How Disability Sport Wales Stopped Bots Without Blocking a Single Disabled User
reCAPTCHA quietly locks out millions of disabled users every day. Here's how Disability Sport Wales replaced it with invisible bot protection, catching more bots while blocking zero real users.
A charity set up to support disabled people, running a login wall that disabled people could not get past. That was roughly the bind Disability Sport Wales found themselves in: a national charity working with disabled athletes, coaches, volunteers, and members right across Wales, with a reCAPTCHA sitting in front of its forms and failing the very people it exists to serve.
They took the puzzles off the screen, the site became usable again, and they ended up catching more bots than before without blocking a single real user. Here is what they changed.
What is accessible bot protection? Accessible bot protection stops automated traffic without ever asking a human to prove they are human. Instead of image puzzles, checkboxes, or audio challenges, all of which create barriers for disabled users, it verifies the visitor's device and behaviour invisibly, in the background, so every real person passes straight through regardless of ability or assistive technology.
The users a CAPTCHA quietly turns away
Most site owners measure a CAPTCHA by the bots it blocks. Almost nobody measures the people it blocks, because those people just leave and you never hear from them.
There are roughly 16 million disabled people in the UK, close to one in four of the population, according to Scope. For a large share of them, a "click all the traffic lights" puzzle is a locked door rather than a minor annoyance.
Disabled People (UK)
16M
almost one in four of the population
None of this is news. W3C published a whole working note on it, Inaccessibility of CAPTCHA, laying out how visual Turing tests systematically exclude users, and WCAG's guidance on non-text content flags CAPTCHA as a problem that demands alternatives. In WebAIM's screen reader user surveys, CAPTCHA shows up again and again as one of the most frustrating things on the web.
Walk through who each challenge type fails:
- Image puzzles: unusable for blind and low-vision users; difficult for many with cognitive disabilities.
- Audio challenges, the supposed fallback: fail deaf-blind users entirely, are notoriously hard for everyone, and are routinely solved by bots anyway.
- Drag, slide, and "select all" tasks: a wall for users with tremors, limited dexterity, or switch-based input.
- Time limits: penalise anyone who needs longer to read, process, or respond.
The audio fallback fails the humans and waves the bots through.
Disability Sport Wales: serving the exact people CAPTCHA fails
Disability Sport Wales gets an unusually sharp version of the problem. Their audience is, by definition, disproportionately disabled, which is the group visual and audio CAPTCHAs fail hardest.
When a disabled member tried to log in, register for a programme, or get in touch, a reCAPTCHA challenge stood in the way: for some of them a puzzle they could not solve, for others an audio clip that did not work with their setup, and for plenty of them a reason to give up and close the tab.
That kind of friction is expensive for any organisation. For one whose mission is removing barriers to participation, it cut straight against the point.
Why they couldn't just remove it
Deleting the CAPTCHA was off the table, because the moment protection comes off a public form the bots arrive. Automated traffic now makes up more than half of all web traffic, according to the Imperva Bad Bot Report. An unprotected login or contact form gets found and probed within days, by crawlers that index the entire web and feed every form they find to spam and credential-stuffing frameworks.
Web Traffic
51%
of all internet traffic is now bots
That left two bad options:
- Keep reCAPTCHA and keep locking out disabled users.
- Remove reCAPTCHA and open the doors to bot spam, fake registrations, and login abuse.
And the CAPTCHA was not even holding up its end of the deal. Commercial solving services defeat image and audio puzzles for fractions of a cent, the same weakness that let the AkiraBot framework spam 80,000+ sites straight through reCAPTCHA, hCaptcha, and Turnstile (we covered that campaign in our form bot protection guide). So the charity was paying the full accessibility cost of a CAPTCHA and getting a leaky version of the security for it.
A better puzzle was never going to fix that. What they needed was protection that never put a puzzle on the screen.
The fix: challenge the bot, not the person
TrustSig tests the environment rather than the visitor.
Instead of asking a human to prove themselves, it reads hardware-level rendering signatures, real-time device telemetry, and traffic cadence to separate a real consumer browser from an automated one running on a rack server. A real phone or laptop produces a specific, consistent fingerprint when it renders, and an emulator cannot fake the underlying silicon. The check happens invisibly, and a server-side verification call returns a clean allow / block decision before anything reaches the application.
Deployment at Disability Sport Wales was deliberately boring: drop in the script (or the relevant SDK), verify the token on the backend, done. For members, nothing changed except that there was nothing left to see.
The accessibility win is structural. An invisible system with zero user interaction has no failure point for assistive technology: no widget for a screen reader to announce, no audio clip to decode, no drag target to hit, no timer to beat.
