One trial per person, not one per inbox.

TrustSig Pro normalises the mailbox, remembers the hardware behind the last signup for as long as you configure, and links a rewritten fingerprint back to the machine it came from.

Mailbox variants collideDevice memory up to 12 monthsCampaign-level filtering

Three mailboxes, 21 days, one machine.

01The pattern

Catch the third trial three weeks after the first

Serial abuse runs slowly: a fresh mailbox, a cleared browser, days between attempts. A rate limit counting per hour never fires on it.

01Normalised mailboxDots, plus tags and provider aliases resolve to one inbox before comparison, so j.d.o.e+trial99 collides with the account it came from.
02Device memoryThe same canonical hardware opening another account three weeks later is caught on a window you configure, up to twelve months.
03Disposable domainsTemporary mailbox providers and machine-generated local parts are flagged as context, weighted with the rest rather than blocking alone.
04Rotated fingerprintsA cleared browser profile or an anti-detect build links back through the spoof layer, so changing the mailbox and the fingerprint is not enough.
05Campaign velocitySignups carry your campaign id, so the fan-out across devices, IPs and mailboxes is filterable for one promotion.
02Wiring

No CAPTCHA, no challenge, no extra step

Collection runs in the page while the visitor fills the form. Your server asks for a decision on the signup event it already writes.

  • The verdict comes back with weighted reasons, so a refusal is explainable to support.
  • The same call returns the alt verdict, naming the account this person already has.
  • Ambiguous signups go to review, so card or email verification only lands where it is earned.
  • Observe mode scores your real traffic and reports a fire rate before anything is refused.
signup.tsone call
const e = await pro.submitEvent({  kind: "signup",  user_id: user.id,  traits: { email: user.email },  request_id: v.request_id,  linked_id: "spring_giveaway",   // filterable later  include: ["alt"],});
if (e.decision === "BLOCK") return refuseTrial();if (e.decision === "REVIEW") return requireCardCheck();
03At scale

Resolve a whole farm into one cluster

Promo abuse at volume is industrial: one operator, a rack of profiles, a script and a schedule. The evidence those devices share is what groups them.

Cluster cl_2f19
Bot score0100
Accounts touched
61
First to last seen
9 days
Shared evidence
Pointer humanizersame library, same cadence19
Renderer stringone virtualised GPU24
Signup window07:00 to 07:40 UTC daily22
ASNsingle hosting range17

11more markers shared across the ring

Find the fleetFilter devices by account count and signup window to surface the hardware carrying far more of your users than a household ever would.
Judge the batchConfirm or reject a grouping from its shared evidence. Your labels tune the policy that scored it.
Keep the receiptsExport the events and observations behind a campaign as NDJSON or CSV when finance or a partner asks what was refused and why.

Replay your last promotion and see what it cost.

Talk to an expert
04 Questions

Trial abuse, answered

The signup event runs the signup-abuse engine against device and network history over a window you configure, up to twelve months. The same hardware opening another account three weeks later still matches. The response tells you how many accounts that device has touched.

john.doe+trial99@gmail.com, johndoe+x@gmail.com and j.o.h.n.doe@gmail.com are one mailbox. TrustSig Pro normalises addresses before comparing them, so each variant lands on the original account as an email_variant link.

The spoof and identity layers cover that. A new fingerprint from the same machine still resolves to that machine, and accounts on linked devices surface through the identity graph. Changing the mailbox and the fingerprint together is the standard playbook, so neither counts as a new person on its own.

No CAPTCHA and no challenge. Collection runs in the page and the decision happens server-side on the event you send. Suspicious signups route to REVIEW, so email or card verification only lands where the score asks for it.

Thresholds, detection weights and per-detection enforcement are editable per project, and changes land as a draft config you activate deliberately. Run the signup group in observe first and read its fire rate on your own traffic before it moves a verdict.

06Get started

Put your signup flow through it

Tell us what you are giving away and how it gets abused. We will reply by email to set up access for your team.

  • EU-hosted and GDPR-native
  • Cookie-free device identity
  • Training mode before anything enforces