No cookies. Not one.
TrustSig Pro recognises devices from telemetry, not from anything left on the visitor's machine, keeps every trait you send in one erasable EU store, and puts no PII in analytics or a webhook payload.
- Traits in analytics
- none
- PII in webhooks
- none
- Consent banner needed
- no
Where the data sits.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Recognise a returning device with nothing stored on it
Device identity is computed from what the browser and the hardware reveal while the page runs. No cookie banner to negotiate, no consent state to carry.
- No cookie is set or read, on any surface, in any flow.
- Nothing is written to local storage. An incognito window resets nothing on our side.
- If you keep the session handle we return, it lives on your origin and TrustSig never reads it.
- Cohort-grade hardware comes back marked as weak identity rather than guessed at.
PII has exactly one home
Traits you choose to send land in one erasable store and travel no further. Everything downstream sees pseudonyms and your own identifiers, so erasure is one operation.
Privacy tools are not evidence of fraud
A careful visitor and an attacker reach for the same tools. Scoring the tool instead of the behaviour refuses your best customers.
Walk your DPO through where every field sits.
Talk to an expertDelete once, and it is gone
An erasure request cascades through the account profile, its device links, its reputation contribution and its event history. No shadow copy is kept for training.
Privacy, answered
No cookies at all. Device identity is computed from telemetry, never written to the visitor's machine, so an incognito window resets nothing. If you store the session handle we return, it lives on your own origin and TrustSig never reads it.
EU infrastructure. Personal data you attach to an account, like email, name or phone, is stored in one erasable vault and nowhere else. Analytics, exports and webhook payloads carry pseudonyms and your own user IDs, never those traits.
Deleting an account cascades through its profile, its device links, its reputation contribution and its event history. IPs are pseudonymised at rest rather than stored raw, so a reputation entry survives without holding the address it came from.
None is mandatory. A user_id you control is enough for the identity layer. Traits like email are optional and buy one thing each, such as matching mailbox variants across signups.
No. Those are context labels that cannot block on their own. Privacy markers such as randomised canvas are reported the same way, and they correlate with lower abuse rates.
A DPA is available, and retention windows are configurable per project rather than fixed by us. The behavioural memory window that drives detection quality is the same setting, up to twelve months.
Ask the same platform a different question
Every page below runs on the same telemetry, the same device identity and the same detection catalog.
Take it through your own review
Tell us what your compliance team needs to see. We will reply by email and set up access for your team.
- EU-hosted and GDPR-native
- Cookie-free device identity
- Training mode before anything enforces











