One trial per person, not one per inbox.
TrustSig Pro normalises the mailbox, remembers the hardware behind the last signup for as long as you configure, and links a rewritten fingerprint back to the machine it came from.
Three mailboxes, 21 days, one machine.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Catch the third trial three weeks after the first
Serial abuse runs slowly: a fresh mailbox, a cleared browser, days between attempts. A rate limit counting per hour never fires on it.
No CAPTCHA, no challenge, no extra step
Collection runs in the page while the visitor fills the form. Your server asks for a decision on the signup event it already writes.
- The verdict comes back with weighted reasons, so a refusal is explainable to support.
- The same call returns the alt verdict, naming the account this person already has.
- Ambiguous signups go to review, so card or email verification only lands where it is earned.
- Observe mode scores your real traffic and reports a fire rate before anything is refused.
const e = await pro.submitEvent({ kind: "signup", user_id: user.id, traits: { email: user.email }, request_id: v.request_id, linked_id: "spring_giveaway", // filterable later include: ["alt"],});
if (e.decision === "BLOCK") return refuseTrial();if (e.decision === "REVIEW") return requireCardCheck();Resolve a whole farm into one cluster
Promo abuse at volume is industrial: one operator, a rack of profiles, a script and a schedule. The evidence those devices share is what groups them.
- Accounts touched
- 61
- First to last seen
- 9 days
11more markers shared across the ring
Replay your last promotion and see what it cost.
Talk to an expertTrial abuse, answered
The signup event runs the signup-abuse engine against device and network history over a window you configure, up to twelve months. The same hardware opening another account three weeks later still matches. The response tells you how many accounts that device has touched.
john.doe+trial99@gmail.com, johndoe+x@gmail.com and j.o.h.n.doe@gmail.com are one mailbox. TrustSig Pro normalises addresses before comparing them, so each variant lands on the original account as an email_variant link.
The spoof and identity layers cover that. A new fingerprint from the same machine still resolves to that machine, and accounts on linked devices surface through the identity graph. Changing the mailbox and the fingerprint together is the standard playbook, so neither counts as a new person on its own.
No CAPTCHA and no challenge. Collection runs in the page and the decision happens server-side on the event you send. Suspicious signups route to REVIEW, so email or card verification only lands where the score asks for it.
Thresholds, detection weights and per-detection enforcement are editable per project, and changes land as a draft config you activate deliberately. Run the signup group in observe first and read its fire rate on your own traffic before it moves a verdict.
Ask the same platform a different question
Every page below runs on the same telemetry, the same device identity and the same detection catalog.
Put your signup flow through it
Tell us what you are giving away and how it gets abused. We will reply by email to set up access for your team.
- EU-hosted and GDPR-native
- Cookie-free device identity
- Training mode before anything enforces











