1M+ bot checks processed

Stop bots before they sign up, log in or check out.

The invisible captcha alternative. No puzzles, no checkboxes, no cookies, no friction. One SDK call protects your forms, logins, and APIs, and real users never see a thing.

EU-hostedNo cookiesFree

No card. Live in 5 minutes.

ZEROCookies or personal data stored
ZEROUser challenges ever shown
EUEU-hosted, always
Built in EstoniaHosted in the EULow-latencyPrivacy by default and by design
LIVE DEMO
// INTEGRATION
import { useTrustSig }
from '@trustsig/react';

const { scan } =
useTrustSig();

const { token } =
await scan();
// API RESPONSE
{
  is_bot: false,
  score: 0,
  action: "ALLOW",
  req_id: "0000..0000",
}
Human verified
200 OK · 19ms
LIVE DEMO
// INTEGRATION
import { useTrustSig }
from '@trustsig/react';

const { scan } =
useTrustSig();

const { token } =
await scan();
// API RESPONSE
{
  is_bot: false,
  score: 0,
  action: "ALLOW",
  req_id: "0000..0000",
}
Human verified
200 OK · 19ms
02 The traffic you can't see

Bots don't knock politely. They look like your best customers, and your CAPTCHA waves them through.

84%

Of contact-form submissions on unprotected sites are bots, not people.

2,400/hr
Brute-force hits per WordPress login, hourly
1 in 3
Signups are fake accounts testing stolen cards
9 in 10
Comment-spam attempts per blog, daily
03 What your real users get

Three things your visitors never see.

Drop in one SDK call. Then nothing. Forms keep submitting, logins keep working, bots disappear at the edge.

01

A CAPTCHA

No puzzles, no traffic lights. Real users are never challenged.

02

A cookie prompt

Identification needs no cookies, so there is nothing to consent to.

03

A spinner

Decisions land at the edge in around 20ms. No waiting.

A CAPTCHA

No puzzles, no traffic lights. Real users are never challenged.

A cookie prompt

Identification needs no cookies, so there is nothing to consent to.

A spinner

Decisions land at the edge in around 20ms. No waiting.

Install in minutes. Bots disappear.

No credit card. Free tier. EU-hosted.

04 Under the hood

One call. Here's everything that happens.

01The pipeline
L1CollectA tamper-resistant client agent gathers raw signals.
L2ResolveA stable risk profile, no cookies.
L3SignalTrustSig scores 200+ signals: network, device and behaviour.
L4DecideOne score, then allow or block.
clientone round trip~20ms at the edge
  1. L1CollectA tamper-resistant client agent gathers raw signals.
  2. L2ResolveA stable risk profile, no cookies.
  3. L3SignalTrustSig scores 200+ signals: network, device and behaviour.
  4. L4DecideOne score, then allow or block.
one round trip, ~20ms at the edge
02What we store

We keep the trust signals. We don't see the person.

TrustSig scores each request on device and network signals without ever touching personal data. No name, no email, no cookie leaves the browser.

No PII storedEU hostedPrivacy by default and by design
kept
  • trust signals
  • risk score
never
  • name / username / email
  • cookies
  • PII data
03Drop-in code
FRONTEND · React
import { TrustSig } from "@trustsig/react";

<TrustSig publicKey="pk_live_..." />
SERVER · Node
import { verify } from "@trustsig/server";

const { action } = await verify(req.token);
if (action === "block") return res.status(403);
Works with
WordPressReactNext.jsVueLaravelDjango
05 Edge Performance

Zero impact on your site.

01
At the edge

Risk decision at the edge

Your user receives an encrypted risk score from TrustSig's edge network, which your backend can read and enforce.

02
Out of band

No blocking, ever

Advanced heuristic evaluation runs asynchronously, completely outside your request path, adding zero milliseconds to page load.

03
Your backend

Instant local verification

Verify tokens locally using static keys, no network call required. Or make a lightweight and fast request to our edge.

client< 1msadded to your page load

06 Platform Comparison

How TrustSig compares.

Most captcha tools challenge your users with image puzzles, click boxes, and math problems. TrustSig is invisible by design, so visitors face zero friction and never see a challenge.

