MX8 Labs records available browser security evidence and uses the respondent source's settings to decide whether to exclude duplicate or suspect respondents. Evidence collection and exclusion are separate: allowing a respondent to continue does not mean the checks found no risk.
For background on the threat these checks address, read how bad actors exploit AI for survey fraud.
Signal Categories
Screening draws on five families of signal, each evaluated in real time as the respondent enters the survey.
- User behavior signals - whether the browser session has been configured or altered to avoid identification, including attempts to conceal, tamper with, or reset the identifiers used to recognize a returning respondent.
- Network signals - whether the connection is consistent with the respondent's reported location, whether the true origin is being masked, and whether the same network is being used repeatedly or switched mid-session.
- Bot detection signals - whether the session shows the characteristics of automated rather than human participation, including scripted browsers and traffic originating from environments built to simulate real devices at scale.
- Device data signals - whether the reported device profile is internally coherent, and whether the device is being operated remotely rather than used directly by the respondent.
- Mobile device signals - whether a mobile device, its operating system, and its app environment are in an unmodified state.
The MX8 suspect score runs from 0 (no suspect evidence after a completed check) to 5 (maximum). The source's Quality filter determines which scores cause exclusion. Duplicate findings have a separate control. An unavailable or pending result is not a score of zero.
We publish the categories rather than the individual signals within them, because the signal-level detail is precisely what a fraud operator would need in order to defeat it. If you need the full inventory for a security review, a procurement questionnaire, or a client audit, contact the MX8 Labs team or see trust.mx8labs.com.
What happens to flagged respondents
Fraud and bot screening is one of several layers of respondent validation. It sits alongside deduplication, in-survey attention and consistency checks, and in-field monitoring - see Data quality methodology for how the layers fit together, and IP Address Hygiene and Exposure Matching for how the same pipeline applies to ad-exposure work.
Use recorded respondent statuses and termination reasons to reconcile exclusions. Quality and duplicate screenouts can appear as Poor Quality or Duplicate Respondent, and their IDs are available in the Respondent reconciliation download. Raw downloads can include non-complete respondents, so filter the analysis population deliberately.
The field report's Quality section separates recorded findings from actual exclusions.
Disabling bot detection
If you are entirely comfortable that everyone entering your survey will be a real human, you can disable bot detection by adding the following to your survey:
s.allow_bots = True
Trusting all respondents on a source
Configure a respondent source's quality controls
Open the respondent source's settings. Eligible browser sources expose two independent controls:
- Allow duplicate respondents — when off, duplicate findings can terminate the respondent. When on, available duplicate evidence is still recorded, but that finding does not trigger duplicate termination.
- Quality filter — a whole number from 0 to 5. Higher values apply stricter suspect screening. Setting it to 0 disables suspect termination, while retaining available evidence.
| Quality filter | Suspect scores screened out |
|---|---|
| 0 | None |
| 1 | 5 |
| 2 | 4–5 |
| 3 | 3–5 |
| 4 | 2–5 |
| 5 | 1–5 |
The standard defaults are Allow duplicate respondents: off and Quality filter: 5. Check the saved settings on the source you are using rather than assuming every source has those defaults.

For record-only monitoring, allow duplicates and set the Quality filter to 0. To allow duplicate findings while keeping suspect screening, change only the duplicate control. Disabling one control does not disable the other.
These controls replace the single Trust all respondents toggle. Existing trusted browser sources still retain available browser evidence. Synthetic, profile synthetic, third-party import, Twilio voice/text and internal test sources have source-specific behavior and do not expose the same browser controls.
Review the data quality methodology before interpreting a score as evidence of fraud. Shared networks, privacy tools and uncertain device identification can affect findings; the score alone is not proof of fraudulent behavior.
