Just the bot protection. Not a whole security suite to adopt.
Myra runs a managed WAF, CDN and DDoS suite. If the problem you have is fake signups and form spam, TrustSig covers it in two npm packages, with nothing to re-platform.
Complete threat engine, no onboarding call.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
TrustSig vs Myra Security
These rows cover scope, how you start, and what has to change in your request path.
| Capability | TrustSig | Myra Security |
|---|---|---|
| Scope | Focused: invisible bot & abuse defense | Broad WAF / CDN / DDoS suite |
| How you start | Self-serve, free, in minutes | Managed onboarding / sales process |
| Integration weight | Two npm packages, no infra change | Route traffic through managed edge |
| User friction | None, fully invisible | Challenge pages on risk |
| Detection method | Hardware-level deterministic signals | Network / WAF rule based |
| Data residency | EU only (Germany) | EU (Germany) |
| Pricing | Public, transparent, free tier | Quote-based managed contracts |
| Server verification | One verify call, ~20ms at the edge | Managed edge decisioning |
Add bot protection without moving your edge
Myra is a strong German security suite, so the mismatch is scope rather than quality.
Bot protection only
Adopting a managed WAF and CDN suite to stop form spam and abuse is a lot of surface to take on. TrustSig is the one piece, with nothing else to operate.
No re-platforming
Myra works by routing traffic through its managed edge. TrustSig is two npm packages and one verify call, so your infrastructure stays where it is.
Self-serve start
No managed onboarding and no sales motion. Create an account, integrate, ship, on a free tier that needs no card.
No challenge pages
Nothing interstitial appears when risk goes up. Real users carry on through the form and never see a page in between.
Dual-country footing
Myra and TrustSig both host in Germany, and TrustSig is additionally built in Estonia. The same EU footing, from an independent vendor doing one job.
Public pricing
Plans are published, and the free tier carries the complete deterministic engine rather than a sample of it.
Add TrustSig without touching your edge
Nothing routes through a managed edge. Two npm packages: the scan on the frontend, one verify call on the server.
- Frontend: invisible scan
import { useTrustSig } from "@trustsig/react" function ActionForm() { const { getResponse } = useTrustSig() const handleSubmit = async () => { const response = await getResponse() await fetch("/api/action", { headers: { "X-TrustSig-Response": response?.token || "" }, }) } } - Backend: verify on your server
import { TrustSig } from "@trustsig/server" const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY }) app.post("/api/action", async (req, res) => { const token = req.headers["x-trustsig-response"] const result = await ts.verifyRemote(token) if (result.action !== "ALLOW") return res.status(403).json({ error: "Blocked" }) })
Start free. Stay free until you grow.
EU-hosted on every tier.
Free
For personal projects and sites getting started with bot protection.
- 5,000 requests / month2 domains • 2 projects • 30-day retention
- Full Signal Coverage
- Device Intelligence
- Reasoned Risk Scoring
- No CAPTCHA for real users
- Community support
Scout
For growing businesses with moderate traffic and multiple properties.
- 30,000 requests / month10 domains • 5 projects • 90-day retention • €2 per extra 1,000
- Everything in Free
- Confidence Scoring
- Verified Bot Detection
- Email support
Scale
For established companies needing high-volume protection and priority SLA.
- 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
- Everything in Scout
- Custom Context
- Data Export
- Full Data Control
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
Myra Security alternative questions
No, and deliberately so. TrustSig covers invisible bot and abuse protection, so if stopping bots, fake signups and form spam is the job, you get that without adopting a managed edge suite.
No. No managed edge sits in your request path. The frontend SDK collects a signal and your server verifies it, so your infrastructure and CDN stay exactly as they are.
Yes. The free tier is the complete threat engine and 5,000 requests a month, with no credit card and no onboarding call.
Only in Germany. No cookies, and each project gets its own device id, so the same machine looks different to every customer.
5,000 requests a month, and detection is not cut down on the free plan.
Add it without changing your request path.
Focused, self-serve, hosted in Germany. No card to start.











