EU privacy, taken further. Hardware-level and fully invisible.
CaptchaFox shows a challenge when risk goes up. TrustSig reads hardware-level signals instead and shows nothing at any risk level, processed only in Germany.
Complete threat engine, no challenge widget.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
TrustSig vs CaptchaFox
Both are EU-aligned and privacy-minded. These rows cover the challenge, the detection model and the verify path.
| Capability | TrustSig | CaptchaFox |
|---|---|---|
| User-facing element | None, no widget at all | Challenge widget on risk |
| Detection method | Hardware-level deterministic signals | Behavioural + challenge fallback |
| Data residency | EU only (Germany) | EU (Germany) |
| Cookies and identifiers | Zero cookies, id scoped to one project | Cookieless, EU-hosted |
| Accessibility | Nothing for users to solve | Challenge can block assistive tech |
| Conversion impact | Zero added steps | Challenge adds a step on risk |
| Free tier | Full engine, free tier, no card | Free tier with usage limits |
| Server verification | One verify call, ~20ms at the edge | Round-trip to verify endpoint |
Invisible at every risk level, not most of them
CaptchaFox is a reasonable EU choice, so the move is usually about the challenge fallback.
No challenge
CaptchaFox can present a challenge when risk is detected. TrustSig never does, so there is nothing on the page for a visitor to solve under any condition.
Hardware-level signals
Detection rests on deterministic hardware-level signals that are hard to spoof at scale, rather than on behaviour with a challenge behind it.
Dual-country footing
You are already EU-hosted with CaptchaFox. TrustSig hosts in Germany and is built in Estonia, so the company and the infrastructure sit in two EU countries.
One server verify
One verifyRemote() call on your server carries the verdict and the reasoning behind it, so the decision lives in your own code path.
Complete free engine
The free tier carries the complete deterministic threat engine and 5,000 requests a month, with detection at full strength.
Mobile conversion
Broad consumer traffic decides in seconds, and a challenge that might appear is a real drop-off. Nothing appears here.
Swap CaptchaFox for TrustSig
Delete the widget mount, then add the scan and one verify call on the server. Two npm packages, and your infrastructure is untouched.
- Frontend: remove the widget
// Before: CaptchaFox widget mount // <div className="captchafox" data-sitekey={SITE_KEY} /> // After: TrustSig (no element, runs in the background) import { useTrustSig } from "@trustsig/react" function ActionForm() { const { getResponse } = useTrustSig() const handleSubmit = async () => { const response = await getResponse() await fetch("/api/action", { headers: { "X-TrustSig-Response": response?.token || "" }, }) } } - Backend: replace the verify call
// Before: CaptchaFox (network round-trip) // await fetch("https://api.captchafox.com/siteverify", ...) // After: TrustSig (one verify call at the edge) import { TrustSig } from "@trustsig/server" const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY }) app.post("/api/action", async (req, res) => { const token = req.headers["x-trustsig-response"] const result = await ts.verifyRemote(token) if (result.action !== "ALLOW") return res.status(403).json({ error: "Blocked" }) })
Start free. Stay free until you grow.
EU-hosted on every tier.
Free
For personal projects and sites getting started with bot protection.
- 5,000 requests / month2 domains • 2 projects • 30-day retention
- Full Signal Coverage
- Device Intelligence
- Reasoned Risk Scoring
- No CAPTCHA for real users
- Community support
Scout
For growing businesses with moderate traffic and multiple properties.
- 30,000 requests / month10 domains • 5 projects • 90-day retention • €2 per extra 1,000
- Everything in Free
- Confidence Scoring
- Verified Bot Detection
- Email support
Scale
For established companies needing high-volume protection and priority SLA.
- 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
- Everything in Scout
- Custom Context
- Data Export
- Full Data Control
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
CaptchaFox alternative questions
Both are EU-aligned and privacy-minded. CaptchaFox can present a challenge widget on risk, where TrustSig has no widget at all and reads hardware-level signals, hosted in Germany.
Yes. There is no challenge under any risk condition. One SDK call runs the scan in the background, and a visitor never sees or does anything.
TrustSig is cookieless and processed only in Germany. It identifies the device rather than the person and scopes every device id to one project, so it runs on legitimate interest under Article 6(1)(f).
Around five minutes a form. Remove the widget mount, install the two TrustSig packages, and swap the verify call for verifyRemote().
The complete deterministic threat engine and 5,000 requests a month, with no credit card.
Keep EU processing and take the challenge out.
Free to start, nothing to solve, and nothing written to the device.











