Case study
Fintech · Estonia

How LEI System eliminated API abuse and form spam — without a single CAPTCHA

LEI System — the official Legal Entity Identifier registration agent — was fighting contact-form spam and competitors scraping its APIs. One free WordPress plugin later, the abuse was gone. Real applicants never noticed a thing.

API abuse eliminated0 false positivesLive in 5 minutes

No credit card · Free forever tier

No CAPTCHANo visitor cookiesEU-hostedGDPR-native
01 The numbers

A clean block rate. Zero false positives.

Early results from LEI System's first 30 days on TrustSig — led by the rate and the zero, not an inflated lifetime total.

0

false positives. Not one genuine LEI applicant was wrongly blocked — because TrustSig never asks a human to prove anything, and never sits in their way.

79%Of form & API traffic blockedautomated requests, first 30 days
23,800Bot submissions & API calls stoppedkept out of the inbox and the dataset
0msAdded to page loadchecks run asynchronously, out-of-band

Figures cover LEI System's first 30 days on TrustSig — roughly 30,000 requests across its contact form and public APIs. Real numbers, kept conservative.

02 The challenge

Junk in the inbox. Competitors in the API.

Two abuse problems at once — and a CAPTCHA could only ever touch one of them.

LEI System's contact form was buried under automated spam, drowning real registration enquiries in junk the team had to clear by hand.

At the same time, competitors were hammering its public APIs — scraping pricing and entire company and LEI lists to copy the data and undercut it. There is no human on an API call to show a puzzle to, so a CAPTCHA was useless against the bigger problem.

They needed one solution that covered the contact form and the APIs, stayed invisible to real people, never routed visitor data through a US ad-tech vendor, and could go live without re-architecting anything.

They had already tried other anti-bot services — none of them stopped the sophisticated, persistent attackers. That ruled out the usual suspects. It is the exact gap TrustSig was built for.

03 The solution

Invisible verification that never blocks a real user.

TrustSig reads hardware-level signals in the browser, turns them into a signed token, and verifies it asynchronously and out-of-band — no puzzle, no image grid, nothing added to the page a visitor loads.

01

Silent fingerprint

On page load, the TrustSig SDK gathers hardware and browser signals invisibly. No checkbox, no images, nothing for the visitor to do.

02

Signed token

Those signals become a short-lived, signed token attached to each form submission and API call — meaningless to replay, hard to forge.

03

Asynchronous check

The token is verified out-of-band, outside the request path. Abusive automated requests are turned away; real people are never delayed, queued, or interrupted.

LEI System runs on the free TrustSig tier, so going live took exactly one step: install the WordPress plugin. Five minutes, no developer, and not a single form or API route had to change.

04 The results

Bots locked out. The inbox and APIs, clean.

The abuse stopped — and not one real applicant noticed a thing.

Across its first 30 days on TrustSig — roughly 30,000 requests to the protected contact form and APIs — 23,800 automated submissions and abusive API calls were blocked, about 79% of all traffic.

Most importantly: zero false positives. Not one genuine applicant was wrongly stopped — because verification never asks a human to do anything, and never sits in their way.

The contact inbox went back to real enquiries only, the pricing and company-list APIs stopped leaking to competitors, and the team stopped losing hours to clearing junk.

We were drowning in relentless API abuse. We tried other anti-bot services — none of them stopped the sophisticated attackers. Then we switched to TrustSig, and it eliminated every last trace of the API abuse we were dealing with.
LEI System · Fintech · Estonia
05 Why it worked

What you can't do with a CAPTCHA.

The same four properties that won LEI System over ship on every TrustSig plan — including the free tier.

Invisible

No puzzles, no image grids. Real users never see it — so it never costs you a conversion.

EU-hosted

Hosted in the EU and GDPR-native. Visitor data is never routed through US ad-tech.

Non-blocking

Verification runs asynchronously and out-of-band. Nothing is added to your page load, and a real user is never delayed or queued.

Covers APIs too

Not just browser forms — TrustSig guards your API endpoints against scraping and abuse, where a CAPTCHA can't reach.

06 Pricing

Start free. Stay free until you grow.

No card. EU-hosted on every tier.

Starter

€0free

For personal projects and sites getting started with bot protection.

  • 50,000 requests / month2 domains
  • Full threat protection suite
  • Bot farm blocking
  • No CAPTCHAs for visitors
  • Community support

Business

€63/mo · billed yearly

For established companies needing high-volume protection and priority SLA.

  • 750,000 requests / month25 domains • €5 per 100k extra reqs
  • Full threat protection suite
  • Bot farm blocking
  • No CAPTCHAs for visitors
  • Priority support

Enterprise: unlimited volume · SLAs · on-prem · dedicated support.

What counts as a check?

One check is a single verification request: a page view, form submit, or login attempt that TrustSig evaluates. You only spend a check when traffic actually hits a protected surface, so bot floods do not quietly drain your quota.

07 Questions

Common questions

No. TrustSig verification is completely invisible — there is no checkbox, puzzle, or image grid. Applicants fill the form exactly as before, legitimate API calls go through untouched, and the bot check runs asynchronously in the background.

Stop bots before they reach your forms and APIs.

The same invisible protection LEI System uses — free to start, live in five minutes, and not one CAPTCHA your visitors will ever curse at.