion clicks analyzed, 10% better IVT detectionPlatform case resultLinkedIn Audience Network display clicks, first four monthsInside the ad platformIntegration from April 2025
HUMANAutomated traffic up 23.51%, human traffic up 3.10%Year-over-year growthInteractions across a subset of HUMAN customers, 2025Customer digital propertiesMarch 26, 2026
CHEQ17.9% of traffic fakeVisit share34 billion data points from client sites, collected in 2023Advertiser websitesMarch 18, 2024
CHEQInvalid traffic up nearly 50%, visit volume up 3.5%Year-over-year growthMore than 300,000 customer-monitored sitesAdvertiser websitesMarch 30, 2026
CHEQMalicious share of invalid traffic from about 11% to under 6%Composition shareInvalid traffic on the same network, past twelve monthsAdvertiser websitesMarch 30, 2026
Three cards. HUMAN sells pre-bid suggestions and click validation to platforms and reports automated traffic up 23.51 percent in 2025. CHEQ sells to advertisers and reports 17.9 percent of site traffic fake in 2023 data. vastlint checks the verification node and URLs in a VAST tag and does not classify traffic.
A click judged inside the platform and a visit judged on the advertiser's site are both about bots, and they are counted at different points with different denominators. Diagram by vastlint.org. An independent open-source project. The diagram restates figures already cited in this post.

Alex Sekowski · October 2, 2026 · 15 min read

HUMAN vs CHEQ is a search that puts an ad-fraud company and a go-to-market security company on one line, usually because a marketer has heard both names in a conversation about bots. Their public numbers come from different seats. HUMAN's Ad Click Defense, launched April 24, 2025, is sold to ad platforms such as DSPs, retail media networks, and walled gardens, and it validates the click or touch event so the platform can filter invalid clicks; in the LinkedIn Audience Network integration it analyzed nearly half a billion clicks in four months and improved LinkedIn's invalid traffic detection by 10 percent. HUMAN's March 26, 2026 benchmark says automated traffic across its customer base grew 23.51 percent in 2025 while human traffic grew 3.10 percent. CHEQ's most recent State of Fake Traffic edition, published March 18, 2024, says 17.9 percent of the traffic it studied was fake, from 34 billion data points collected through 2023 on its clients' websites, and a March 30, 2026 CHEQ post says invalid traffic on its network grew nearly 50 percent year over year while visit volume rose 3.5 percent. vastlint does not rank HUMAN against CHEQ. It checks whether a VAST 2.0–4.4 tag still carries the verification node a measurement script would need, and it does not classify invalid traffic or score clicks.

The figures share a vocabulary (bots, invalid traffic, fake users) and very little else. A click validated inside a platform is judged before the advertiser is billed. A visit judged fake on the advertiser's own site is counted after the click was already bought, or after a visitor arrived without any click at all. A growth rate across one firm's customer interactions is a trend, not a share. Placing 23.51 percent beside nearly 50 percent, or 17.9 percent beside a 10 percent improvement, joins four denominators into one row.

Both firms sell protection against automated and fraudulent traffic, and both now describe AI agents as part of that job. Hiring one, the other, or both is a decision about where in the path a check should sit. The public research does not settle it. With the names removed, a platform-side click check, a pre-bid suggestion, and a share of visits to an advertiser's site still do not order one another.

What the HUMAN figures measure

The audited part of HUMAN's advertising business is stated in a Media Rating Council letter dated April 4, 2025. The MRC board continued accreditation for Ad Fraud Defense, the pre-bid platform formerly called MediaGuard, for GIVT and SIVT requests across desktop, mobile web, mobile in-app, and CTV, and for Ad Fraud Sensor, the post-serve platform formerly called FraudSensor, for display and video tracked ads, impressions, decisions, and incomplete loads in the same four environments. The MRC's April 11, 2025 statement on pre-bid IVT adds the seat: HUMAN supplies suggestions on whether a request is IVT to DSPs and SSPs, and the platform decides whether to act. That is an accreditation scope and a distribution rule, and neither one is a rate.

