No cookies. Not one.

TrustSig Pro recognises devices from telemetry, not from anything left on the visitor's machine, keeps every trait you send in one erasable EU store, and puts no PII in analytics or a webhook payload.

Nothing stored on the devicePII in one erasable vaultIPs pseudonymised at rest
Everything held for one useru_4821ErasabletodayEU-hosted12-month windowone call to erase
Your user IDopaque to us, yours to revokevault
Optional traitsemail, name, phone, only if you send themvault
Device telemetrycomputed, never written to the visitoranalytics
IPpseudonymised at restanalytics
On the visitor's device
0cookies set0bytes written
Traits in analytics
none
PII in webhooks
none
Consent banner needed
no
Nothing is written to the visitor

Where the data sits.

01Identity

Recognise a returning device with nothing stored on it

Device identity is computed from what the browser and the hardware reveal while the page runs. No cookie banner to negotiate, no consent state to carry.

  • No cookie is set or read, on any surface, in any flow.
  • Nothing is written to local storage. An incognito window resets nothing on our side.
  • If you keep the session handle we return, it lives on your origin and TrustSig never reads it.
  • Cohort-grade hardware comes back marked as weak identity rather than guessed at.
Device telemetry
Device classdesktop
Rendererreports Windows 11Apple M2
Cores / memory8 / 16 GB
Audio sample rate44,100 Hz
Timezonenetwork resolves to FrankfurtAmerica/Chicago
NetworkAS3320
ProtocolTLSv1.3
Integrity signals
Platform against GPUclaims Windows, renders Apple50
Property getter trapnavigator proxied100
Timezone against networklocale disagrees10
02Data architecture

PII has exactly one home

Traits you choose to send land in one erasable store and travel no further. Everything downstream sees pseudonyms and your own identifiers, so erasure is one operation.

01The vaultEmail, name, phone and your custom traits, stored once, per project, and only if you send them. None of it is required for detection to work.
02AnalyticsVerdicts, detections and enrichment, keyed by pseudonyms and your own user IDs. No trait ever reaches this layer.
03Webhooks and exportSigned deliveries and bulk exports carry the same pseudonymous shape, so a downstream system cannot become a second copy of your PII.
04Network dataIPs are pseudonymised at rest. A reputation entry survives without holding the address that earned it.
05RetentionThe behavioural window that drives detection quality is the same setting as your retention policy, configurable up to twelve months.
03Fairness

Privacy tools are not evidence of fraud

A careful visitor and an attacker reach for the same tools. Scoring the tool instead of the behaviour refuses your best customers.

VPN and TorRecorded as network context. They add nothing to a block on their own, and a long clean history outweighs them.
Anti-fingerprintingRandomised canvas and similar markers are detected and reported as context, and they correlate with lower abuse rates.
Earned trustAccounts that behave well accumulate reputation, so one odd session does not flip the verdict.

Walk your DPO through where every field sits.

Talk to an expert
04Erasure

Delete once, and it is gone

An erasure request cascades through the account profile, its device links, its reputation contribution and its event history. No shadow copy is kept for training.

EU infrastructureDPA availableConfigurable PII categoriesConfigurable retention
05 Questions

Privacy, answered

No cookies at all. Device identity is computed from telemetry, never written to the visitor's machine, so an incognito window resets nothing. If you store the session handle we return, it lives on your own origin and TrustSig never reads it.

EU infrastructure. Personal data you attach to an account, like email, name or phone, is stored in one erasable vault and nowhere else. Analytics, exports and webhook payloads carry pseudonyms and your own user IDs, never those traits.

Deleting an account cascades through its profile, its device links, its reputation contribution and its event history. IPs are pseudonymised at rest rather than stored raw, so a reputation entry survives without holding the address it came from.

None is mandatory. A user_id you control is enough for the identity layer. Traits like email are optional and buy one thing each, such as matching mailbox variants across signups.

No. Those are context labels that cannot block on their own. Privacy markers such as randomised canvas are reported the same way, and they correlate with lower abuse rates.

A DPA is available, and retention windows are configurable per project rather than fixed by us. The behavioural memory window that drives detection quality is the same setting, up to twelve months.

07Get started

Take it through your own review

Tell us what your compliance team needs to see. We will reply by email and set up access for your team.

  • EU-hosted and GDPR-native
  • Cookie-free device identity
  • Training mode before anything enforces