Know exactly what is on your site.
Beyond bot-or-human: verified crawlers, declared AI agents, automation frameworks, headless scrapers, and the stealth scrapers that pass every single-session check. Pro classifies on behaviour over time, lets the good ones through, and names the rest.
EU-hosted. Verdicts in milliseconds.
One visitor's classification journey. Single sessions lie; cadence doesn't.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Pristine fingerprint. Machine cadence. Never sleeps.
A stealth scraper is a real browser driven by a machine, flawless in any one session. The disguise it can't keep up is time: request intervals no human produces, zero interaction, and a working day that never ends.
A “Googlebot” from a rented box is not Googlebot.
Claims are checked against infrastructure. A crawler's name is only believed when the network it arrives from actually belongs to it.
Tell the good bots from the scrapers.
Book a demoYour AI-crawler policy becomes a choice.
Classification is policy-neutral. You pick the response for each class, so SEO crawlers keep indexing, AI agents follow your rules instead of their defaults, and scrapers stop exploiting your catalogue. The classes below are a sample of the taxonomy.
Put a name on every visitor you already have.
Book a demoLabels, not punishments.
Datacenter origin, VPN and Tor are context that sharpens verdicts, never sentences on their own. Consistency checks do the heavy lifting, like a user agent claiming one OS while the device reports another, a timezone conflict, a missing language header. Those are a handful of many. Privacy-conscious humans stay welcome; liars get caught lying.
Every visitor, classified and queryable.
Bot classes flow into analytics (class mix, silent high-volume entities), into search filters, and into every entity response, so the stealth scraper that quietly read 40,000 pages this month stops being invisible.
{ "entity": "ent_7d02", "bot_class": "stealth_scraper", "trust_score": 4, "last_decision": "BLOCK", "observation_count": 47, "first_seen": "2026-05-14", "active_hours_per_day": 24}One signal layer. Every abuse pattern.
Each detection engine reads the same account, device and network memory – turn on one, the rest are a toggle away.
Bot classification, answered
Categories like verified search and infrastructure crawlers, declared AI agents and AI crawlers, automation frameworks, headless scrapers and stealth scrapers, the last being high-quality real browsers that pass single-session checks but reveal themselves over time. The taxonomy goes finer than that, and verified good bots are let through, not blindly blocked.
A real browser with a pristine fingerprint, driven by a machine. It looks human in any single session — but across visits it shows machine-perfect request cadence, zero human interaction, and round-the-clock activity. Pro classifies on accumulated behaviour, so the disguise fails within dozens of visits, not months.
A user agent claiming to be Googlebot is checked against the network it actually comes from. A 'Googlebot' arriving from a generic hosting provider is flagged as a spoof — the claim has to match the infrastructure.
Yes. Classification is policy-neutral: declared AI agents, verified crawlers and scrapers are separate categories, and you decide per category — allow, watch, or block. Your AI-access policy becomes a deliberate choice instead of a default.
No. VPN and Tor are context labels, never bot evidence and never automatic blocks. Pro's network intelligence adds signal for spoof detection and consistency checks without penalising privacy-conscious humans.
Tell the good bots from the scrapers.
Tell us what you are trying to protect and why now. We will reply by email to set up access for your team.
- EU-hosted, GDPR-native
- No CAPTCHAs, no friction for your users
- Verdicts in milliseconds











