reCAPTCHA Alternative

The reCAPTCHA Alternative. That doesn't send your users to Google.

Swap the image grid for a check your visitors never see, and keep every request inside Germany. Cookieless, live in five minutes, and every device id is scoped to one project.

Complete threat engine on the free tier.

EU-hosted in GermanyGDPR Article 25 by design0 cookiesNo US data transfer
5 minto migrate
0cookies set
0user puzzles
Germanydata residency
01 Side by side

reCAPTCHA alternative, side by side

Both stop bots. Only one does it without a US data transfer, a cookie banner, and an image grid in front of your users.

CapabilityTrustSigGoogle reCAPTCHA
User frictionNone, fully invisibleImage grids, checkbox, v3 score gates
Data residencyEU only (Germany)Processed by Google, US transfer
Cookies and identifiersZero cookies, id scoped to one projectSets cookies, profiles users
GDPR postureLegitimate interest, Article 6(1)(f)Consent + Schrems II exposure
Detection methodHardware-level deterministic signalsBehavioural + reputation scoring
AccessibilityNothing for users to solveAudio/visual challenges fail screen readers
Free tierFull engine, free tier, no cardFree but data-funded
Server verificationOne verify call, ~20ms at the edgeRound-trip to Google on every verify
Strong
Partial
Weak / none
02 Why teams migrate

reCAPTCHA costs you a consent banner and a conversion step

Every item here is structural, not something you can tune in the console.

US data transfer

Every reCAPTCHA call ships behavioural data to Google in the US, which several EU data protection authorities have ruled on since Schrems II. TrustSig processes nothing outside the EU.

Consent banner

reCAPTCHA sets cookies and profiles visitors, so it is not a strictly necessary cookie and belongs behind consent. TrustSig sets none and runs on legitimate interest under Article 6(1)(f), so it loads before your banner does.

Conversion friction

Image grids and the v3 score gate add a step exactly when a human is trying to convert. TrustSig puts nothing in that path.

Accessibility barrier

Visual and audio challenges are a known barrier for assistive technology. There is no challenge for a screen reader to get stuck on.

Opaque scoring

A v3 score with no explanation is hard to tune and hard to defend in a review. verifyRemote() answers with a deterministic verdict and the reason codes behind it.

Data-funded pricing

reCAPTCHA is free because the data has value to Google. TrustSig's free tier carries the complete deterministic threat engine and is funded by the paid plans.

03 Migration

Replace reCAPTCHA in 5 minutes

Remove the reCAPTCHA script and the grecaptcha call, then add the scan and one verify call. Two npm packages, no infrastructure changes.

  1. Frontend: replace the widget
    // Before: reCAPTCHA
    // <script src="https://www.google.com/recaptcha/api.js" />
    // const token = await grecaptcha.execute(SITE_KEY, { action: "submit" })
    
    // After: TrustSig (no widget, nothing rendered)
    import { useTrustSig } from "@trustsig/react"
    
    function ActionForm() {
      const { getResponse } = useTrustSig()
    
      const handleSubmit = async () => {
        const response = await getResponse()
        await fetch("/api/action", {
          headers: { "X-TrustSig-Response": response?.token || "" },
        })
      }
    }
  2. Backend: replace the verify call
    // Before: reCAPTCHA (round-trip to Google)
    // await fetch("https://www.google.com/recaptcha/api/siteverify", ...)
    
    // After: TrustSig (one verify call at the edge)
    import { TrustSig } from "@trustsig/server"
    
    const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY })
    
    app.post("/api/action", async (req, res) => {
      const token = req.headers["x-trustsig-response"]
    
      const result = await ts.verifyRemote(token)
    
      if (result.action !== "ALLOW")
        return res.status(403).json({ error: "Blocked" })
    })
04 Pricing

Start free. Stay free until you grow.

EU-hosted on every tier.

Free

€0free

For personal projects and sites getting started with bot protection.

  • 5,000 requests / month2 domains • 2 projects • 30-day retention
  • Full Signal Coverage
  • Device Intelligence
  • Reasoned Risk Scoring
  • No CAPTCHA for real users
  • Community support

Scale

€95/mo · billed yearly

For established companies needing high-volume protection and priority SLA.

  • 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
  • Everything in Scout
  • Custom Context
  • Data Export
  • Full Data Control
  • Priority support

Enterprise: unlimited volume · SLAs · on-prem · dedicated support.

05 FAQ

reCAPTCHA migration questions

It can be, with consent. It sets cookies, profiles visitors and transfers data to Google in the US, which several EU data protection authorities have flagged since Schrems II. TrustSig sets no cookies, processes only in Germany, and identifies the device rather than the person with every id scoped to one project, so it runs on legitimate interest under Article 6(1)(f).

No. TrustSig reads deterministic hardware-level signals instead of a behavioural reputation score, so it catches automation that passes a v3 score gate without challenging a real user.

Remove the reCAPTCHA script and grecaptcha call, install @trustsig/react and @trustsig/server, and swap siteverify for verifyRemote(). Most teams finish a form in under five minutes.

Yes. Install the free plugin from https://wordpress.org/plugins/trustsig-security/, or search TrustSig under Plugins, Add New. It covers login, registration, comments and WooCommerce with no API key and no code.

The complete deterministic threat engine and 5,000 requests a month, with no credit card. Nothing in detection is held back for the paid plans.

For EU teams, the one that keeps the accuracy without the Google data transfer. TrustSig replaces reCAPTCHA invisibly, sets no cookies, and processes only in Germany.

Usually the Google data transfer first, then the friction of v2 image grids. Teams also cite v3 scores they cannot explain to a reviewer, and challenges their screen-reader users cannot pass.

EU regulators have treated specific deployments that way, where cookies, profiling and a Google transfer met weak consent. TrustSig removes the structure behind that: no cookies, no third-country transfer, and a device id scoped to one project.

The same swap works in React, Next.js, Vue and vanilla JS, and the WordPress plugin does it without touching code. Nothing about your hosting or CDN changes.

Move off reCAPTCHA without touching your conversion path.

Start free in minutes, with no card and no Google round-trip.