5M+ bot checks processed

Stop every bot, know every device.

Score every request your public surfaces take, and read the evidence behind each verdict. Nothing leaves the EU.

This browser, right now
--/100trust scoreReading this browser

Device ID
Identity confidence
Returning
Connection
Reason codes
Device class
Browser
Operating system
Screen
Logical cores
Device memory
Graphics
Private window
Connection
Country
VPN
Tor
Datacenter
Mobile carrier
<script
  src="https://edge.trustsig.eu/trustsig.js"
  data-site-key="pk_live_41c44dc6fdfa1ade9a82d6de679eff9e"
  data-auto-scan="true"
></script>

<script>
const data = await window.TrustSig.getResponse();

await fetch('/api/login', {
  method: 'POST',
  headers: { 'X-TrustSig-Response': data?.token ?? '' },
  body: JSON.stringify({ email }),
});
</script>
Reading this browser
import { TrustSig } from '@trustsig/server';
const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY });

const result = await ts.verifyRemote(token);
if (result.is_bot) {
  console.warn('login denied', {
    request_id: result.request_id,
    device_id: result.identity.device_id,
    risk_score: result.risk.score,
    reason_codes: result.risk.reason_codes,
  });

  return res.status(403).json({ error: 'Access denied.' });
}
ZEROCookies set on a visitor
ZEROChallenges shown to a real user
200+Detections in the library, run on every request

02Evidence

A verdict tells you what to do. The evidence tells you why.

Every verify call returns the findings, free tier included.

Subject
device
9f1c04ab7e2d5610
network
datacenter, Frankfurt
sightings
47 in the last hour
Raised
  • AUTOMATION_DRIVERdriver attached
  • PLATFORM_MISMATCHdeclared os conflicts
  • TAMPERED_ENVIRONMENTbuilt-ins replaced
  • ANTI_DETECT_BROWSERknown engine
Clear
  • Automated pointernone
  • Token replaynone
  • VPN or Tornone
96risk scorecriticalBLOCK
Every call also returns
verdict
allow, challenge or block
risk
0 to 100, with reason codes
identity
one device, your project only
device
class, browser, operating system
network
vpn, tor, datacenter, mobile
integrity
automation and tampering
behaviour
pointer motion, scored
velocity
sightings per time window

A real visitor never sees a challenge.

Scoring starts when the page loads and finishes before anyone presses submit.

5stepsWith a CAPTCHA
  1. Presses submit
  2. Challenge appears
  3. Picks out the traffic lights
  4. Consent banner
  5. Submit lands
2stepsWith TrustSig
  1. Presses submit
  2. Submit lands

Gone with TrustSigStill the visitor's

03Going live

Your server gets the verdict before it answers the request.

  1. In the browser

    The SDK reads the device and attaches a token to the submit.

    Nothing is written to the visitor's device.

    React
    import { useTrustSig } from "@trustsig/react";
    
    const { getResponse } = useTrustSig();
    const { token } = await getResponse();
  2. On your server

    One call turns that token into a verdict, a device id and the reasons behind it.

    The same id comes back the next time that device shows up.

    Node
    import { TrustSig } from "@trustsig/server";
    
    const result = await ts.verifyRemote(token);
    
    if (result.is_bot) {
      console.warn('login denied', {
        request_id: result.request_id,
        device_id: result.identity.device_id,
        risk_score: result.risk.score,
        reason_codes: result.risk.reason_codes,
      });
      return res.status(403).json({ error: 'Blocked' });
    }
    
    analytics.track('login', {
      device_id: result.identity.device_id,
      country: result.network.country,
      device_class: result.device.class,
      browser: result.device.browser_family,
    });
Read the docs

04What we store

Nothing we store identifies your visitor.

The id TrustSig resolves never leaves your project.

  • EU hosted
  • No cookie to declare
  • Scoped to your project
Read our Privacy Notice
Kept
  • Trust signals
  • Risk score
  • Device id
Never
  • Names, usernames, emails
  • Cookies
  • Ids shared between customers

05 Platform Comparison

Cookieless, EU hosted, and it tells you why.

