The reCAPTCHA Alternative. That doesn't send your users to Google.
Swap the image grid for a check your visitors never see, and keep every request inside Germany. Cookieless, live in five minutes, and every device id is scoped to one project.
Complete threat engine on the free tier.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
reCAPTCHA alternative, side by side
Both stop bots. Only one does it without a US data transfer, a cookie banner, and an image grid in front of your users.
| Capability | TrustSig | Google reCAPTCHA |
|---|---|---|
| User friction | None, fully invisible | Image grids, checkbox, v3 score gates |
| Data residency | EU only (Germany) | Processed by Google, US transfer |
| Cookies and identifiers | Zero cookies, id scoped to one project | Sets cookies, profiles users |
| GDPR posture | Legitimate interest, Article 6(1)(f) | Consent + Schrems II exposure |
| Detection method | Hardware-level deterministic signals | Behavioural + reputation scoring |
| Accessibility | Nothing for users to solve | Audio/visual challenges fail screen readers |
| Free tier | Full engine, free tier, no card | Free but data-funded |
| Server verification | One verify call, ~20ms at the edge | Round-trip to Google on every verify |
reCAPTCHA costs you a consent banner and a conversion step
Every item here is structural, not something you can tune in the console.
US data transfer
Every reCAPTCHA call ships behavioural data to Google in the US, which several EU data protection authorities have ruled on since Schrems II. TrustSig processes nothing outside the EU.
Consent banner
reCAPTCHA sets cookies and profiles visitors, so it is not a strictly necessary cookie and belongs behind consent. TrustSig sets none and runs on legitimate interest under Article 6(1)(f), so it loads before your banner does.
Conversion friction
Image grids and the v3 score gate add a step exactly when a human is trying to convert. TrustSig puts nothing in that path.
Accessibility barrier
Visual and audio challenges are a known barrier for assistive technology. There is no challenge for a screen reader to get stuck on.
Opaque scoring
A v3 score with no explanation is hard to tune and hard to defend in a review. verifyRemote() answers with a deterministic verdict and the reason codes behind it.
Data-funded pricing
reCAPTCHA is free because the data has value to Google. TrustSig's free tier carries the complete deterministic threat engine and is funded by the paid plans.
Replace reCAPTCHA in 5 minutes
Remove the reCAPTCHA script and the grecaptcha call, then add the scan and one verify call. Two npm packages, no infrastructure changes.
- Frontend: replace the widget
// Before: reCAPTCHA // <script src="https://www.google.com/recaptcha/api.js" /> // const token = await grecaptcha.execute(SITE_KEY, { action: "submit" }) // After: TrustSig (no widget, nothing rendered) import { useTrustSig } from "@trustsig/react" function ActionForm() { const { getResponse } = useTrustSig() const handleSubmit = async () => { const response = await getResponse() await fetch("/api/action", { headers: { "X-TrustSig-Response": response?.token || "" }, }) } } - Backend: replace the verify call
// Before: reCAPTCHA (round-trip to Google) // await fetch("https://www.google.com/recaptcha/api/siteverify", ...) // After: TrustSig (one verify call at the edge) import { TrustSig } from "@trustsig/server" const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY }) app.post("/api/action", async (req, res) => { const token = req.headers["x-trustsig-response"] const result = await ts.verifyRemote(token) if (result.action !== "ALLOW") return res.status(403).json({ error: "Blocked" }) })
Start free. Stay free until you grow.
EU-hosted on every tier.
Free
For personal projects and sites getting started with bot protection.
- 5,000 requests / month2 domains • 2 projects • 30-day retention
- Full Signal Coverage
- Device Intelligence
- Reasoned Risk Scoring
- No CAPTCHA for real users
- Community support
Scout
For growing businesses with moderate traffic and multiple properties.
- 30,000 requests / month10 domains • 5 projects • 90-day retention • €2 per extra 1,000
- Everything in Free
- Confidence Scoring
- Verified Bot Detection
- Email support
Scale
For established companies needing high-volume protection and priority SLA.
- 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
- Everything in Scout
- Custom Context
- Data Export
- Full Data Control
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
reCAPTCHA migration questions
It can be, with consent. It sets cookies, profiles visitors and transfers data to Google in the US, which several EU data protection authorities have flagged since Schrems II. TrustSig sets no cookies, processes only in Germany, and identifies the device rather than the person with every id scoped to one project, so it runs on legitimate interest under Article 6(1)(f).
No. TrustSig reads deterministic hardware-level signals instead of a behavioural reputation score, so it catches automation that passes a v3 score gate without challenging a real user.
Remove the reCAPTCHA script and grecaptcha call, install @trustsig/react and @trustsig/server, and swap siteverify for verifyRemote(). Most teams finish a form in under five minutes.
Yes. Install the free plugin from https://wordpress.org/plugins/trustsig-security/, or search TrustSig under Plugins, Add New. It covers login, registration, comments and WooCommerce with no API key and no code.
The complete deterministic threat engine and 5,000 requests a month, with no credit card. Nothing in detection is held back for the paid plans.
For EU teams, the one that keeps the accuracy without the Google data transfer. TrustSig replaces reCAPTCHA invisibly, sets no cookies, and processes only in Germany.
Usually the Google data transfer first, then the friction of v2 image grids. Teams also cite v3 scores they cannot explain to a reviewer, and challenges their screen-reader users cannot pass.
EU regulators have treated specific deployments that way, where cookies, profiling and a Google transfer met weak consent. TrustSig removes the structure behind that: no cookies, no third-country transfer, and a device id scoped to one project.
The same swap works in React, Next.js, Vue and vanilla JS, and the WordPress plugin does it without touching code. Nothing about your hosting or CDN changes.
Move off reCAPTCHA without touching your conversion path.
Start free in minutes, with no card and no Google round-trip.











