Sort the crawler from the scraper.

TrustSig Pro labels what arrived from the traces the automation left behind, and returns the evidence that put it in that class.

Automation evidence, not request ratesKnown agents validated by networkClusters for the fleets behind it
Claims to be Googlebot203.0.113.44Fake botnowhosting range, not Google1,204 requests in 6 min/search, /pricing
Verified crawlerreverse-DNS and ASN both check outallow
Declared AI agentidentifies itself, behaves like itallow
Fake verified botclaims Googlebot from a hosting rangeblock
Automation frameworkWebDriver or CDP traces presentblock
Stealth scraperreal browser, machine cadence, no pointerreview
Humancoherent hardware, human pointer profileallow
Evidence behind it
Property getter trap, navigator proxied+36
Impossible typing cadence, no dwell+24
Worker env disagrees with main thread+22
Software renderer, no GPU behind it+14
Fake Googlebot, caught by its network

Six classes of arrival, three verdicts.

01Evidence

Traces, not guesses

A user agent is a claim. TrustSig Pro scores what the automation had to touch in order to hide.

01Driver tracesWebDriver flags, CDP runtime leaks, headless-only API gaps and the iteration-order changes a patched navigator leaves behind.
02Proxy overheadFaking a property means trapping its getter. The extra call cost on cookies, languages and locale is measurable in the browser.
03Engine identityEval length, JIT tier behaviour, math implementations and worker-environment agreement identify the real engine behind the claim.
04Render realitySoftware renderers, dropped frames, GPU profiles that contradict the declared platform, and canvas output that cannot come from that stack.
05Human motionLinear pointer paths, synthetic constant velocity, impossible typing cadence and the cursor-humanizer libraries nobody installs by accident.
06Identity claimsA user agent claiming a verified crawler is checked against the network it actually arrives from before the claim counts for anything.
02The hard case

One careful visit proves nothing

A real browser on real hardware, driven by a machine and paced to look bored, beats any single-session check.

  • Pointer behaviour is scored per session and carried as a lifetime profile for the device.
  • Idle sessions are reported and never scored, because plenty of real people fill a form with a keyboard.
  • Fingerprint drift, detections and scores are kept on a timeline you can replay for any device.
  • Evidence that lands after the token was minted can tighten the verdict, never loosen it.
ent_9a71c204
Mar 04First seen
May 19Second account
Jul 02Fingerprint rewritten
Aug 11Humanizer detected
Trust
84 → 21
Sessions
412
Accounts on this deviceyour user IDs
u_4821signed up 04 Maru_990719 Mayu_1105802 Julu_30474banned 11 Augu_4829114 Aug2 more, joined this month
03Your call

Decide which bots get through

Which classes you serve, watch or refuse is yours to set.

server.tssignals
const v = await pro.verify(token);
v.signals.automation;          // webdriver / headless / CDP evidencev.signals.fake_verified_bot;   // claims Googlebot, arrives from hostingv.enrichment.agent_label;      // "Googlebot", "curl", ""v.enrichment.bot_class;        // taxonomy class for this devicev.behavior.mouse;              // { state, score, lifetime_score }
if (v.enrichment.agent_category === "search_engine") return serve();
Let throughVerified crawlers and declared AI agents that identify themselves and behave as claimed, validated against the network they arrive from.
WatchTraffic that looks automated but harms nothing yet, counted and reported without being touched.
StopForged crawler identities, driven browsers and scraping fleets, blocked at the action rather than behind a puzzle nobody solves.
04At scale

Scrapers arrive as fleets

One operator runs hundreds of profiles. Devices that share evidence group into one cluster, so you action the whole campaign once instead of device by device.

Cluster cl_2f19
Bot score0100
Accounts touched
61
First to last seen
9 days
Shared evidence
Pointer humanizersame library, same cadence19
Renderer stringone virtualised GPU24
Signup window07:00 to 07:40 UTC daily22
ASNsingle hosting range17

11more markers shared across the ring

Point it at the traffic your current tool calls human.

Talk to an expert
05 Questions

Bot classification, answered

Direct evidence rather than heuristics: WebDriver and CDP traces, headless-specific API gaps, proxy-getter overhead, JS-engine mismatches, and GPU profiles that contradict the claimed platform. Pointer and typing behaviour no human produces counts too. That is the automation group alone, before browser integrity, engine and graphics run.

By not judging a single session. A machine-driven browser still leaves override traces, still renders on the hardware it has, and still keeps machine-perfect cadence across visits. Device history, cluster membership and pointer profiles accumulate, so the disguise has to hold on every visit.

Yes. Known agents are labelled and categorised, and a claimed verified crawler is validated against the network it arrives from. You decide per category what allow, watch and block mean.

No. VPN sits at zero weight by default, and network context is a label rather than bot evidence. Accounts with a consistent history build reputation that pulls their score down.

Scrapers and signup farms run on many devices at once. Devices that share evidence group into one connected component, so a whole campaign is investigated and actioned once.

07Get started

Run it against your own traffic

Tell us what is being scraped or automated and what you have tried. We will reply by email to set up access for your team.

  • EU-hosted and GDPR-native
  • Cookie-free device identity
  • Training mode before anything enforces