CaptchaFox Alternative

EU privacy, taken further. Hardware-level and fully invisible.

CaptchaFox shows a challenge when risk goes up. TrustSig reads hardware-level signals instead and shows nothing at any risk level, processed only in Germany.

Complete threat engine, no challenge widget.

EU-hosted in GermanyGDPR Article 25 by designNo challenge widget0 cookies
0challenges to solve
0cookies set
5 minto migrate
Germanydata residency
01 Side by side

TrustSig vs CaptchaFox

Both are EU-aligned and privacy-minded. These rows cover the challenge, the detection model and the verify path.

CapabilityTrustSigCaptchaFox
User-facing elementNone, no widget at allChallenge widget on risk
Detection methodHardware-level deterministic signalsBehavioural + challenge fallback
Data residencyEU only (Germany)EU (Germany)
Cookies and identifiersZero cookies, id scoped to one projectCookieless, EU-hosted
AccessibilityNothing for users to solveChallenge can block assistive tech
Conversion impactZero added stepsChallenge adds a step on risk
Free tierFull engine, free tier, no cardFree tier with usage limits
Server verificationOne verify call, ~20ms at the edgeRound-trip to verify endpoint
Strong
Partial
Weak / none
02 Why teams choose TrustSig

Invisible at every risk level, not most of them

CaptchaFox is a reasonable EU choice, so the move is usually about the challenge fallback.

No challenge

CaptchaFox can present a challenge when risk is detected. TrustSig never does, so there is nothing on the page for a visitor to solve under any condition.

Hardware-level signals

Detection rests on deterministic hardware-level signals that are hard to spoof at scale, rather than on behaviour with a challenge behind it.

Dual-country footing

You are already EU-hosted with CaptchaFox. TrustSig hosts in Germany and is built in Estonia, so the company and the infrastructure sit in two EU countries.

One server verify

One verifyRemote() call on your server carries the verdict and the reasoning behind it, so the decision lives in your own code path.

Complete free engine

The free tier carries the complete deterministic threat engine and 5,000 requests a month, with detection at full strength.

Mobile conversion

Broad consumer traffic decides in seconds, and a challenge that might appear is a real drop-off. Nothing appears here.

03 Migration

Swap CaptchaFox for TrustSig

Delete the widget mount, then add the scan and one verify call on the server. Two npm packages, and your infrastructure is untouched.

  1. Frontend: remove the widget
    // Before: CaptchaFox widget mount
    // <div className="captchafox" data-sitekey={SITE_KEY} />
    
    // After: TrustSig (no element, runs in the background)
    import { useTrustSig } from "@trustsig/react"
    
    function ActionForm() {
      const { getResponse } = useTrustSig()
    
      const handleSubmit = async () => {
        const response = await getResponse()
        await fetch("/api/action", {
          headers: { "X-TrustSig-Response": response?.token || "" },
        })
      }
    }
  2. Backend: replace the verify call
    // Before: CaptchaFox (network round-trip)
    // await fetch("https://api.captchafox.com/siteverify", ...)
    
    // After: TrustSig (one verify call at the edge)
    import { TrustSig } from "@trustsig/server"
    
    const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY })
    
    app.post("/api/action", async (req, res) => {
      const token = req.headers["x-trustsig-response"]
    
      const result = await ts.verifyRemote(token)
    
      if (result.action !== "ALLOW")
        return res.status(403).json({ error: "Blocked" })
    })
04 Pricing

Start free. Stay free until you grow.

EU-hosted on every tier.

Free

€0free

For personal projects and sites getting started with bot protection.

  • 5,000 requests / month2 domains • 2 projects • 30-day retention
  • Full Signal Coverage
  • Device Intelligence
  • Reasoned Risk Scoring
  • No CAPTCHA for real users
  • Community support

Scale

€95/mo · billed yearly

For established companies needing high-volume protection and priority SLA.

  • 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
  • Everything in Scout
  • Custom Context
  • Data Export
  • Full Data Control
  • Priority support

Enterprise: unlimited volume · SLAs · on-prem · dedicated support.

05 FAQ

CaptchaFox alternative questions

Both are EU-aligned and privacy-minded. CaptchaFox can present a challenge widget on risk, where TrustSig has no widget at all and reads hardware-level signals, hosted in Germany.

Yes. There is no challenge under any risk condition. One SDK call runs the scan in the background, and a visitor never sees or does anything.

TrustSig is cookieless and processed only in Germany. It identifies the device rather than the person and scopes every device id to one project, so it runs on legitimate interest under Article 6(1)(f).

Around five minutes a form. Remove the widget mount, install the two TrustSig packages, and swap the verify call for verifyRemote().

The complete deterministic threat engine and 5,000 requests a month, with no credit card.

Keep EU processing and take the challenge out.

Free to start, nothing to solve, and nothing written to the device.