Cloudflare Turnstile Alternative

The Cloudflare Turnstile Alternative. Independent, EU-hosted, invisible.

Turnstile fits if your stack already lives on Cloudflare. TrustSig reads the same kind of invisible signal on Vercel, AWS or bare metal, from an independent vendor that processes only in Germany.

Complete threat engine, no Cloudflare account.

No Cloudflare account neededWorks with any infrastructureEU-hosted in Germany0 cookies
0vendor accounts required
0cookies set
5 minto migrate
Germanydata residency
01 Side by side

Turnstile alternative, side by side

Turnstile is a strong invisible option tied to Cloudflare's ecosystem. These rows cover residency, vendor dependency and the verify path.

CapabilityTrustSigCloudflare Turnstile
Vendor dependencyIndependent, no account elsewhereRequires a Cloudflare account
Infrastructure fitAny host, any CDN, any stackBest inside the Cloudflare ecosystem
Data residencyEU only (Germany)US-incorporated, global edge
User frictionNone, fully invisibleMostly invisible, can show a widget
Detection methodHardware-level deterministic signalsBehavioural + network reputation
Cookies and identifiersZero cookies, id scoped to one projectSets a clearance cookie
Free tierFull engine, free tier, no cardFree, tied to Cloudflare onboarding
Server verificationOne verify call, ~20ms at the edgeRound-trip to Cloudflare to verify
Strong
Partial
Weak / none
02 Why teams migrate

Turnstile assumes you run on Cloudflare

These are the reasons teams give for keeping bot defense separate from their CDN.

Cloudflare dependency

Turnstile is built to shine inside Cloudflare's ecosystem and needs a Cloudflare account. TrustSig has no such dependency and behaves the same on Vercel, AWS or bare metal.

US incorporation

Cloudflare is US-incorporated with a global edge. Where a review needs one jurisdiction named, TrustSig processes only in Germany.

CDN coupling

Tying detection to your CDN turns a CDN migration into a security migration. A separate layer keeps the two decisions apart.

Clearance cookie

Turnstile sets a clearance cookie. TrustSig sets none, so it stays out of your cookie banner and your cookie policy.

Deterministic verdicts

verifyRemote() answers with a deterministic verdict and the reason codes behind it, so an ALLOW is something you can explain.

Complete free engine

The free tier carries the complete deterministic threat engine and 5,000 requests a month, with no card and no CDN onboarding.

03 Migration

Turnstile replacement in 5 minutes

Remove the Turnstile widget and its siteverify call, then add the scan and one verify call. Two npm packages, and no account anywhere else.

  1. Frontend: remove the widget
    // Before: Cloudflare Turnstile
    // <script src="https://challenges.cloudflare.com/turnstile/v0/api.js" />
    // <div className="cf-turnstile" data-sitekey={SITE_KEY} />
    
    // After: TrustSig (no element, no Cloudflare account)
    import { useTrustSig } from "@trustsig/react"
    
    function ActionForm() {
      const { getResponse } = useTrustSig()
    
      const handleSubmit = async () => {
        const response = await getResponse()
        await fetch("/api/action", {
          headers: { "X-TrustSig-Response": response?.token || "" },
        })
      }
    }
  2. Backend: replace the verify call
    // Before: Turnstile (round-trip to Cloudflare)
    // await fetch("https://challenges.cloudflare.com/turnstile/v0/siteverify", ...)
    
    // After: TrustSig (one verify call at the edge)
    import { TrustSig } from "@trustsig/server"
    
    const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY })
    
    app.post("/api/action", async (req, res) => {
      const token = req.headers["x-trustsig-response"]
    
      const result = await ts.verifyRemote(token)
    
      if (result.action !== "ALLOW")
        return res.status(403).json({ error: "Blocked" })
    })
04 Pricing

Start free. Stay free until you grow.

EU-hosted on every tier.

Free

€0free

For personal projects and sites getting started with bot protection.

  • 5,000 requests / month2 domains • 2 projects • 30-day retention
  • Full Signal Coverage
  • Device Intelligence
  • Reasoned Risk Scoring
  • No CAPTCHA for real users
  • Community support

Scale

€95/mo · billed yearly

For established companies needing high-volume protection and priority SLA.

  • 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
  • Everything in Scout
  • Custom Context
  • Data Export
  • Full Data Control
  • Priority support

Enterprise: unlimited volume · SLAs · on-prem · dedicated support.

05 FAQ

Turnstile migration questions

No. TrustSig is an independent vendor with no relationship to Cloudflare, and it behaves the same whether or not you use Cloudflare for anything else.

Yes. Vercel, Netlify, AWS, your own servers, any CDN or none. Neither the frontend SDK nor the server verify assumes a host.

More so. Turnstile is usually invisible but can present a widget, where TrustSig has no UI element at all and reads hardware-level signals in the background.

Only in Germany, with no cookies and no transfer outside the EU. Every device id is scoped to one project, so it never follows a visitor to another site.

The complete deterministic threat engine and 5,000 requests a month, with no card and no CDN onboarding.

Turnstile is a privacy step up from reCAPTCHA and is tied to Cloudflare. reCAPTCHA carries documented GDPR risk. TrustSig sits outside both ecosystems as an independent EU vendor, invisible and deterministic.

It drops the Cloudflare account dependency without giving up invisibility, and adds single-jurisdiction EU residency, zero cookies and one verify call at the edge.

Remove the Turnstile script and the cf-turnstile div, install @trustsig/react and @trustsig/server, and swap siteverify for verifyRemote(). Most teams are done with a form inside five minutes.

Run invisible bot defense with no account anywhere else.

Start free in minutes. Any host, any CDN, processed in Germany.