Engineering Blog.
Hardware-level signals, edge telemetry, and protocol defense – from the TrustSig engineering team.
BeyondTrust and LastPass Got Breached Through a Vendor They Plugged Into Salesforce
BeyondTrust, LastPass, and over a dozen other firms had Salesforce data stolen through the Klue compromise, a textbook supply chain breach that turned a connected app into an attacker's entry point.
Half of LG Smart TV Apps Are Quietly Running Residential Proxies
Spur Intelligence found residential proxy SDKs in over 2,000 LG webOS and Samsung Tizen apps, turning home TVs into proxy nodes and breaking IP reputation as a defense.
A Spy Agency Just Cleaned Your Neighbour's Router. The Bots Will Be Back.
Canada's CSIS used a first-of-its-kind threat reduction warrant to access and shut down two foreign botnets running on infected Canadian home routers and IoT devices, and here is what it means for anyone defending a product.
Reverse Once, Run Forever: Defending Code You Can't Hide
Every line of client-side bot detection runs on hardware the attacker fully owns. Here's the engineering philosophy we use to defend code we can never actually hide.
Bot Protection Without CAPTCHA: Why Agent Identity Changes Everything
AWS's Web Bot Auth moves bot defence from detection to cryptographic identity. We explain the shift, the gaps, vLEI as a neutral alternative — and why real protection never stops your users from clicking.
How Disability Sport Wales Stopped Bots Without Blocking a Single Disabled User
reCAPTCHA quietly locks out millions of disabled users every day. Here's how Disability Sport Wales replaced it with invisible bot protection — catching more bots while blocking zero real users.
Bot Attacks on E-Commerce Web Forms: Threats, Real Breaches & How to Protect Your Store in 2026
Bots now generate 53% of all web traffic. Discover how bot attacks on e-commerce web forms cause real data breaches, millions in losses, and learn proven security strategies to protect your store in 2026.
When Bot Mitigation Becomes Ecosystem Control: Analyzing Google's Play Services reCAPTCHA Dependency
A deep technical analysis of how the recent Google Cloud Fraud Defense update ties reCAPTCHA verification to proprietary Google Play Services, and why modern bot mitigation must remain independent of OS-level telemetry.
Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)
Build a Wasm-in-Wasm VM that turns readable code into a hardened binary using JIT page encryption to stop memory scrapers.
Website Form Bot Protection: The Complete 2026 Guide
Bots now generate 51% of web traffic. Learn how to stop AI-driven form spam, ditch failing CAPTCHAs, and protect your site with invisible, GDPR-compliant solutions.
Engineering TrustSig Lab: Building a High-Performance WebAssembly Reverse Engineering Workbench
A technical deep dive into the architecture of TrustSig Lab, our browser-native WebAssembly analysis tool. We explore the Rust-based analysis engine, stack-to-expression lifting, and concurrent frontend architecture.
Replacing Legacy Anti-Bot Providers With Zero-Latency Mitigation
Legacy CAPTCHA tools damage user experience and fail to stop automated attacks. We built an invisible, zero-latency alternative to secure your infrastructure.