Catch the bad signups, logins and payments before they cost you.
TrustSig Pro checks every login, signup and payment the moment it happens, then answers in milliseconds: let it through, ask for one more step, or stop it. No CAPTCHAs. No blocking real customers.
EU-hosted, GDPR-native. Verdicts in milliseconds.
Sample traffic. The verdict, reason and latency shape of the live fraud API.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
One question, asked of everything that matters.
Standard bot protection asks whether a visitor is a bot. TrustSig Pro asks the question that actually costs you money: is this account, on this device, doing this action, safe? You send the action, Pro answers allow, review or block, with the reason in plain language. One system, every action. You turn on only the parts you need.
Most tools say yes or no. The expensive mistakes live in the maybe.
Block or allow forces a brutal trade: catch the fraud, or turn away a real customer who just bought a new laptop. Pro keeps a third answer, so friction lands only where it is earned.
Clean signal, known history. The request sails through and nobody sees a thing.
Genuinely unsure. Ask for one more step: an MFA tap, a magic link, a quick check, instead of slamming the door on a maybe-customer.
Hard evidence, stopped at the moment of the action. A review never overrides a real block.
The bands are yours to move.
The block threshold, the review ceiling and every signal weight are editable per project. Replay your history to preview any change before it goes live.
One memory. Every kind of trouble.
Pro keeps a rolling memory of how accounts, devices and networks behave, over a window you tune up to 18 months, and every kind of fraud is a different question asked of that same memory. The takeover, the serial trial signup, the shared password, the ring of fake accounts, the patient scraper, and the ones particular to your business. One system, asked many ways. Turn one on, the rest are a switch away.
A snippet on the page. One call on the server.
Drop the TrustSig web SDK into your frontend once: it quietly collects a device signal and hands your backend a token. Server-side, you pass that token, plus an optional user_id, to a single verify call, and the verdict, risk score and plain-language reasons come back in the same response. No redirect flow, no rebuild, and nothing your real users ever see.
const result = await trustsig.verify({ token: req.body.trustsig_token, ip: req.ip,
// turn on account intelligence: user_id: req.user.id,});{ "action": "ALLOW", "risk": 12, "reasons": ["KNOWN_DEVICE"], "latency_ms": 38}See TrustSig Pro run on your own traffic.
Book a demoWe remember. That's how we catch the patient ones.
Rate limits see a burst. Single-session checks see a snapshot. TrustSig Pro keeps a rolling profile for every signal, over a window you set up to 18 months, read in single-digit milliseconds on the hot path. The fraudster who strikes once a week looks brand new to everyone else.
A control room, not a black box.
Every verdict is inspectable: the reasons behind it, the account and devices involved, and the exact policy version that produced it. Pro gives your team a full operations dashboard.
Sample data, shown to convey the layout and the signal shape.
Ready to stop guessing at every signup and login?
Book a demoPrivacy is the architecture, not the asterisk.
We stop fraud, not privacy. Built on privacy by design and by default, our service minimises the personal data we ever touch, lets you control exactly which categories of PII are processed, and makes data retention fully configurable. With erasure built in and a DPA available, your compliance is covered from the ground up.
TrustSig Pro, answered
Standard bot protection answers one question: is this visitor a bot? Pro answers the question that actually loses you money: is this account, on this device, doing this action, safe? It watches logins, signups, payments and any custom action in real time, remembers behaviour across accounts, devices and networks over a window you set, up to 90 days, and returns an allow, review or block verdict in milliseconds, all without a single CAPTCHA.
Two small pieces: a web SDK snippet on your frontend plus one server-side call. The snippet captures a device signal and hands your backend a token; you pass that token, plus an optional user_id, to a single verify call and read the verdict, risk score and plain-language reasons from the same response. Sending business events (login, signup, payment) is that same one-call shape, synchronous, with no redirect flow.
Review means step up, don't shut down. Instead of forcing a binary allow-or-block decision, ambiguous actions route to whatever step-up you choose: MFA, a second factor, or a manual queue. It kills false declines without trading away safety, and a review never overrides a genuine block.
No, by design. VPN, Tor and anti-fingerprinting signals are labels that add context; they can never cause a block on their own. Ambiguity routes to review instead of denial, and consistently-good accounts build trust that makes them structurally hard to false-flag.
EU-first. Personal data like email, name and phone lives in one erasable vault and nowhere else. Analytics and webhooks only ever see pseudonyms and your own user IDs. Deleting an account cascades through profiles, reputation and event history. GDPR compliance is the architecture, not a retrofit.
Yes. Every policy change lands as a draft, and you can replay a candidate policy against your real historical traffic to see exactly what would have been blocked, reviewed or allowed, scored against your own labelled outcomes, before you enforce anything.
See TrustSig Pro on your own traffic.
Tell us what you are trying to protect and why now. We will reply by email to set up access for your team.
- EU-hosted, GDPR-native
- No CAPTCHAs, no friction for your users
- Verdicts in milliseconds











