Unfortunately, there's no real way to hide a website on the internet. Spam bots will find it eventually if they can, and differentiating human from bot can be quite a tricky task.
If you're finding that the simple spam filter isn't meeting your needs, there are other spam filters in the extensions section of the website that might further your protection and help alleviate the problem. However, no implementation will be perfect, so there will always be some level of vigilance necessary to prevent spam.
I haven't looked at your website, but one other precaution you could take is to only allow registered users to comment. If anyone can comment, it will be significantly easier for spam bots to do what they do best.
One other thought: I haven't looked through the `comment_form` code, but one common way of blocking spam bots is to use a hidden form field which is initially unchecked. Since spam bots do not (usually) use graphical browsers, they will unknowingly check the hidden field, thus disabling the comment form. The only caveats with this method are that not all spam comes from bots (though most does, in my experience) and not all actual users use graphical browsers (the hidden field would need to be denoted to these users so that they do not unwittingly deactivate the comment form).
Another common way is to use an extra question, such as "What is the name of my website?" at which most bots will fail to answer correctly.