Enterprise-grade bot defense. Without the enterprise sales call.
DataDome is a capable platform sold through a demo and a contract. Turn TrustSig on yourself today: invisible hardware-level detection, public pricing, processed in Germany.
Complete threat engine, no sales call.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
TrustSig vs DataDome
DataDome is sold and run as a managed enterprise platform. These rows cover how you start, what you deploy and where the data sits.
| Capability | TrustSig | DataDome |
|---|---|---|
| How you start | Self-serve, free, in minutes | Demo request and sales process |
| Pricing | Public, transparent, free tier | Quote-based enterprise contracts |
| User friction | None, fully invisible | Invisible, challenge on risk |
| Data residency | EU only (Germany) | Multi-region, US-aligned vendor |
| Detection method | Hardware-level deterministic signals | ML behavioural detection |
| Integration weight | Two npm packages, no infra change | Edge/server module deployment |
| Cookies and identifiers | Zero cookies, id scoped to one project | Sets cookies for device tracking |
| Server verification | One verify call, ~20ms at the edge | Managed edge decisioning |
Buy it without a contract or an edge module
The mismatch is the buying motion and the deployment weight, not the detection.
No sales process
DataDome is bought through a demo and a contract. TrustSig is self-serve: create an account, integrate, ship. The free tier needs no card and no call.
Public pricing
Quote-based enterprise pricing makes a budget hard to write before the call. TrustSig's plans are published, and the free tier carries the full engine.
Two npm packages
Install the client and server packages and add one verify call, instead of deploying and operating a managed edge module in your request path.
One jurisdiction
TrustSig processes only in Germany, sets no cookies, and scopes every device id to one project. That is one jurisdiction to document, not a multi-region data map.
Deterministic verdicts
verifyRemote() answers with a verdict and the reason codes behind it, so a blocked signup comes with the evidence for it.
No enterprise overhead
You get invisible hardware-level protection without an enterprise process wrapped around it, and you add volume when you need it.
Add TrustSig in minutes
Nothing to deploy at the edge. Add the scan on the frontend and one verify call on the server, in two npm packages.
- Frontend: invisible scan
import { useTrustSig } from "@trustsig/react" function ActionForm() { const { getResponse } = useTrustSig() const handleSubmit = async () => { const response = await getResponse() await fetch("/api/action", { headers: { "X-TrustSig-Response": response?.token || "" }, }) } } - Backend: one verify call
import { TrustSig } from "@trustsig/server" const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY }) app.post("/api/action", async (req, res) => { const token = req.headers["x-trustsig-response"] const result = await ts.verifyRemote(token) if (result.action !== "ALLOW") return res.status(403).json({ error: "Blocked" }) })
Start free. Stay free until you grow.
EU-hosted on every tier.
Free
For personal projects and sites getting started with bot protection.
- 5,000 requests / month2 domains • 2 projects • 30-day retention
- Full Signal Coverage
- Device Intelligence
- Reasoned Risk Scoring
- No CAPTCHA for real users
- Community support
Scout
For growing businesses with moderate traffic and multiple properties.
- 30,000 requests / month10 domains • 5 projects • 90-day retention • €2 per extra 1,000
- Everything in Free
- Confidence Scoring
- Verified Bot Detection
- Email support
Scale
For established companies needing high-volume protection and priority SLA.
- 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
- Everything in Scout
- Custom Context
- Data Export
- Full Data Control
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
DataDome alternative questions
Yes. The free tier is the complete threat engine and 5,000 requests a month, and it needs no sales call and no credit card.
The detection model is hardware-level and deterministic, and the paid plans scale request volume on published pricing. You start small and grow without renegotiating a contract.
Much lighter. There is no edge or server module to deploy and operate, just two npm packages and one verify call, with no infrastructure changes.
Only in Germany, with no cookies. Every device id is scoped to one project, so the same machine returns a different id to every customer.
The same detection engine the paid plans run, at 5,000 requests a month, with no card.
Start today, without a sales call in the way.
Self-serve, published pricing, hosted in Germany. No credit card.











