Identify every device that lies.
TrustSig Pro reads the telemetry behind every device and links a rewritten fingerprint back to the hardware it left.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Trace any verdict back to one device record
Each layer hands back what it saw, so you can decide with your own logic.
A device can present a new fingerprint every session and still resolve to one identity.
A token per page load. Nothing is written to the device.
Allow, review or block, and the reasons that got there.
The device stays queryable long after the decision.
A new fingerprint is not a new device
Anti-detect browsers rotate the fingerprint between sessions. TrustSig Pro reads the new one against the hardware it cannot rewrite.
Carries a spoof verdict
- Platform against GPUclaims Windows, renders Apple
- Proxied navigatornative getter overridden
- Prototype tamperingiteration order rewritten
- Diverged from a matched devicesame hardware, new mask
Recorded as context
- Randomised canvasprivacy tooling, lower abuse
- Blocked font enumerationa hardened browser
- Reduced timer precisiona browser setting
- Tor exit nodea network label
The evidence comes back with the verdict
See what the device claimed, and where measurement contradicts it.
- Every detection that fired, with its weight and its evidence.
- Named signals you can read on their own.
- Where the device sits, and whose network it is on.
- Pointer behaviour scored per session, idle sessions skipped.
200+detections behind those four, returned the same way
Every one of 200+ detections is yours to set
Off, observing or enforcing: you set the state per detection.
Observe records a group without moving a verdict, so you measure your own false-positive rate before promoting it.
Set the thresholds yourself
Thresholds and detection weights are edited per project. Changes land as a draft config version you activate deliberately, and every change is audit-logged.
Every account this device has touched
Send your own user IDs on the call and the answers come back in them.
- Which other accounts have used this hardware, and how often.
- The devices this account has used, and when each appeared.
- Its alts, and the evidence behind each link.
- How the device behaved before today, session by session.
Up to 12 monthsof device memory behind every answer
- Trust
- 84 → 21
- Sessions
- 412
Action the whole cluster once
Fraud arrives in fleets. Devices that share evidence group into one connected component.
- Accounts touched
- 61
- First to last seen
- 9 days
11more markers shared across the ring
Each action runs through its own engine
Post a login, a signup, a payment or any action you name. The engine for that kind weighs it against the device, the account and the history behind both.
- Action
- 4 min after a password reset
- Device
- first seen today
- Accounts on it
- 1
- Network
- residential, Lisbon PT
- Accounts on device, 24h
- 1
- Devices on account, 28d
- 3
Ship it without rebuilding your flows
Three steps, none of them visible to your visitors.
<script src="https://epro.trustsig.eu/sdk/trustsig.js" data-site-key="YOUR_SITE_KEY" data-auto-scan="true" async></script>const v = await pro.verify(token, { user_id: user.id, traits: { email: user.email }, include: ["alt"],});
if (v.blocked) return deny();if (v.alt?.is_alt) return review(v.alt.accounts);const e = await pro.submitEvent({ kind: "payment_success", user_id: user.id, request_id: v.request_id, metadata: { amount: "500" },});
if (e.blocked) return stepUp(e.reasons);See what TrustSig Pro finds in your own traffic.
Talk to an expertSee what every rule did after it ran
Open any verdict down to the policy version that produced it.
Compose your own logic and run it in shadow before it counts.
200+detections to write rules against, across 15+ groups
Verdict trends, with config changes marked.
Your own allow and block entries.
Signed deliveries with a retry ledger.
Your chargebacks and false positives, fed back.
Everything logged while the decision stays advisory.
No cookies. Not one.
Device identity is computed from telemetry, never written to the visitor's machine. There is nothing to consent to, nothing to clear, and nothing an incognito window resets. Personal data you send lives in one erasable EU vault, never in analytics or a webhook payload.
TrustSig Pro, answered
A device intelligence and fraud platform. It resolves browser and mobile telemetry to a stable device identity, checks it against 200+ detections, and links accounts into an identity graph. Fraud engines score the business actions you send it, and every verdict comes back with the evidence behind it.
Standard protection answers one question at the edge: is this visitor a bot. TrustSig Pro answers the questions under it. Which telemetry is tampered with, which hardware a rotated fingerprint belongs to, and which other accounts sit on that hardware.
Anti-detect browsers rewrite canvas, WebGL, fonts, user agent and timezone so a returning fraudster looks new. TrustSig Pro checks the presented fingerprint for internal contradictions and against the hardware markers that held. The report names which fingerprint groups diverged.
Either. Every response carries the fired detections with severity, confidence and weight, plus geo and network enrichment, device class and velocity counters. Teams with their own fraud engine read that and ignore the verdict, and teams without one use the verdict and tune it.
Each detection has an on/off state, an observe or enforce mode and a weight, all set per project. Observe mode tells you a group's false-positive rate on your own traffic before it can move a verdict.
No cookies at all. Device identity is computed from telemetry, so an incognito window or a cleared browser resets nothing. Personal data you send us, like an email on an account, lives in one erasable EU vault.
A script tag on the page and one server-side call gets you decisions and evidence. Send your own user_id on that call and the identity layer comes with it: alt accounts, account sharing, device history per account. Login, signup and payment events take the same single call.
New projects run in a training window. Every verdict is computed, scored and logged while the returned decision stays advisory. Nothing in your integration changes when you turn enforcement on.
Run TrustSig Pro against your own traffic
Tell us what you are protecting and what you are seeing. We will reply by email to set up access for your team.
- EU-hosted and GDPR-native
- Cookie-free device identity
- Training mode before anything enforces











