Security and data quality

Bot filtering

How bots pollute results, which signals Testvoy checks and how review workflow works.

Last updated: May 22, 20268-14 minBeginner to intermediate
Start free See pricingMethodology

How bots distort experiment results

Bots, crawlers, headless browsers, repeated requests and event spam can make variant performance look different from reality. Testvoy's bot-aware reporting approach focuses on making these signals visible and separable before they influence decisions.

Bot signature library

Signed ingest context

Rate-limit and abuse guard

SRM traffic quality check

Bot review workflow

Trust engine
EventGuardSRMReport
Visitor event, signature check, abuse guard, SRM and clean report flow.

Privacy-first data quality

Bot protection works for experiment accuracy and data security; it does not move unnecessary personal data, raw card data or sensitive customer data into the public marketing surface. The goal is to reduce polluted traffic deciding the winner and warn users before decision time.

  • Is suspicious traffic visible separately?
  • Is the dropped event reason understandable?
  • Was the SRM warning taken seriously?
  • Does event context match the right project/experiment?
  • Was data quality read before the decision?

Example data-quality check

Example: a report shows unexpectedly high conversion. Before deciding, review bot signals, signed event context, dropped event reasons, rate-limit signals and SRM checks in order.

  1. 01

    Open Report > Data quality

  2. 02

    Check suspicious traffic count

  3. 03

    Look for signature/context errors in dropped events

  4. 04

    Inspect rate-limit or abuse guard signals

  5. 05

    If SRM warning exists, hold decision or re-QA

  6. 06

    Share the clean report with a shareable link

Example quality note
Traffic quality: healthy
SRM: no mismatch
Dropped events: 0.8% invalid context
Suspicious traffic: reviewed separately
Decision status: safe to review

Practical scenario

A growth team changes CTA copy on the pricing page, connects signup_started and signup_completed goals, then reads Google Ads and returning visitor segments separately. If the result is promising, they share a report link with the client or leadership.

Common mistakes

Most mistakes come from wrong project keys, overly broad selectors, missing goals, staging/prod mixups, early decisions on small samples or skipping mobile QA.

Naming an experiment 'test'

Launching without a goal

Deciding on total CVR only

Sending screenshots instead of shareable reports

Frequently asked questions

Who is Bot filtering for?

Marketing, growth, product and developer teams can use the same guide at different depths.

Do I need a developer?

Not for basic visual changes and report reading; SDK, custom events, custom JS or enterprise security benefit from technical support.

How do I know it worked?

Verifier, recent events, preview, QA checklist and report warnings show setup and experiment health.

What is the common mistake?

Wrong project keys, missing goals, fragile selectors, early decisions on small samples and skipped mobile QA are common.

Docs

Try this guide in the app

Finish setup, create your first experiment and read the report with cleaner data in Testvoy.