Privacy is the architecture, not the asterisk.
Our fraud detection service, TrustSig Pro, provides the legal assurances your DPO will be satisfied with: an EU-hosted service built on privacy by design and by default, giving you configurable retention, right to be forgotten by design, control over processed PII categories, and a clear DPA.
EU-hosted. Verdicts in milliseconds.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
What “privacy-first” means when it's load-bearing.
Each of these is enforced by how the system is built – not by a policy document promising restraint.
Erasure is one call, not a cleanup project.
Article 17 requests shouldn't spawn a three-week data-archaeology ticket. In Pro, account deletion walks the same edges the data was written through – so nothing derived from the account survives it. See also our Privacy Notice and Data Processing Agreement.
Done – the account and everything derived from it is gone
Everything derived from the account, gone – not flagged for a cleanup job. The cascade is the data model.
Same signal. Fairer outcome.
A brand-new account and a 14-month customer trip the same wire – and get different treatment, because one of them has earned context. That's not leniency; it's accuracy.
A confirmed attack signature always blocks, no matter how much trust an account has built.
Nobody gets blocked for protecting themselves.
VPN, Tor and privacy browsers are how journalists, lawyers, security teams and ordinary careful people use the internet. Pro labels them as context and refuses to treat them as guilt. If a fraud tool punishes privacy, it's training your best users to leave.
The compliance file.
The legal documents, ready when your DPO asks.
One signal layer. Every abuse pattern.
Each detection engine reads the same account, device and network memory – turn on one, the rest are a toggle away.
Privacy & compliance, answered
As the data controller, you decide which personal data is processed. This may include direct identifiers such as email, name, username and phone number, and, where these are present, indirect identifiers such as IP address also become essential. This data is hosted in the EU.
One call. Deleting an account cascades through everything derived from it – the vault record, device links, behavioural profiles, reputation entries and event history. Erasure is built into the data model, not bolted on as a cleanup job. Anonymised threat intelligence, together with account-registration and contractual data that TrustSig processes as a controller in its own right, is retained for the periods set out in the TrustSig Privacy Notice.
Yes. For TrustSig Pro, fraud prevention is the core purpose: to detect fraudsters and their specific accounts and stop them stealing your money. You remain in control – you can enable or disable the service, choose which registration- and login-related personal data we process, set retention periods and delete all data. Where this profiling involves automated decision-making with legal or similarly significant effects, it is carried out under the fraud-prevention grounds recognised in GDPR Article 22 and Recital 71.
In most cases it is legitimate interest under Article 6(1)(f) of the GDPR. You are the data controller, so that basis is yours to establish, while TrustSig acts as your data processor for this processing under the DPA. Your legal team should run their own assessment for your context, but the GDPR is explicit that fraud prevention (Recital 47) and network and information security (Recital 49) are legitimate interests. Because classification is automated and may produce legal or similarly significant effects, Article 22 and Recital 71 are also relevant, recognising fraud monitoring as a permitted purpose. A compliant legitimate interest requires a Legitimate Interests Assessment. If your legal team needs support, they can reach ours at legal@trustsig.eu.
Yes. A DPA is available as a standard annex to the Terms of Service.
You do. Under the GDPR, the data collected on your website and passed to TrustSig's threat protection service (bot protection and fraud prevention) belongs to you. You act as the data controller, and TrustSig acts as your data processor. This means you own the data and decide how it is processed, while delegating the bot-protection and fraud-prevention processing to TrustSig on your behalf. This relationship is set out legally in our Terms of Service, together with the Data Processing Agreement (DPA) annexed to it. For full details, please also see our Privacy Notice.
Never on their own. Privacy browsers, VPN, Tor and anti-fingerprinting protections cannot cause a block by themselves – ambiguity routes to a step-up, not a denial. Punishing people for protecting themselves would contradict the entire architecture.
Fraud prevention that respects your users.
Tell us what you are trying to protect and why now. We will reply by email to set up access for your team.
- EU-hosted, GDPR-native
- No CAPTCHAs, no friction for your users
- Verdicts in milliseconds











