Identify every device that lies.

TrustSig Pro reads the telemetry behind every device and links a rewritten fingerprint back to the hardware it left.

200+ detections, every one a switchCookie-free device identityEU-hosted and GDPR-native
Fingerprint rewrittenent_9a71c2047accounts on this hardware41 → 42sessions, 2 min apart
canvasa41c…9e7b02…d5
webgl stringsApple M2Intel UHD 620
fonts142 present38 present
user agentmacOS 14Windows 10
88/100Link confidence to the original hardware
Held constant
GPU decode profile, same silicon path+24
TLS fingerprint, unchanged JA4+24
Audio clock skew, identical drift+22
CPU concurrency, 8 logical cores+18
Fingerprint faked, hardware matched
01The platform

Trace any verdict back to one device record

Each layer hands back what it saw, so you can decide with your own logic.

02Resolve

A device can present a new fingerprint every session and still resolve to one identity.

01Collect

A token per page load. Nothing is written to the device.

03Decide

Allow, review or block, and the reasons that got there.

04Investigate

The device stays queryable long after the decision.

02Spoof linkage

A new fingerprint is not a new device

Anti-detect browsers rotate the fingerprint between sessions. TrustSig Pro reads the new one against the hardware it cannot rewrite.

Carries a spoof verdict

  • Platform against GPUclaims Windows, renders Apple
  • Proxied navigatornative getter overridden
  • Prototype tamperingiteration order rewritten
  • Diverged from a matched devicesame hardware, new mask

Recorded as context

  • Randomised canvasprivacy tooling, lower abuse
  • Blocked font enumerationa hardened browser
  • Reduced timer precisiona browser setting
  • Tor exit nodea network label

Spoofed devices and ban evasion

03Evidence

The evidence comes back with the verdict

See what the device claimed, and where measurement contradicts it.

  • Every detection that fired, with its weight and its evidence.
  • Named signals you can read on their own.
  • Where the device sits, and whose network it is on.
  • Pointer behaviour scored per session, idle sessions skipped.

200+detections behind those four, returned the same way

Device telemetry
Device classdesktop
Rendererreports Windows 11Apple M2
Cores / memory8 / 16 GB
Audio sample rate44,100 Hz
Timezonenetwork resolves to FrankfurtAmerica/Chicago
NetworkAS3320
ProtocolTLSv1.3
Integrity signals
Platform against GPUclaims Windows, renders Apple50
Property getter trapnavigator proxied100
Timezone against networklocale disagrees10
04Control

Every one of 200+ detections is yours to set

Off, observing or enforcing: you set the state per detection.

Observe records a group without moving a verdict, so you measure your own false-positive rate before promoting it.

Detection catalog
automationwebdriver, CDP, headless, proxy traps13
consistencyplatform against GPU, codecs, fonts, touch18
mobileemulator, root, mock location, sensors24
behavioralpointer paths, typing cadence, bursts21
fingerprintspoof links, memory claims, timestamps13
reputationbanned hardware, collisions, lists10
Pointer behaviour
Offnot evaluated
Observerecorded, never scored
Enforcemoves the verdict

Set the thresholds yourself

Thresholds and detection weights are edited per project. Changes land as a draft config version you activate deliberately, and every change is audit-logged.

Review 40Block 70
ALLOW
REVIEW
BLOCK
risk 0 · trusteddrag the handlesrisk 100 · certain
05Identity

Every account this device has touched

Send your own user IDs on the call and the answers come back in them.

  • Which other accounts have used this hardware, and how often.
  • The devices this account has used, and when each appeared.
  • Its alts, and the evidence behind each link.
  • How the device behaved before today, session by session.

Up to 12 monthsof device memory behind every answer

ent_9a71c204
Mar 04First seen
May 19Second account
Jul 02Fingerprint rewritten
Aug 11Humanizer detected
Trust
84 → 21
Sessions
412
Accounts on this deviceyour user IDs
u_4821signed up 04 Maru_990719 Mayu_1105802 Julu_30474banned 11 Augu_4829114 Aug2 more, joined this month
06Investigation

Action the whole cluster once

Fraud arrives in fleets. Devices that share evidence group into one connected component.