Ad Click Defense is the HUMAN product closest to CHEQ's territory, and its buyer is again the platform. HUMAN's April 24, 2025 launch release names DSPs, retail media networks, and walled gardens, describes real-time behavioral analysis of the click or touch event, and says the product classifies both SIVT and GIVT clicks, drawing on more than 400 detection algorithms and attack patterns seen across 3 billion internet-connected devices a month. HUMAN's click fraud guide reports the LinkedIn result: an integration across display inventory on the LinkedIn Audience Network from April 2025, nearly half a billion clicks analyzed over the first four months, and a 10 percent improvement in LinkedIn's invalid traffic detection, with the stated aim that advertisers are not billed for clicks identified as invalid. The 10 percent is an improvement over one network's existing detection. It is not the share of LinkedIn clicks that were invalid.

The March 26, 2026 State of AI Traffic and Cyberthreat Benchmark Report is a different instrument. HUMAN says the Human Defense Platform processed more than one quadrillion interactions in 2025 and that the report draws on a subset of its customers, aggregated and anonymized. Automated traffic, which the report defines as all non-human traffic, grew 23.51 percent year over year; human traffic grew 3.10 percent. Monthly AI-driven traffic grew 187 percent from January to December 2025, and traffic from AI agents and agentic browsers grew 7,851 percent, which HUMAN notes started from a very low base. These are growth rates of categories inside HUMAN's customer traffic. Because automated traffic includes training crawlers and other declared bots, the 23.51 percent is not an invalid traffic rate either.

HUMAN's Satori threat intelligence team publishes a fourth kind of number: the size of one operation. On March 5, 2025, HUMAN said BADBOX 2.0 had infected more than 1 million off-brand Android Open Source Project devices, with associated traffic from 222 countries and territories. On May 19, 2026, it described Trapdoor, a pipeline of 455 malicious Android apps and 183 threat-actor-owned HTML5 domains that at its peak accounted for 480 million bid requests a day, with associated apps downloaded more than 24 million times. HUMAN says customers using Ad Fraud Defense and Ad Click Defense remain protected from Trapdoor. A peak daily bid-request count for one scheme says how large that scheme was, and it does not say what share of anyone's traffic was invalid.

What the CHEQ figures measure

CHEQ describes its category as go-to-market security, and its paid-media product, CHEQ Acquisition, is sold to the advertiser. The product page says it removes bots and invalid traffic from paid campaigns, audiences, and remarketing across more than 15 platforms, including Google Search, Display, and Performance Max, Facebook and Instagram, and LinkedIn, with reporting down to campaign and UTM. The measurement point is the advertiser's own site. CHEQ's 2023 State of Fake Traffic report explains the method: when a user arrived on a domain owned and operated by a CHEQ customer, CHEQ ran more than 2,000 real-time challenges to decide whether the visit was valid. The unit is a visit that already happened.

The most recent edition on CHEQ's research page is The State of Fake Traffic 2024, published March 18, 2024. It is based on 34 billion data points collected throughout 2023 from enterprise-level companies, and it says 17.9 percent of all traffic studied was fake, up from 11.3 percent in the previous edition, which CHEQ calls a 58 percent increase. Industry rows include retail and ecommerce at 15.8 percent, software at 14.1 percent, finance and insurance at 17.3 percent, and higher education at 15.7 percent. No 2025 or 2026 edition with a comparable headline appeared in the material reviewed, so the 17.9 percent describes 2023 traffic on CHEQ clients' sites.

The 2023 edition is the one that splits by source, and the split shows how much the denominator matters. Across more than 15,000 customers in 2022, 11.3 percent of all traffic was fake, 5.9 percent of paid traffic, 5.7 percent of organic traffic, and 22.1 percent of direct traffic. CHEQ then applied the 5.9 percent paid rate to more than $600 billion of global digital ad spend and estimated that about $35.7 billion was wasted. That step moves a rate measured on visits to CHEQ customers' sites onto all global ad spend, including impressions that never produced a visit. The report presents it as a conservative estimate, and it is a projection rather than a measurement.

