The FriendlyCaptcha Alternative. Hardware-level and truly invisible.
Read hardware-level signals passively, with no widget on the page and no proof-of-work spending the visitor's battery. Cookieless, hosted in Germany, and running in five minutes.
Complete threat engine, no device-side compute.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Friendly Captcha vs TrustSig, side by side
Both are EU-hosted and cookieless. The difference is the detection model and how much of it runs on the visitor's machine.
| Capability | TrustSig | Friendly Captcha |
|---|---|---|
| User-facing element | None, no widget at all | Embedded widget with status text |
| Work on user's device | None, passive signal read | Proof-of-work computation in browser |
| Detection method | Hardware-level deterministic signals | Proof-of-work + behavioural heuristics |
| Data residency | EU only (Germany) | EU (Germany) |
| Cookies and identifiers | Zero cookies, id scoped to one project | Cookieless |
| Low-end device experience | No compute cost to the visitor | PoW can be slow on weak hardware |
| Free tier | Full engine, free tier, no card | Free tier with usage limits |
| Server verification | One verify call, ~20ms at the edge | Round-trip to verify endpoint |
TrustSig asks the visitor's device for nothing
Friendly Captcha is a solid EU choice, so the move is usually about the widget and the compute.
No widget
Friendly Captcha renders a small widget that shows progress. TrustSig puts no element on the page, so there is nothing for a visitor to notice or wait on.
No device compute
A proof-of-work check spends the visitor's CPU and battery, which shows on older phones. TrustSig reads existing hardware signals passively instead.
Deterministic verdict
verifyRemote() answers ALLOW or BLOCK with the reason codes behind it, rather than a difficulty parameter and a heuristic to tune.
Dual-country footing
Friendly Captcha and TrustSig both host in Germany. TrustSig is additionally built in Estonia, which puts the company and the infrastructure in two EU jurisdictions.
One server verify
One verifyRemote() call on your server carries the verdict, so the decision lives in your own code path.
Complete free engine
The free tier runs the full deterministic engine at 5,000 requests a month, with no card.
Swap Friendly Captcha for TrustSig
Remove the widget mount and its verify call, then add the scan and one verify call. Two npm packages, no infrastructure changes.
- Frontend: remove the widget mount
// Before: Friendly Captcha widget // <div className="frc-captcha" data-sitekey={SITE_KEY} /> // After: TrustSig (no element, nothing computed in the browser) import { useTrustSig } from "@trustsig/react" function ActionForm() { const { getResponse } = useTrustSig() const handleSubmit = async () => { const response = await getResponse() await fetch("/api/action", { headers: { "X-TrustSig-Response": response?.token || "" }, }) } } - Backend: replace the verify call
// Before: Friendly Captcha (network round-trip) // await fetch("https://api.friendlycaptcha.com/api/v1/siteverify", ...) // After: TrustSig (one verify call at the edge) import { TrustSig } from "@trustsig/server" const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY }) app.post("/api/action", async (req, res) => { const token = req.headers["x-trustsig-response"] const result = await ts.verifyRemote(token) if (result.action !== "ALLOW") return res.status(403).json({ error: "Blocked" }) })
Start free. Stay free until you grow.
EU-hosted on every tier.
Free
For personal projects and sites getting started with bot protection.
- 5,000 requests / month2 domains • 2 projects • 30-day retention
- Full Signal Coverage
- Device Intelligence
- Reasoned Risk Scoring
- No CAPTCHA for real users
- Community support
Scout
For growing businesses with moderate traffic and multiple properties.
- 30,000 requests / month10 domains • 5 projects • 90-day retention • €2 per extra 1,000
- Everything in Free
- Confidence Scoring
- Verified Bot Detection
- Email support
Scale
For established companies needing high-volume protection and priority SLA.
- 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
- Everything in Scout
- Custom Context
- Data Export
- Full Data Control
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
Friendly Captcha migration questions
Friendly Captcha is a cookieless EU widget that runs a proof-of-work puzzle in the browser. TrustSig has no widget, asks the device to compute nothing, and reads hardware-level signals passively.
It is, and the comparison is not about privacy. TrustSig is for teams that additionally want no visible element and no compute cost on the visitor's device.
On modern hardware the cost is small. On the older phones that broad consumer campaigns bring in, it can add a noticeable wait before the form submits.
Under five minutes a form is typical. Remove the widget mount, install the two TrustSig packages, and swap the siteverify call for verifyRemote().
The full deterministic engine at 5,000 requests a month, with no card.
Both start free and tier up by monthly request volume. TrustSig's free tier is 5,000 requests a month with the complete deterministic threat engine, then Scout at €29 and Scale at €119 as volume grows.
It is EU-built, cookieless, and a credible way off Google. The trade-off is a visible widget and a proof-of-work computation on the user's device, which is noticeable on older phones.
Pick Friendly Captcha if a small visible widget and proof-of-work fit your stack. Pick TrustSig when you need nothing on the page, hardware-level deterministic detection, and one verify call at the edge.
Yes. TrustSig is built on passive hardware signals rather than a browser puzzle, so nothing is asked of the device. On campaigns where mobile load is the conversion lever, that is the whole difference.
Run the check without a widget or a proof-of-work.
Nothing rendered, nothing computed on the device, hosted in Germany. Free to start.











