A build nobody has catalogued still reports
Wrapping the reads leaves an interception pattern behind, and the field reports the pattern.
integrity.tamperedthis browserAn anti-detect browser rewrites what the page reports. One verify call returns what the hardware underneath still renders, and whether the two hold together.
A profile controls what the page reports, never what the GPU draws.
A rewritten environment and a randomised one raise different fields, so a careful visitor does not read as an attacker.
Wrapping the reads leaves an interception pattern behind, and the field reports the pattern.
integrity.tamperedthis browserA known engine is identified before any surface it rewrote is read.
integrity.anti_detect_browserthis browserintegrity.privacy_toolingA privacy browser as often as an attacker.
Bind the sessionthis browserintegrity.virtual_machineA hosted desktop renders the same way.
Weigh with the networkthis browseranti_detect_browsertampered_environmentruntime_patchedplatform_mismatchrendering_anomalyspoofed_deviceprivacy_toolingvirtual_machineimport { useTrustSig } from "@trustsig/react";
const { getResponse } = useTrustSig();
const { token } = await getResponse();import { TrustSig } from '@trustsig/server';
const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY });
app.post('/signup', async (req, res) => {
const token = req.headers['x-trustsig-response'];
const result = await ts.verifyRemote(token);
// is_bot is true once the session crossed the block threshold.
if (result.is_bot) {
return res.status(403).json({ error: 'Access denied.' });
}
const { anti_detect_browser, tampered, privacy_tooling, virtual_machine } =
result.integrity;
// A named engine, or the interception pattern one leaves behind.
if (anti_detect_browser || tampered) {
return requireSecondFactor(result.identity.device_id);
}
// Randomised readback on its own is a privacy browser as often as an
// attacker. Bind the account to the device instead of turning them away.
if (privacy_tooling) {
return completeSignup(req, res, { pin: result.identity.device_id });
}
// A software renderer is ordinary on a corporate desktop and is not on a
// hosting network. The pair is the finding, neither half alone.
if (virtual_machine && result.network.datacenter) {
return res.status(403).json({ error: 'Access denied.' });
}
return completeSignup(req, res);
});integrity.privacy_toolingintegrity.virtual_machineidentity.device_idintegrity.tamperedA known engine is named outright. Everything else is caught by the interception pattern a rewritten environment leaves behind, so a build TrustSig has never seen still reports as tampered. The probes that fired are not published, because publishing them is how they get patched.
No. Randomised canvas and WebGL readback sets integrity.privacy_tooling, separately from integrity.tampered and integrity.anti_detect_browser, so a privacy browser and an anti-detect build never arrive looking the same.
A new profile produces a new identity.device_id, but the integrity findings survive the reset: an anti-detect build rewrites the same surfaces on the second run as on the first, and reports the same way. Linking the two profiles back to one machine is TrustSig Pro.
No. /verify returns action, the risk grade and the evidence behind it, and the branch is yours. An anti-detect browser on a signup route and the same browser on a support page are not the same problem, so a fixed answer would be wrong on one of them.
integrity.virtual_machine covers virtual machines, emulators and software renderers, so a corporate VDI desktop and a remote worker on a hosted image both raise it. It arrives as one finding in a response that also carries network.datacenter, which is what separates a hosting fleet from an office build.
One script tag and one server call. The integrity block is filled by the same scan that produces the token, so there is no second request, no puzzle and nothing for the visitor to complete. See the response schema for every field it returns.
One script tag, one server call, and the integrity block is in the first response.