Free trial abuse

One machine,one free trial.

A fresh address and a fresh card cost a minute. One verify call returns the id of the machine behind them, and the date it first took a trial from you.

Trial entitlement, this browser

Reading this browser

first_seen
sightings
degraded
trial
01The run

Four inboxes, four cards, fifty-six free days

Each trial arrived on a new inbox and a new card, and on the same machine.

12 MayPro trialr.kaljas@gmail.comVisa 414914 days
27 MayPro trialkaljas.trials@proton.meVisa 552214 days
11 JunTeam trialrk.builds99@gmail.comMastercard 731014 days
25 JunTeam trialhello@rk-labs.devVisa 880414 days
A recorded trial history

e41d7a05c98b2f63

56free days served to one machine, on four inboxes and four cards
SAME MACHINE
02The grant

An email address proves two things at the moment you grant

2things the email address proves
The address accepts mailtrue
The card authorisedtrue

Neither says whether this machine has had a trial.

7things the machine hands over at the same moment
identity.device_ide41d7a05c98b2f63
identity.first_seen12 May 2026
identity.sightings38
identity.returningtrue
identity.degradedfalse
identity.linked_devices1
network.datacenterfalse
03Your browser

The questions a trial gate asks, answered on this session

Has this machine been here before?identity.returning
When did it first show up?identity.first_seen
How often has this project seen it?identity.sightings
Does its fingerprint name a crowd?identity.degraded
Has more than one id resolved to it?identity.linked_devices
Did it arrive from a hosting network?network.datacenter
Open every field this scan returnedthe whole response, on your own browser
04Wiring

Read the id before you grant the trial

start-trial.tsxCLIENT
import { useTrustSig } from "@trustsig/react";

const { getResponse } = useTrustSig();
const { token } = await getResponse();
start-trial.jsSERVER
import { TrustSig } from '@trustsig/server';

const ts = new TrustSig({ secretKey: process.env.TRUSTSIG_SECRET_KEY });

app.post('/start-trial', async (req, res) => {
  const token = req.headers['x-trustsig-response'];
  const { is_bot, identity } = await ts.verifyRemote(token);

  // is_bot is true once the session crossed the block threshold.
  if (is_bot) {
    return res.status(403).json({ error: 'Access denied.' });
  }

  // degraded marks an id a large cohort shares, so it names a crowd.
  if (identity.degraded) {
    return grantTrial(req, res, { days: 14 });
  }

  // Your table, keyed on the id. One row per machine, not per email.
  const used = await trialsForDevice(identity.device_id);

  if (used.length > 0) {
    return res.json({ trial: 'none', prior: used[0].started_at });
  }

  await trials.open(identity.device_id, { email: req.body.email });
  return grantTrial(req, res, { days: 14 });
});
05Limits

What one trial per machine does not claim

One machine can be a whole householdidentity.device_id
A shared laptop, a family desktop, a hot desk. One id, and a second person who has never had a trial.
Some ids name a cohortidentity.degraded
A locked-down browser withholds enough of the surface that its fingerprint belongs to a crowd, and the response marks it before you rule on it.
A second laptop still gets a trialidentity.linked_devices
The next trial costs a laptop rather than another inbox.
A hosted desktop is not proofintegrity.virtual_machine
Remote workers and QA fleets render through software too. It reads as a farm only next to the network it arrived on.
06 Answers

Repeat trials, answered

The trial is granted against identity.device_id rather than the email address. The id is computed from the machine, so a second signup with a fresh inbox, a fresh card and a cleared browser arrives on the id that already used its trial, and identity.first_seen says when.

They get one, because that is a different machine and a different id. Resolving both machines to one person is TrustSig Pro.

No. The reading happens in the page, so the exit country and the payment method never touch it, and a private window is reported separately as device.incognito. The connection is returned on its own in the network block, which is where vpn, tor and datacenter live.

Each virtual machine is its own id, so a farm spends a machine per trial and reports what it is: integrity.virtual_machine is set, and network.datacenter usually is too. See anti-detect browsers for the rewritten-environment case.

identity.degraded marks an id whose fingerprint a large cohort shares, so a locked-down office build is visible before you turn anyone away. A family desktop is one machine that several people will start a trial from.

No. The scan runs on the page before an account exists, and the verify call returns the id from the token alone. Nothing you collect in the form reaches TrustSig, and the id is scoped to one project, so it cannot be joined against another site. See the privacy note.

Grant the next trial to a machine.

One script tag on the trial form, and the id comes back with the verify result.