CHEQ's 2026 figures come from blog posts rather than a numbered report. A March 30, 2026 post says CHEQ's network analyzes roughly 6 trillion signals a day across more than 300,000 customer-monitored sites; that invalid traffic, defined as automated, suspicious, or otherwise non-genuine, grew nearly 50 percent year over year in the most recent measurement period while visit volume rose 3.5 percent; and that the share of invalid traffic classified as malicious fell from roughly 11 percent to under 6 percent over twelve months. A January 26, 2026 threat intelligence post says AI agent activity rose sharply from July 2025 and reached a majority of monitored enterprise environments while remaining a small share of traffic. On the corporate side, CHEQ announced its acquisition of Deduce, an identity fraud company, on January 30, 2025, calling it the company's third acquisition, and named CyberArk founder Udi Mokady chairman of its board on July 7, 2026.

Why the HUMAN and CHEQ headlines have no shared scale

The moment differs. Ad Fraud Defense answers before a bid. Ad Click Defense answers when the click or touch happens inside the platform, so the platform can keep the click out of billing. CHEQ's visit check answers after the visitor reaches the advertiser's page. A click the platform filtered may still have sent a browser to the landing page, and a click whose landing page never loaded is absent from CHEQ's data. A visit CHEQ marks fake may have come through a click the platform accepted, through organic search, or with no referrer at all, which is why CHEQ's 2022 direct-traffic rate of 22.1 percent was nearly four times its paid rate.

The denominators differ. HUMAN's 10 percent is an improvement in one network's detection, measured on LinkedIn Audience Network display clicks. HUMAN's 23.51 percent is growth in all non-human interactions across a subset of its customers. CHEQ's 17.9 percent is a share of visits to its clients' sites in 2023. CHEQ's nearly 50 percent is growth in invalid traffic across more than 300,000 monitored sites. Two of those are growth rates and two are not, and no two share a population.

The definitions differ even where the words match. HUMAN's automated traffic counts every non-human request, including crawlers a site owner allows. CHEQ's invalid traffic counts automated, suspicious, or otherwise non-genuine traffic, and CHEQ says the malicious part of it has been shrinking as a share. GIVT and SIVT, the categories in HUMAN's accreditation letter, come from the MRC's invalid traffic standard for advertising measurement. A visitor CHEQ marks as suspicious on a lead form sits outside that standard's unit, even if the same bot also clicked an ad.

The dates differ. CHEQ's 17.9 percent is 2023 traffic, published in March 2024. HUMAN's 23.51 percent is 2025 traffic, published in March 2026. CHEQ's nearly 50 percent covers a most recent measurement period that ends before March 30, 2026 and is not dated more precisely. Reading 23.51 percent against nearly 50 percent as proof that CHEQ sees twice the bot growth confuses a category that includes permitted crawlers with a category built around suspicion, over windows that are not stated to match. Reading HUMAN's 3.10 percent human growth against CHEQ's 3.5 percent visit growth as agreement makes the same mistake in the other direction, since one is human traffic only and the other is all visits.

Which question each firm's number answers

Cells restate what each firm has published; Not published means the reviewed material does not answer the question.

Question a buyer asksHUMAN public answerCHEQ public answer
Will a bid request be flagged before the bid?Ad Fraud Defense sends an IVT suggestion to DSPs and SSPs, MRC-accredited for GIVT and SIVT requestsNot published
Are clicks validated before the platform bills them?Ad Click Defense, sold to platforms; LinkedIn reported 10% better IVT detection on nearly half a billion clicksCHEQ Acquisition works from the advertiser's side across 15+ platforms; platform billing is not its published seat
What share of visits to my site are fake?Not published as a single visit share17.9% of traffic studied, from 34 billion data points collected in 2023
Is automated traffic growing?Automated traffic up 23.51% and human traffic up 3.10% in 2025Invalid traffic up nearly 50% and visits up 3.5% in the most recent period
How much of it is malicious or organized?Named schemes, such as Trapdoor at 480 million bid requests a day at peakMalicious share of invalid traffic fell from about 11% to under 6% in twelve months
Is the method MRC accredited?Yes, for the products and environments in the April 4, 2025 letterNot published
Does the measurement ride in a VAST tag?Ad Fraud Sensor docs recommend JavaScript tags for VAST 4.x video and pixel tags for other videoNot published; measurement starts on the advertiser's site

