Bots don't fill in CAPTCHAs. They hit your API directly. We stop them anyway.
TrustSig Bot Management blocks credential stuffing, scraping, scalping and account takeover across every API, app and endpoint – whether the traffic comes from a headless browser or a raw script. Deterministic verdicts, invisible to real users.
Or start free in minutes – no sales call required.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
One engine. Both kinds of bot.
Whether an attacker drives a headless Chrome farm or fires raw HTTP at your API, the intent is the same – and so is the block. TrustSig scores every request on hardware and behavioural signals that automation can't fake.
01PRIMARY VECTOR
Credential stuffing & account takeover
Stolen password lists replayed against your login API at scale. The traffic looks like thousands of real sign-ins – until accounts start draining. TrustSig blocks the replay, not your users.
Scraping & content theft
Pricing, catalogues and proprietary data siphoned by scrapers – many running headless browsers to defeat simple rate limits.
Scalping & inventory hoarding
Bots that reserve stock, drops and appointments in milliseconds, locking out the customers you actually want.
Card testing & payment fraud
Stolen cards validated against your checkout and payment endpoints, racking up processor fees and chargebacks.
Fake account creation
Mass signups that poison your metrics, abuse free tiers and seed downstream fraud.
Headless browser automation
Puppeteer, Playwright, Selenium and anti-detect browsers that render JavaScript and pass classic checks. We detect the automation underneath.
Gift card & loyalty fraud
Bots brute-forcing gift-card balances and draining loyalty points through your redemption and balance-check endpoints.
Every request gets a verdict.
No proxy. No traffic rerouting. No rip-and-replace. A lightweight SDK reads device, behaviour and automation signals, seals them into a signed token, and your server checks that token locally – instantly, with no extra network call. The result is a clear allow or block, every time.
Fail-closed by design: if the token is missing or can't be verified, the request is treated as a threat – never waved through.
Two packages. Any stack.
A client SDK collects the signals. A server SDK verifies the token and hands you a verdict. No infrastructure changes, no traffic routed through us – drop it onto the endpoints that matter and ship.
Real users are scored invisibly in the background – no challenge, no friction. Your server verifies the token locally with zero added latency. Only unverified automation is blocked.
Built for teams that outgrew CAPTCHA.
Legacy bot vendors lock you into US clouds, opaque scoring and per-seat enterprise contracts. TrustSig is the opposite.
EU data hosting
Hosted entirely in the EU, with global low-latency delivery (EU-located visitors are served by EU servers).
Deterministic & explainable
Every verdict traces to concrete signals. No black-box ML score you can't audit or appeal.
Cookieless & GDPR-native
No tracking cookies, no consent banner, no PII required to score a request. Compliance is the default.
Fail-closed security
Unverifiable traffic is blocked, not waved through. Your posture doesn't degrade under load or attack.
TrustSig vs legacy bot management.
How an EU-native, deterministic engine compares to existing bot vendors.
| Capability | TrustSigEU-hosted · Cookieless · Deterministic | Legacy bot vendors |
|---|---|---|
| API + headless browser coverage | Both, one engine | Often separate add-ons |
| EU hosting | EU | US clouds |
| Cookieless / no consent banner | Cookieless | Tracking cookies |
| Explainable verdicts | Signal-level | Black-box ML |
| Deploy time | Minutes | Weeks + onboarding |
| Pricing transparency | Public, flat | Sales quote only |
| Free tier | All features | None |
Start free. Stay free until you grow.
No card. EU-hosted on every tier.
Starter
For personal projects and sites getting started with bot protection.
- 50,000 requests / month2 domains
- Full threat protection suite
- Bot farm blocking
- No CAPTCHAs for visitors
- Community support
Growth
For growing businesses with moderate traffic and multiple properties.
- 300,000 requests / month20 domains • €5 per 100k extra reqs
- Full threat protection suite
- Bot farm blocking
- No CAPTCHAs for visitors
- Email support
Business
For established companies needing high-volume protection and priority SLA.
- 750,000 requests / month25 domains • €5 per 100k extra reqs
- Full threat protection suite
- Bot farm blocking
- No CAPTCHAs for visitors
- Priority support
Enterprise: unlimited volume · SLAs · on-prem · dedicated support.
One check is a single verification request: a page view, form submit, or login attempt that TrustSig evaluates. You only spend a check when traffic actually hits a protected surface, so bot floods do not quietly drain your quota.
Bot management questions.
No. TrustSig never shows a challenge, puzzle or checkbox. It scores requests in the background and returns a verdict your app enforces – real users never see anything.
Yes. Puppeteer, Playwright, Selenium and anti-detect browsers render JavaScript and pass classic checks, but they leave automation tells in hardware, timing and network signals. TrustSig detects those whether the request comes from a browser or a raw HTTP client.
No. We intentionally protect only form submits and API calls. Page visits and crawling stay open, so Googlebot and other legitimate crawlers index your content without interference.
Data is hosted in the EU. A global content delivery network keeps content close to visitors for low-latency access, and EU visitors are served from EU-based servers. Please remember, no tracking cookies are set, and no personal data is required to score a request – GDPR-native by design.
The client SDK returns a signed token, your server verifies it locally with verifyLocal, and you gate on the verdict – a single allow-list check. No traffic is routed through us, and your app stays in control of what happens on a block.
No. Real users are scored invisibly in the background, and your server verifies the token locally with no network call – zero added latency. Nobody is delayed, redirected or challenged.
Stop automated abuse across every endpoint.
Book a walkthrough with our engineers, or start free and protect your first API today.











