hCaptcha Alternative

The hCaptcha Alternative. For GDPR-conscious teams.

Take the image puzzle off every form hCaptcha protects today, in about five minutes per form. Your visitors see nothing and solve nothing, and processing stays in Germany.

Complete threat engine, no puzzle to solve.

EU-hosted in GermanyGDPR Article 25 by design0 puzzles0 cookies
0image puzzles
0cookies set
5 minto migrate
Germanydata residency
01 Side by side

hCaptcha vs TrustSig, side by side

hCaptcha improved on reCAPTCHA's data handling and kept the visual puzzle. These rows cover friction, accessibility and residency.

CapabilityTrustSighCaptcha
User frictionNone, fully invisibleImage-selection puzzle / checkbox
Data residencyEU only (Germany)Global CDN, US-incorporated vendor
Cookies and identifiersZero cookies, id scoped to one projectSets cookies for challenge state
Detection methodHardware-level deterministic signalsBehavioural + the puzzle itself
AccessibilityNothing for users to solveVisual challenge blocks assistive tech
Conversion impactZero added stepsEvery challenge is a drop-off point
Free tierFull engine, free tier, no cardFree tier with usage caps
Server verificationOne verify call, ~20ms at the edgeRound-trip to verify endpoint
Strong
Partial
Weak / none
02 Why teams migrate

The puzzle is what teams want gone

hCaptcha answered the reCAPTCHA data question. These are the ones it left open.

Puzzle friction

Selecting buses and crosswalks is friction whoever runs it. On a mobile landing page where a visitor decides in seconds, every challenge is a measurable drop in conversion.

Accessibility barrier

A visual selection task is a hard barrier for screen-reader and motor-impaired users. Removing the task removes the barrier with it.

Solver farms

Visual challenges are economically defeated by solver farms. Spoofing hardware-level signals at that scale is a much harder job than clicking the right tiles.

EU-only processing

TrustSig processes only in Germany. One jurisdiction to name in a review, rather than a global CDN footprint to map.

Zero cookies

TrustSig sets no cookies and runs on legitimate interest under Article 6(1)(f), so it stays out of your banner and never delays a paid landing page.

Complete free engine

The free tier carries the complete deterministic threat engine and 5,000 requests a month, with no card. Nothing in detection is held back.

03 Migration

Replace hCaptcha in 5 minutes

Remove the hCaptcha widget and its verify endpoint, then add the scan and one verify call. Two npm packages, nothing else to install.

  1. Frontend: remove the widget
    // Before: hCaptcha
    // <script src="https://js.hcaptcha.com/1/api.js" />
    // <div className="h-captcha" data-sitekey={SITE_KEY} />
    
    // After: TrustSig (no widget element)
    import { useTrustSig } from "@trustsig/react"
    
    function ActionForm() {
      const { getResponse } = useTrustSig()
    
      const handleSubmit = async () => {
        const response = await getResponse()
        await fetch("/api/action", {
          headers: { "X-TrustSig-Response": response?.token || "" },
        })
      }
    }
  2. Backend: replace the verify call
    // Before: hCaptcha (network round-trip)
    // await fetch("https://api.hcaptcha.com/siteverify", ...)
    
    // After: TrustSig (one verify call at the edge)
    import { TrustSig } from "@trustsig/server"
    
    const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY })
    
    app.post("/api/action", async (req, res) => {
      const token = req.headers["x-trustsig-response"]
    
      const result = await ts.verifyRemote(token)
    
      if (result.action !== "ALLOW")
        return res.status(403).json({ error: "Blocked" })
    })
04 Pricing

Start free. Stay free until you grow.

EU-hosted on every tier.

Free

€0free

For personal projects and sites getting started with bot protection.

  • 5,000 requests / month2 domains • 2 projects • 30-day retention
  • Full Signal Coverage
  • Device Intelligence
  • Reasoned Risk Scoring
  • No CAPTCHA for real users
  • Community support

Scale

€95/mo · billed yearly

For established companies needing high-volume protection and priority SLA.

  • 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
  • Everything in Scout
  • Custom Context
  • Data Export
  • Full Data Control
  • Priority support

Enterprise: unlimited volume · SLAs · on-prem · dedicated support.

05 FAQ

hCaptcha migration questions

Yes. No widget, no checkbox, no image task. The scan runs in the background from a single SDK call, so a real user never sees or does anything.

It is built to be stronger against automation. Hardware-level deterministic signals are harder to spoof than a visual puzzle, which solver farms defeat economically.

Usually under five minutes per form. Remove the hCaptcha script and div, install the two TrustSig packages, and swap siteverify for verifyRemote().

Cookieless, processed only in Germany, and identifying the device rather than the person, with every id scoped to one project. That is the basis for legitimate interest under Article 6(1)(f).

5,000 requests a month, with the deterministic engine complete and no card required.

Image puzzles cost conversion on mobile landing pages and fail screen-reader users. Solver farms defeat the puzzle economically, and a clearance cookie complicates the consent flow.

The differentiators are residency, friction and detection model. TrustSig is built on hardware-level signals, hosts only in the EU, and puts no challenge in front of a visitor at any risk level.

The same swap works in Next.js, Vue and vanilla JS, and the WordPress plugin does it without touching code. Your hosting and CDN stay exactly as they are.

Keep the protection. Drop the puzzle.

Start free in minutes, invisible on every form you protect today.