The hCaptcha Alternative. For GDPR-conscious teams.
Take the image puzzle off every form hCaptcha protects today, in about five minutes per form. Your visitors see nothing and solve nothing, and processing stays in Germany.
Complete threat engine, no puzzle to solve.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
hCaptcha vs TrustSig, side by side
hCaptcha improved on reCAPTCHA's data handling and kept the visual puzzle. These rows cover friction, accessibility and residency.
| Capability | TrustSig | hCaptcha |
|---|---|---|
| User friction | None, fully invisible | Image-selection puzzle / checkbox |
| Data residency | EU only (Germany) | Global CDN, US-incorporated vendor |
| Cookies and identifiers | Zero cookies, id scoped to one project | Sets cookies for challenge state |
| Detection method | Hardware-level deterministic signals | Behavioural + the puzzle itself |
| Accessibility | Nothing for users to solve | Visual challenge blocks assistive tech |
| Conversion impact | Zero added steps | Every challenge is a drop-off point |
| Free tier | Full engine, free tier, no card | Free tier with usage caps |
| Server verification | One verify call, ~20ms at the edge | Round-trip to verify endpoint |
The puzzle is what teams want gone
hCaptcha answered the reCAPTCHA data question. These are the ones it left open.
Puzzle friction
Selecting buses and crosswalks is friction whoever runs it. On a mobile landing page where a visitor decides in seconds, every challenge is a measurable drop in conversion.
Accessibility barrier
A visual selection task is a hard barrier for screen-reader and motor-impaired users. Removing the task removes the barrier with it.
Solver farms
Visual challenges are economically defeated by solver farms. Spoofing hardware-level signals at that scale is a much harder job than clicking the right tiles.
EU-only processing
TrustSig processes only in Germany. One jurisdiction to name in a review, rather than a global CDN footprint to map.
Zero cookies
TrustSig sets no cookies and runs on legitimate interest under Article 6(1)(f), so it stays out of your banner and never delays a paid landing page.
Complete free engine
The free tier carries the complete deterministic threat engine and 5,000 requests a month, with no card. Nothing in detection is held back.
Replace hCaptcha in 5 minutes
Remove the hCaptcha widget and its verify endpoint, then add the scan and one verify call. Two npm packages, nothing else to install.
- Frontend: remove the widget
// Before: hCaptcha // <script src="https://js.hcaptcha.com/1/api.js" /> // <div className="h-captcha" data-sitekey={SITE_KEY} /> // After: TrustSig (no widget element) import { useTrustSig } from "@trustsig/react" function ActionForm() { const { getResponse } = useTrustSig() const handleSubmit = async () => { const response = await getResponse() await fetch("/api/action", { headers: { "X-TrustSig-Response": response?.token || "" }, }) } } - Backend: replace the verify call
// Before: hCaptcha (network round-trip) // await fetch("https://api.hcaptcha.com/siteverify", ...) // After: TrustSig (one verify call at the edge) import { TrustSig } from "@trustsig/server" const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY }) app.post("/api/action", async (req, res) => { const token = req.headers["x-trustsig-response"] const result = await ts.verifyRemote(token) if (result.action !== "ALLOW") return res.status(403).json({ error: "Blocked" }) })
Start free. Stay free until you grow.
EU-hosted on every tier.
Free
For personal projects and sites getting started with bot protection.
- 5,000 requests / month2 domains • 2 projects • 30-day retention
- Full Signal Coverage
- Device Intelligence
- Reasoned Risk Scoring
- No CAPTCHA for real users
- Community support
Scout
For growing businesses with moderate traffic and multiple properties.
- 30,000 requests / month10 domains • 5 projects • 90-day retention • €2 per extra 1,000
- Everything in Free
- Confidence Scoring
- Verified Bot Detection
- Email support
Scale
For established companies needing high-volume protection and priority SLA.
- 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
- Everything in Scout
- Custom Context
- Data Export
- Full Data Control
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
hCaptcha migration questions
Yes. No widget, no checkbox, no image task. The scan runs in the background from a single SDK call, so a real user never sees or does anything.
It is built to be stronger against automation. Hardware-level deterministic signals are harder to spoof than a visual puzzle, which solver farms defeat economically.
Usually under five minutes per form. Remove the hCaptcha script and div, install the two TrustSig packages, and swap siteverify for verifyRemote().
Cookieless, processed only in Germany, and identifying the device rather than the person, with every id scoped to one project. That is the basis for legitimate interest under Article 6(1)(f).
5,000 requests a month, with the deterministic engine complete and no card required.
Image puzzles cost conversion on mobile landing pages and fail screen-reader users. Solver farms defeat the puzzle economically, and a clearance cookie complicates the consent flow.
The differentiators are residency, friction and detection model. TrustSig is built on hardware-level signals, hosts only in the EU, and puts no challenge in front of a visitor at any risk level.
The same swap works in Next.js, Vue and vanilla JS, and the WordPress plugin does it without touching code. Your hosting and CDN stay exactly as they are.
Keep the protection. Drop the puzzle.
Start free in minutes, invisible on every form you protect today.











