We help you defend against reversing and piracy.

TrustSig Protect obfuscates and virtualizes your web app's logic, while defending it at runtime against unauthorized tampering and debugging.

01The problem

Web apps have the same problem native software always had.

Software piracy is a tale as old as time. Protection against reversing and tampering has been refined for decades on native software, because that is what everyone used. WebAssembly is now becoming the standard for all kinds of software, and it needs the same protections.

  • JavaScript and WebAssembly
  • Rust toolchain
  • Only the functions you pick
Book a demo
In every build29 protections
  • Virtualization
  • Obfuscation
  • Anti-tamper
  • Anti-debug
  • Encryption
Never comes back
  • Readable source
  • Reusable patches
  • Plaintext keys
02The defense stack

We make it financially and practically unviable to attack your software by overpowering the attacker with defenses.

Each layer covers a different angle, together they compound into a strong multi-layered defense.

Per-build virtualizationYour core logic is recompiled into a private instruction set and run by a small virtual machine of ours, so the real code never sits readable on the page.
Two virtual machines, JavaScript and WebAssemblyTwo independent VMs run your logic, so there is no single engine to crack.
Polymorphic buildsEvery build is byte-for-byte different, down to the layout of the bytecode.
Per-brand uniquenessEach brand ships its own machine and bytecode. Breaking one teaches nothing about the rest.
Control-flow flatteningFlattening scrambles the path through your code, so the order it runs in is no longer visible.
Call-graph breakingFunction calls are rerouted through the engine, so no one can map which part of your code calls which.
Callstack breakingYour code runs without leaving the normal execution trail that debuggers and profilers rely on.
Opaque predicatesFake decision points that look real to automated tools and survive even aggressive cleanup passes.
03Why it holds

Every build is a new puzzle.

An attack built against one release stops working on the next one. The crack an attacker already has gives no head start, because no two builds lay out the same.

04Secrets at runtime

Encrypted at rest. Decrypted for one instant.

Keys and tokens are decrypted at the moment of use and scrubbed straight after, so a memory dump comes back as ciphertext. Each key is used once, then rolls forward.

  • Data never exists complete in memory.
  • No single key ever unlocks everything.
  • Every call between JavaScript and WebAssembly is an encrypted packet.
05 Questions

TrustSig Protect, answered

The bytecode our virtual machines run is unique to each build and each brand, and honeytokens rotate every build.

It detects the patched function, the attached debugger or the swapped runtime, hides its memory and drops the session. The attacker gets no error and no reason.

Only the functions you choose run inside the virtual machines. The rest of your bundle runs natively.

JavaScript and WebAssembly. With the Rust toolchain, one virtualize! annotation compiles a function into private bytecode run by an embedded interpreter.

06Get started

Get in touch.

Tell us what you are working on, what needs protecting, or whatever you want to ask.