Cluster cl_2f19
Bot score0100
Accounts touched
61
First to last seen
9 days
Shared evidence
Pointer humanizersame library, same cadence19
Renderer stringone virtualised GPU24
Signup window07:00 to 07:40 UTC daily22
ASNsingle hosting range17

11more markers shared across the ring

OpenAll its devices, in one view.
ReplayFingerprint drift and detections, session by session.
ExportNDJSON or CSV into your own warehouse.
07Engines

Each action runs through its own engine

Post a login, a signup, a payment or any action you name. The engine for that kind weighs it against the device, the account and the history behind both.

Sign-inu_4821REVIEWnow
Action
4 min after a password reset
Device
first seen today
Accounts on it
1
Network
residential, Lisbon PT
64/100Risk, takeover engine
Weighted reasons
Reset then new device+35
Unknown hardware+25
Recent MFA success−18
Accounts on device, 24h
1
Devices on account, 28d
3
Step up before the session opens
Try another action
08Integration

Ship it without rebuilding your flows

Three steps, none of them visible to your visitors.

01Collect in the pageOne script tag. The SDK reads telemetry while the visitor fills your form.
index.html
<script src="https://epro.trustsig.eu/sdk/trustsig.js"        data-site-key="YOUR_SITE_KEY"        data-auto-scan="true" async></script>
02Verify where you decideOne server call returns the verdict and the evidence under it.
server.ts
const v = await pro.verify(token, {  user_id: user.id,  traits: { email: user.email },  include: ["alt"],});
if (v.blocked) return deny();if (v.alt?.is_alt) return review(v.alt.accounts);
03Score the actions you namePost the actions you care about and the engine answers with weighted reasons.
server.ts
const e = await pro.submitEvent({  kind: "payment_success",  user_id: user.id,  request_id: v.request_id,  metadata: { amount: "500" },});
if (e.blocked) return stepUp(e.reasons);
200+detections, individually switchable
15+detection groups
12 monthsconfigurable memory window
0cookies set or read

See what TrustSig Pro finds in your own traffic.

Talk to an expert
09Operations

See what every rule did after it ran

Open any verdict down to the policy version that produced it.

Rules

Compose your own logic and run it in shadow before it counts.

200+detections to write rules against, across 15+ groups

Analytics

Verdict trends, with config changes marked.

Lists

Your own allow and block entries.

Webhooks

Signed deliveries with a retry ledger.

Feedback

Your chargebacks and false positives, fed back.

Training mode

Everything logged while the decision stays advisory.

10Privacy

No cookies. Not one.

Device identity is computed from telemetry, never written to the visitor's machine. There is nothing to consent to, nothing to clear, and nothing an incognito window resets. Personal data you send lives in one erasable EU vault, never in analytics or a webhook payload.

EU-hosted, DPA availableIPs pseudonymised at restErasure cascades through every storeVPN and Tor are context only
How the data architecture works
11 Questions

TrustSig Pro, answered

A device intelligence and fraud platform. It resolves browser and mobile telemetry to a stable device identity, checks it against 200+ detections, and links accounts into an identity graph. Fraud engines score the business actions you send it, and every verdict comes back with the evidence behind it.

Standard protection answers one question at the edge: is this visitor a bot. TrustSig Pro answers the questions under it. Which telemetry is tampered with, which hardware a rotated fingerprint belongs to, and which other accounts sit on that hardware.

Anti-detect browsers rewrite canvas, WebGL, fonts, user agent and timezone so a returning fraudster looks new. TrustSig Pro checks the presented fingerprint for internal contradictions and against the hardware markers that held. The report names which fingerprint groups diverged.

Either. Every response carries the fired detections with severity, confidence and weight, plus geo and network enrichment, device class and velocity counters. Teams with their own fraud engine read that and ignore the verdict, and teams without one use the verdict and tune it.

Each detection has an on/off state, an observe or enforce mode and a weight, all set per project. Observe mode tells you a group's false-positive rate on your own traffic before it can move a verdict.

No cookies at all. Device identity is computed from telemetry, so an incognito window or a cleared browser resets nothing. Personal data you send us, like an email on an account, lives in one erasable EU vault.

A script tag on the page and one server-side call gets you decisions and evidence. Send your own user_id on that call and the identity layer comes with it: alt accounts, account sharing, device history per account. Login, signup and payment events take the same single call.

New projects run in a training window. Every verdict is computed, scored and logged while the returned decision stays advisory. Nothing in your integration changes when you turn enforcement on.

12Get started

Run TrustSig Pro against your own traffic

Tell us what you are protecting and what you are seeing. We will reply by email to set up access for your team.

  • EU-hosted and GDPR-native
  • Cookie-free device identity
  • Training mode before anything enforces