Where each firm meets a VAST tag, and where the buyer has nothing to check

HUMAN's post-serve tag has a documented relationship to VAST. Its FraudSensor tag-type guide recommends JavaScript detection tags for VAST 4.x video and VAST 4.1 audio in every environment, including CTV, and pixel tags for all other video. In a VAST document those are two different places. A script that runs through Open Measurement belongs in the AdVerifications node in VAST 4.1 and later, or in an Extension of type AdVerifications before 4.1: a Verification element with a vendor attribute, a JavaScriptResource whose apiFramework is omid, VerificationParameters, and a TrackingEvents block whose verificationNotExecuted event tells the vendor the script did not run. A pixel is a URL in Impression or in TrackingEvents. Which form a particular buyer's HUMAN integration uses is set in the integration, not in the spec.

Both forms can be lost after the bid is won. A wrapper hop can rebuild the document so the impression pixel survives while the verification node never reaches the InLine the player parses. A server-side ad insertion stitcher fetches VAST on the server and can forward impression URLs with nothing on the device to execute a script. A CTV player without OM SDK cannot run the JavaScriptResource at all, which is the case verificationNotExecuted exists to report. Google's Authorized Buyers help notes that VPAID has never been accepted on app inventory there, and that OM SDK is what lets video buyers use third-party viewability providers on app buys. None of that appears in a pre-bid suggestion or a click validation, because it is a property of the XML.

CHEQ has no VAST role in its published material, and for most of what CHEQ protects there is no VAST tag in the buyer's hands. Google Search ads, Performance Max, Facebook and Instagram, and LinkedIn campaigns are bought and measured inside each platform, and YouTube, Meta, and TikTok video does not hand the buyer a VAST document to inspect. Where a video ad does run on VAST, the click goes to the ClickThrough URL inside VideoClicks, and CHEQ's measurement starts only when that visitor loads the advertiser's site. A validator can flag click and tracking URLs served over plain HTTP, and it cannot tell who arrives at them.

What to do with the shortlist

Decide where the check has to sit before comparing vendors. If the risk is bidding on requests that already look invalid, the seat is the DSP or SSP, and HUMAN's accredited pre-bid service is sold there. If the risk is paying a platform for invalid clicks, the seat is the platform's billing, which is where Ad Click Defense is sold and where an advertiser can only ask whether the platform runs such a check. If the risk is bots filling lead forms, polluting remarketing audiences, and skewing analytics on your own site, the seat is your site, which is where CHEQ measures.

Ask for the number with your traffic as the denominator. A benchmark of 17.9 percent fake traffic on other companies' sites in 2023, or 23.51 percent automated growth in another firm's customer base in 2025, does not give you your own rate. A trial on your own paid traffic does, and it should report invalid visits by channel and campaign with the definition of invalid written down. For platform-side click filtering, ask the platform which vendor it uses and whether filtered clicks are excluded from billing, since that is the claim HUMAN's LinkedIn case makes.

Then check the part neither firm's headline covers. When the campaign includes VAST video, the verification script or pixel has to survive every wrapper and stitcher between the ad server and the player, or the post-serve measurement never runs. vastlint is independent of HUMAN and of CHEQ. It checks VAST 2.0–4.4 structure, including the AdVerifications or Extension node, the Verification vendor and resources, impression and tracking URLs, and click URLs. It does not detect invalid traffic, validate clicks, measure site visits, or know whether a vendor's host is responding.

What to separate before using this comparison

  • An MRC accreditation scope for named products and environments is a statement about an audited method, not a fraud rate.
  • A 10 percent improvement in LinkedIn's invalid traffic detection is a lift on one network's baseline, not the share of clicks that were invalid.
  • HUMAN's 23.51 percent is growth in all non-human traffic, including permitted crawlers, across a subset of its customers in 2025.
  • CHEQ's 17.9 percent is a share of visits to CHEQ clients' sites in 2023, published in March 2024, and it remains the latest State of Fake Traffic headline.
  • CHEQ's nearly 50 percent is growth in invalid traffic across more than 300,000 monitored sites, with malicious traffic falling as a share of it.
  • A scheme size such as Trapdoor's 480 million bid requests a day at peak describes one operation, not a market rate.
  • Paid search and walled-garden social campaigns do not give the buyer a VAST tag, so only VAST video placements leave a document to validate.