CapabilityTrustSigEU hosted · No cookies · InvisibleCF TurnstilereCAPTCHAhCaptcha
User frictionNone (invisible)Minimal puzzlePuzzle / clickPuzzle / click
EU-basedYes (EU)Yes (EU)No (US)No (US)
GDPR-nativeYesYesPartialNo
Bypass-resistantHardware-levelEasily bypassableModerateEasily bypassed
Uses cookiesNoNoYesYes
All features in free tierYesNoNoLimited
Monetises user behaviourNeverNeverPartiallyYes
YesPartialNo

Comparison based on publicly available documentation, June 2026.

CapabilityTrustSigCF Turnstile
User frictionNone (invisible)Minimal puzzle
EU-basedYes (EU)Yes (EU)
GDPR-nativeYesYes
Bypass-resistantHardware-levelEasily bypassable
Uses cookiesNoNo
All features in free tierYesNo
Monetises user behaviourNeverNever
3/7capabilities where TrustSig leads CF Turnstile

Comparison based on publicly available documentation, June 2026.

07 Customer story · LEI System
We were drowning in relentless API abuse. We tried other anti-bot services, none of them stopped the sophisticated attackers. Then we switched to TrustSig, and it eliminated every last trace of the API abuse we were dealing with.
LEI System
ZEROfalse positives for real applicants
79%of bot & API traffic blocked
08 Behind TrustSig

Built by security engineers.

The core team behind TrustSig brings a decade of national cyber defence experience to enterprise bot protection.

Aare Reintam

Chief Executive OfficerCo-Founder

Former Cyber Defence Exercise Manager at NATO CCDCOE, architect of Locked Shields and Crossed Swords, the world's largest live-fire cyber exercises. At TrustSig, he applies that same operational grade to stopping automated attacks.

NATO CCDCOE, CybExer Technologies, 10+ yrs cyber defence

Robert Vähhi

Chief Technology & Product OfficerCo-Founder

The architectural force behind TrustSig's core signal processing engine and hardware attestation layer. Leads all platform engineering from protocol design to SDK delivery.

Core Engine Architect, Hardware Attestation

Rünno Reinu

Chief Operating & InfoSec OfficerCo-Founder

Leads security governance and operations across all TrustSig layers, ensuring each layer remains sound, secure and compliant.

CISSP, CISA, CSSLP, ISO27001 Senior LA

Email copied to clipboard
09 Pricing

Start free. Stay free until you grow.

No card. EU-hosted on every tier.

Starter

€0free

For personal projects and sites getting started with bot protection.

  • 50,000 requests / month2 domains
  • Full threat protection suite
  • Bot farm blocking
  • No CAPTCHAs for visitors
  • Community support

Business

€63/mo · billed yearly

For established companies needing high-volume protection and priority SLA.

  • 750,000 requests / month25 domains • €5 per 100k extra reqs
  • Full threat protection suite
  • Bot farm blocking
  • No CAPTCHAs for visitors
  • Priority support

Enterprise: unlimited volume · SLAs · on-prem · dedicated support.

What counts as a check?

One check is a single verification request: a page view, form submit, or login attempt that TrustSig evaluates. You only spend a check when traffic actually hits a protected surface, so bot floods do not quietly drain your quota.

10 Common Questions

Frequently asked.

No. TrustSig is a threat protection platform, not a CAPTCHA tool. We eliminate the need for CAPTCHAs entirely by providing deterministic signals that allow your infrastructure to block bot traffic with absolute confidence. Your visitors experience nothing. No puzzles, no checkboxes, no friction.

Extremely simple. For free tier usage, you just need to upload the plugin and activate it. No signup, API keys, or complex configuration required. Your forms and login pages are protected instantly upon activation.

Existing CAPTCHA solutions can be defeated in seconds by commercial bot farms, a well-documented industry reality. TrustSig operates at the hardware attestation and traffic behaviour layer, not the challenge layer. We mathematically verify the rendering environment via deterministic hardware cryptography, making circumvention fundamentally harder and economically unviable.

Minimal. A single script tag for web, or a lightweight SDK for iOS and Android. TrustSig operates out-of-band, meaning zero blocking impact on your application startup or user latency. Most teams are fully protected in under an hour.

Yes. Add the client SDK to your frontend and verify the token on your server, and your existing forms and logins keep working. No reverse proxy, no rewrite, no migration project. Visitors simply stop seeing puzzles.

Yes. The Starter tier covers 50,000 requests a month with the full threat engine and no credit card. Paid plans add volume and domains, but every tier ships the same protection.

Email copied to clipboard

Stop bots. Not your users.

Free. No card. Live in 5 minutes.

1M+ checks served
20ms at the edge
Zero cookies

Drops in with one snippet, rip it out anytime.