The other three in this table set a cookie on your visitor's device.

CapabilityTrustSigEU hosted · No cookies · InvisibleFingerprintreCAPTCHAhCaptcha
User frictionNone (invisible)None (invisible)Puzzle / clickPuzzle / click
EU-basedYes (EU)No (US)No (US)No (US)
GDPR-nativeYesPartialPartialNo
Bypass-resistantHardware-levelFingerprint-levelModerateEasily bypassed
Uses cookiesNoYesYesYes
Full detection on free tierYesNoNoLimited
Monetises user behaviourNeverNeverPartiallyYes
Tells you whyReason codesSignal flagsScore onlyPass / fail
Persistent device idYesYesNoNo
YesPartialNo

Comparison based on publicly available documentation, August 2026.

CapabilityTrustSigFingerprint
User frictionNone (invisible)None (invisible)
EU-basedYes (EU)No (US)
GDPR-nativeYesPartial
Bypass-resistantHardware-levelFingerprint-level
Uses cookiesNoYes
Full detection on free tierYesNo
Monetises user behaviourNeverNever
Tells you whyReason codesSignal flags
Persistent device idYesYes
6/9capabilities where TrustSig leads Fingerprint

Comparison based on publicly available documentation, August 2026.

06 Pricing

Start free. Stay free until you grow.

EU-hosted on every tier.

Free

€0free

For personal projects and sites getting started with bot protection.

  • 5,000 requests / month2 domains • 2 projects • 30-day retention
  • Full Signal Coverage
  • Device Intelligence
  • Reasoned Risk Scoring
  • No CAPTCHA for real users
  • Community support

Scale

€95/mo · billed yearly

For established companies needing high-volume protection and priority SLA.

  • 120,000 requests / month30 domains • 15 projects • 365-day retention • €1 per extra 1,000
  • Everything in Scout
  • Custom Context
  • Data Export
  • Full Data Control
  • Priority support

Enterprise: unlimited volume · SLAs · on-prem · dedicated support.

07 Common Questions

Frequently asked.

The verdict, plus the evidence behind it: a 0 to 100 risk grade, coarse reason codes, a project-scoped device id, and whether the request arrived over a VPN, Tor, a datacenter or a mobile carrier. Gate on the verdict, log the rest, or set your own threshold per surface.

TrustSig identifies the device, not the person on it. The id is derived from hardware and scoped to your project alone, so the same machine returns a different id to every customer. Nothing follows a visitor from your site to anyone else's. No cookie is set, and no name or email reaches TrustSig.

No. A CAPTCHA puts the work on the visitor. TrustSig scores the device and the request instead, then hands your backend a signed verdict to enforce.

Upload it and activate it. The free tier needs no signup and no key, and your forms, login and comments are covered from that moment.

Commercial farms solve CAPTCHAs for a fraction of a cent, which is why the challenge layer stopped being a defence. TrustSig scores the rendering environment instead: hardware attestation, timing and network origin. It raises the attacker's cost rather than ending the problem.

A single script tag, or the WordPress plugin. Scoring runs out of band, so nothing blocks your page load and nobody waits on a verdict. Most teams are protected in under an hour.

Yes. Add the client SDK to your frontend and verify the token on your server, and your existing forms and logins keep working. No reverse proxy, no rewrite, no migration project.

Yes. Free covers 5,000 requests a month, with the same detection library and the same device history the paid tiers get. Scout and Scale add volume, domains, retention, confidence scoring and verified bot detection.

Score your next request with the evidence behind it.

The free tier covers 5,000 requests a month, and you can pull the script back out the same day.

08Talk to us

Tell us what you need to protect.

Describe the abuse you are seeing, and we come back with what TrustSig would do about it.

  • A reply from an engineer, not a sales sequence
  • EU-hosted, nothing leaves the region
  • Every detection on every tier