Questions buyers ask about HUMAN and CHEQ

  • Do HUMAN and CHEQ do the same thing? They overlap on bots and invalid traffic, but HUMAN's advertising products are sold to platforms such as DSPs, SSPs, retail media networks, and walled gardens, while CHEQ Acquisition is sold to advertisers and measures visits on their own sites.
  • Is HUMAN or CHEQ MRC accredited? HUMAN's April 4, 2025 MRC letter continues accreditation for Ad Fraud Defense GIVT and SIVT requests and Ad Fraud Sensor measurement across desktop, mobile web, in-app, and CTV. No MRC accreditation scope for CHEQ appeared in the CHEQ material reviewed for this page.
  • What is CHEQ's latest fake traffic percentage? The State of Fake Traffic 2024 puts fake traffic at 17.9 percent of 34 billion data points collected in 2023, and CHEQ's March 30, 2026 post reports invalid traffic up nearly 50 percent year over year rather than a new share.
  • Does HUMAN handle click fraud? Yes, at the platform level: Ad Click Defense, launched April 24, 2025, validates clicks for ad platforms, and HUMAN reports a 10 percent improvement in LinkedIn's invalid traffic detection after integration.
  • Can vastlint tell me whether HUMAN or CHEQ is better? No. vastlint checks VAST 2.0–4.4 structure, including whether the verification node and tracking URLs survive in the tag, and it does not rank vendors or classify traffic.

Validate the VAST tag that carries the measurement

Paste a VAST 2.0–4.4 tag to check verification nodes, impression and tracking URLs, and click URLs against specification-derived rules. Nothing is stored.

Paste the tag

XML opens the validator, and a live tag URL opens the tester.

Or test a live URL

Sources

Continued accreditation for Ad Fraud Defense (formerly MediaGuard) and Ad Fraud Sensor (formerly FraudSensor), with environments.

HUMAN supplies suggestions to DSPs and SSPs, and the platform decides whether to act.

April 24, 2025. Buyers named as DSPs, retail media networks, and walled gardens; 400+ algorithms and 3 billion devices a month.

The LinkedIn Audience Network case: nearly half a billion clicks in four months and a 10 percent detection improvement.

Automated traffic up 23.51 percent, human up 3.10 percent, AI-driven up 187 percent, and the methodology note on a customer subset.

Publication date of March 26, 2026 for the benchmark figures.

May 19, 2026. 455 apps, 183 domains, 480 million bid requests a day at peak, 24 million downloads.

March 5, 2025. More than 1 million infected devices and traffic from 222 countries and territories.

JavaScript tags for VAST 4.x video and VAST 4.1 audio, pixel tags for other video.

March 18, 2024. 17.9 percent fake from 34 billion data points collected in 2023, plus industry rates.

Visit-level method on customer domains, and 2022 rates by source: 11.3 percent all, 5.9 percent paid, 22.1 percent direct.

Lists The State of Fake Traffic 2024 as the current edition.

March 30, 2026. 300,000+ sites, invalid traffic up nearly 50 percent, visits up 3.5 percent, malicious share under 6 percent.

January 26, 2026. AI agent activity inflecting from July 2025 while staying a small share of traffic.

Paid campaign protection across 15+ platforms, including Google Search, Display, PMax, Facebook, Instagram, and LinkedIn.

January 30, 2025. Described by CHEQ as its third acquisition.

AdVerifications added in VAST 4.1, with the Extension node used before 4.1.

Open Measurement SDKGoogle Authorized Buyers Help

Sample Verification markup with verificationNotExecuted, and the note that VPAID was never accepted on app inventory.

The pre-bid side of HUMAN in more detail, including the FraudSensor loop.

The hop split this page extends to clicks and site visits.

Where the verification node has to live, and what breaks it across wrappers and stitchers.

Read another comparison in this set

All posts

Check the tag these notes describe

The rates above do not say whether AdVerifications survived the wrapper.