The Cloudflare Turnstile Alternative. Independent, EU-hosted, invisible.
Turnstile fits if your stack already lives on Cloudflare. TrustSig reads the same kind of invisible signal on Vercel, AWS or bare metal, from an independent vendor that processes only in Germany.
Complete threat engine, no Cloudflare account.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Turnstile alternative, side by side
Turnstile is a strong invisible option tied to Cloudflare's ecosystem. These rows cover residency, vendor dependency and the verify path.
| Capability | TrustSig | Cloudflare Turnstile |
|---|---|---|
| Vendor dependency | Independent, no account elsewhere | Requires a Cloudflare account |
| Infrastructure fit | Any host, any CDN, any stack | Best inside the Cloudflare ecosystem |
| Data residency | EU only (Germany) | US-incorporated, global edge |
| User friction | None, fully invisible | Mostly invisible, can show a widget |
| Detection method | Hardware-level deterministic signals | Behavioural + network reputation |
| Cookies and identifiers | Zero cookies, id scoped to one project | Sets a clearance cookie |
| Free tier | Full engine, free tier, no card | Free, tied to Cloudflare onboarding |
| Server verification | One verify call, ~20ms at the edge | Round-trip to Cloudflare to verify |
Turnstile assumes you run on Cloudflare
These are the reasons teams give for keeping bot defense separate from their CDN.
Cloudflare dependency
Turnstile is built to shine inside Cloudflare's ecosystem and needs a Cloudflare account. TrustSig has no such dependency and behaves the same on Vercel, AWS or bare metal.
US incorporation
Cloudflare is US-incorporated with a global edge. Where a review needs one jurisdiction named, TrustSig processes only in Germany.
CDN coupling
Tying detection to your CDN turns a CDN migration into a security migration. A separate layer keeps the two decisions apart.
Clearance cookie
Turnstile sets a clearance cookie. TrustSig sets none, so it stays out of your cookie banner and your cookie policy.
Deterministic verdicts
verifyRemote() answers with a deterministic verdict and the reason codes behind it, so an ALLOW is something you can explain.
Complete free engine
The free tier carries the complete deterministic threat engine and 5,000 requests a month, with no card and no CDN onboarding.
Turnstile replacement in 5 minutes
Remove the Turnstile widget and its siteverify call, then add the scan and one verify call. Two npm packages, and no account anywhere else.
- Frontend: remove the widget
// Before: Cloudflare Turnstile // <script src="https://challenges.cloudflare.com/turnstile/v0/api.js" /> // <div className="cf-turnstile" data-sitekey={SITE_KEY} /> // After: TrustSig (no element, no Cloudflare account) import { useTrustSig } from "@trustsig/react" function ActionForm() { const { getResponse } = useTrustSig() const handleSubmit = async () => { const response = await getResponse() await fetch("/api/action", { headers: { "X-TrustSig-Response": response?.token || "" }, }) } } - Backend: replace the verify call
// Before: Turnstile (round-trip to Cloudflare) // await fetch("https://challenges.cloudflare.com/turnstile/v0/siteverify", ...) // After: TrustSig (one verify call at the edge) import { TrustSig } from "@trustsig/server" const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY }) app.post("/api/action", async (req, res) => { const token = req.headers["x-trustsig-response"] const result = await ts.verifyRemote(token) if (result.action !== "ALLOW") return res.status(403).json({ error: "Blocked" }) })
Start free. Stay free until you grow.
EU-hosted on every tier.
Free
For personal projects and sites getting started with bot protection.
- 5,000 requests / month2 domains • 2 projects • 30-day retention
- Full Signal Coverage
- Device Intelligence
- Reasoned Risk Scoring
- No CAPTCHA for real users
- Community support
Scout
For growing businesses with moderate traffic and multiple properties.
- 30,000 requests / month10 domains • 5 projects • 90-day retention • €2 per extra 1,000
- Everything in Free
- Confidence Scoring
- Verified Bot Detection
- Email support
Scale
For established companies needing high-volume protection and priority SLA.
- 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
- Everything in Scout
- Custom Context
- Data Export
- Full Data Control
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
Turnstile migration questions
No. TrustSig is an independent vendor with no relationship to Cloudflare, and it behaves the same whether or not you use Cloudflare for anything else.
Yes. Vercel, Netlify, AWS, your own servers, any CDN or none. Neither the frontend SDK nor the server verify assumes a host.
More so. Turnstile is usually invisible but can present a widget, where TrustSig has no UI element at all and reads hardware-level signals in the background.
Only in Germany, with no cookies and no transfer outside the EU. Every device id is scoped to one project, so it never follows a visitor to another site.
The complete deterministic threat engine and 5,000 requests a month, with no card and no CDN onboarding.
Turnstile is a privacy step up from reCAPTCHA and is tied to Cloudflare. reCAPTCHA carries documented GDPR risk. TrustSig sits outside both ecosystems as an independent EU vendor, invisible and deterministic.
It drops the Cloudflare account dependency without giving up invisibility, and adds single-jurisdiction EU residency, zero cookies and one verify call at the edge.
Remove the Turnstile script and the cf-turnstile div, install @trustsig/react and @trustsig/server, and swap siteverify for verifyRemote(). Most teams are done with a form inside five minutes.
Run invisible bot defense with no account anywhere else.
Start free in minutes. Any host, any CDN, processed in Germany.











