Bans that survive a new fingerprint.

Anti-detect browsers change the fingerprint, not the machine. TrustSig Pro links the rewritten identity back to the hardware it left, and names which parts were forged.

Coherence and linkage evidenceAssociation, never a silent mergePrivacy markers stay context
Fingerprint rewrittenent_9a71c2047accounts on this hardware41 → 42sessions, 2 min apart
canvasa41c…9e7b02…d5
webgl stringsApple M2Intel UHD 620
fonts142 present38 present
user agentmacOS 14Windows 10
88/100Link confidence to the original hardware
Held constant
GPU decode profile, same silicon path+24
TLS fingerprint, unchanged JA4+24
Audio clock skew, identical drift+22
CPU concurrency, 8 logical cores+18
Fingerprint faked, hardware matched
01The physics

What a new profile cannot change

These are measured from the machine rather than read from what the browser reports, so a fresh profile does not move them.

01GPU decode profileVideo decode paths, execution-unit behaviour and blending overhead follow the silicon.
02Audio clock skewThe system clock drift measured through the audio stack is a property of the device, and it survives a new canvas hash.
03Property getter overheadFaking navigator, screen or languages means proxying a getter, and the extra call cost is measurable from the page itself.
04Engine identityEval length, JIT tier behaviour and math implementations identify the real JS engine, whatever the user agent claims to be.
05Platform coherenceA declared OS has to agree with the codec set, the OEM fonts, the audio sample rate, the touch capability and the GPU.
02How it reports

Know which parts of the fingerprint moved

TrustSig Pro reports the association and its confidence rather than merging two device records into one, so your team weighs it.

01CoherenceThe fingerprint contradicts itself. No second device is needed, because the configuration it presents is impossible on real hardware.
02LinkageA device the resolver already matched by an exact key is presenting a different fingerprint. TrustSig Pro verifies the pair before it reports the link.
responseverify
{  "spoof": {    "detected": true,    "confidence": 88,    "method": "linkage",    "groups": ["canvas", "webgl_strings", "fonts"],    "linked_entity_id": "ent_9a71c204"  },  "canonical_entity_id": "ent_9a71c204",  "decision": "REVIEW"}
03Ban evasion

Enforcement that outlives the profile

Attach the ban to the canonical device, and an account that returns under a new mailbox and a new fingerprint still carries its old record.

  • Devices you block stay on the reputation list for the length of the hotlist window.
  • Accounts created on hardware tied to fraud fire their own detection, separate from the device verdict.
  • Temporary bans expire on their own, so a shared or recycled device is not punished forever.
  • Every device carries a timeline: what it presented, what fired and what changed, session by session.
ent_9a71c204
Mar 04First seen
May 19Second account
Jul 02Fingerprint rewritten
Aug 11Humanizer detected
Trust
84 → 21
Sessions
412
Accounts on this deviceyour user IDs
u_4821signed up 04 Maru_990719 Mayu_1105802 Julu_30474banned 11 Augu_4829114 Aug2 more, joined this month

Bring us a profile that beats your current stack.

Talk to an expert
04 Questions

Spoofed devices, answered

Two ways. Coherence: the presented fingerprint contradicts itself, such as a declared platform that disagrees with the GPU, the OEM fonts or the audio sample rate. Linkage: a device already matched to a known one shows up with a materially different fingerprint, and the report names which groups diverged.

The detection is not tool-specific. It targets what every fingerprint-rewriting stack has to do: override native APIs, randomise canvas output, forge platform strings and relocate the timezone. Those overrides leave measurable traces, and the rewritten fingerprint still renders on real hardware.

No. A spoof link is an association between two device records, with a confidence and the evidence behind it. It is never a silent merge of two identities, and what the link is worth is your call.

No. Randomised canvas and similar privacy markers are reported as context, and they correlate with lower abuse rates. A spoof verdict needs an incoherent fingerprint or a device presenting someone else's.

You ban an account and the device behind it. When that machine returns under a fresh fingerprint and a new email, the spoof link ties it back to the banned hardware. The ban carries over.

06Get started

Test it against your own evaders

Tell us what you are seeing and how they come back. We will reply by email to set up access for your team.

  • EU-hosted and GDPR-native
  • Cookie-free device identity
  • Training mode before anything enforces