Sort the crawler from the scraper.
TrustSig Pro labels what arrived from the traces the automation left behind, and returns the evidence that put it in that class.
Six classes of arrival, three verdicts.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Traces, not guesses
A user agent is a claim. TrustSig Pro scores what the automation had to touch in order to hide.
One careful visit proves nothing
A real browser on real hardware, driven by a machine and paced to look bored, beats any single-session check.
- Pointer behaviour is scored per session and carried as a lifetime profile for the device.
- Idle sessions are reported and never scored, because plenty of real people fill a form with a keyboard.
- Fingerprint drift, detections and scores are kept on a timeline you can replay for any device.
- Evidence that lands after the token was minted can tighten the verdict, never loosen it.
- Trust
- 84 → 21
- Sessions
- 412
Decide which bots get through
Which classes you serve, watch or refuse is yours to set.
const v = await pro.verify(token);
v.signals.automation; // webdriver / headless / CDP evidencev.signals.fake_verified_bot; // claims Googlebot, arrives from hostingv.enrichment.agent_label; // "Googlebot", "curl", ""v.enrichment.bot_class; // taxonomy class for this devicev.behavior.mouse; // { state, score, lifetime_score }
if (v.enrichment.agent_category === "search_engine") return serve();Scrapers arrive as fleets
One operator runs hundreds of profiles. Devices that share evidence group into one cluster, so you action the whole campaign once instead of device by device.
- Accounts touched
- 61
- First to last seen
- 9 days
11more markers shared across the ring
Point it at the traffic your current tool calls human.
Talk to an expertBot classification, answered
Direct evidence rather than heuristics: WebDriver and CDP traces, headless-specific API gaps, proxy-getter overhead, JS-engine mismatches, and GPU profiles that contradict the claimed platform. Pointer and typing behaviour no human produces counts too. That is the automation group alone, before browser integrity, engine and graphics run.
By not judging a single session. A machine-driven browser still leaves override traces, still renders on the hardware it has, and still keeps machine-perfect cadence across visits. Device history, cluster membership and pointer profiles accumulate, so the disguise has to hold on every visit.
Yes. Known agents are labelled and categorised, and a claimed verified crawler is validated against the network it arrives from. You decide per category what allow, watch and block mean.
No. VPN sits at zero weight by default, and network context is a label rather than bot evidence. Accounts with a consistent history build reputation that pulls their score down.
Scrapers and signup farms run on many devices at once. Devices that share evidence group into one connected component, so a whole campaign is investigated and actioned once.
Ask the same platform a different question
Every page below runs on the same telemetry, the same device identity and the same detection catalog.
Run it against your own traffic
Tell us what is being scraped or automated and what you have tried. We will reply by email to set up access for your team.
- EU-hosted and GDPR-native
- Cookie-free device identity
- Training mode before anything enforces