Challenges Shown To Users
0
no puzzles, checkboxes, or audio, for anyone
There was a second problem the switch took care of. TrustSig is built in Estonia, hosted in Germany, and processes all data inside the EU without setting a cookie, so none of a visitor's behavioural data goes to US ad infrastructure the way reCAPTCHA's does. For a UK charity handling members' personal data, that posture matters about as much as the accessibility one. (We break down the full picture in our reCAPTCHA alternatives comparison and the GDPR-native CAPTCHA guide.)
What changed
| With reCAPTCHA | With TrustSig | |
|---|---|---|
| What the user sees | Puzzles, checkboxes, audio | Nothing |
| Disabled users completing forms | Many blocked or gave up | Every user, no challenge |
| Screen readers & assistive tech | Frequent failures | Unaffected, nothing to interact with |
| Bots that beat image CAPTCHAs | Got through | Stopped |
| Visitor data sent to US ad networks | Yes | No, processed in the EU |
Every legitimate user could log in and use the site again, including those relying on assistive technology. The friction that had been turning members away went away with the widget.
Security got stronger in the process. Because TrustSig verifies the device rather than the user, the automated traffic that had previously solved or skipped past reCAPTCHA was now caught. Detection went up. False positives, meaning real people wrongly flagged, stayed at the floor, and the charity stopped having to choose between protecting its members and serving them.
Accessibility and security were never a real trade-off
None of that is specific to one charity. Any organisation running a CAPTCHA is making the same hidden bet: that the customers it turns away are worth fewer than the bots it stops. For a disability charity the bet is obviously upside-down, but it is upside-down for an e-commerce store losing mobile conversions, a SaaS losing sign-ups, and a council losing residents who cannot complete a form, too.
The trade-off felt real for so long because the whole CAPTCHA category is built on interrogating the user. Move the test off the human and onto the machine and it dissolves: bots cannot fake the hardware they run on, and humans are never asked for anything. The people most failed by the old model get the most out of the new one. "Invisible" here is the mechanism, not the marketing.
Frequently asked questions
Is reCAPTCHA accessible for disabled users?
Not reliably. W3C has formally documented the inaccessibility of CAPTCHA, and screen reader users consistently rank it among the most frustrating barriers online. Blind and low-vision users cannot complete image puzzles, deaf-blind users cannot complete audio challenges, drag-and-select tasks defeat many people with motor impairments, and time limits penalise people with cognitive disabilities. The audio fallback is hard for humans and easy for bots, so it solves nothing.
What is the most accessible CAPTCHA alternative?
The most accessible alternative is no CAPTCHA at all. Invisible bot protection verifies the visitor's device and behaviour in the background, so there is no puzzle, checkbox, or audio clip to fail. With no user interaction in the page, assistive technology has nothing to get stuck on, and every real person passes straight through regardless of ability.
Can you really stop bots without showing a CAPTCHA?
Yes, and often better than a CAPTCHA can. Hardware-level rendering signatures and device telemetry catch automated browsers that defeat image and audio puzzles, because a bot cannot fake the silicon it runs on. Verification happens invisibly and is confirmed server-side, where it cannot be bypassed by replaying a frontend token.
Does invisible bot protection work with screen readers?
Yes. TrustSig renders nothing for the user to complete, so screen readers, switch devices, and magnifiers have nothing to trip over and the tab order picks up no extra stop. The check runs entirely in the background.
Is this GDPR compliant for a UK or EU charity?
TrustSig is built in Estonia, hosted in Germany, and processes all data inside the EU. It writes no cookie, identifies the device rather than the person, and earns nothing from monetising visitors. That is a cleaner posture than US-based CAPTCHAs that transfer behavioural data overseas, and it matters most for public-sector, healthcare, and charity sites handling sensitive member data.
Make your site usable for everyone
If your site shows a CAPTCHA, some share of your real users are failing it right now and leaving without a trace, so you will never see them. For most sites that is lost revenue. For an organisation serving disabled people, it is a barrier standing directly in front of the mission.
Either way, you do not have to choose. TrustSig's free tier covers 5,000 requests a month across two domains with the full threat engine included, invisible to every user, hosted in the EU, with zero puzzles for anyone. You can be live in under five minutes with a single script or a dedicated SDK for React, Node.js, Vue, or edge middleware.
Start protecting your forms free at trustsig.eu. No credit card required.
If you run a charity, council, healthcare, or other public-service site and want a hand making the switch, our team is happy to help.
Sources & further reading
- W3C, Inaccessibility of CAPTCHA | w3.org/TR/turingtest
- W3C WAI, Understanding Non-text Content (WCAG 1.1.1) | w3.org/WAI
- WebAIM, Screen Reader User Survey | webaim.org
- Scope, Disability facts and figures | scope.org.uk
- Imperva, 2025 Bad Bot Report | imperva.com