Know who is on the other end.

Stop the bots, unmask spoofed devices, catch the ones that come back under a new fingerprint, and protect the code you ship. Real users see none of it.

200+ detections in the libraryCookie-free device identityEU-hosted and GDPR-native
This browser, right now
Browser
Operating system
Platform
Screen
Touch points
Logical cores
Device memory
GPU vendor
Graphics
Fonts installed
Time zone
Language
Location
Network
Sightings
What just happened
/100
Trust score for this session
Device IDDevice IDIdentifies this machine from the hardware, so it survives cleared cookies and private windows. Every customer gets a different id for the same machine.reading
Masked connection
Browser state
Reason codes
Now flip it:
Open the playground and read the whole response
01What we do

Four answers about the browser in front of you

Each one arrives with the evidence behind it.

  • Human pointer
  • Scripted input
Is this a person?Answered without a puzzle for the real user.TrustSig Web
macOS 14.4Windows 11Apple M2GTX 1650en-GBen-GB
  • Claims
  • Renders
Is this device what it claims?Read against the hardware actually rendering the page.TrustSig WebTrustSig Pro
dev_7f3a91
  • Cookies cleared
  • Private window
  • New account
Have we seen it before?Matched on the hardware, so a cleared browser still matches.TrustSig Pro
  • Your source
  • What ships
Is your own code intact?Hardened before it ships, because you cannot watch it run.TrustSig Protect
03The engine

Every product reads the same telemetry

Pro asks more of it than Web does.

Detection groups
Automation frameworksHeadless runtimesDriver tracesBrowser integrityCanvasWebGLAudio stackFont stackGPU decodeHardware coherencePointer behaviourKeyboard cadenceNetwork originTLS fingerprintMobile signalsVirtual machinesAnti-detect profilesPrivacy tooling
200+detections, individually switchable
15+detection groups
12 monthsconfigurable memory window
0cookies set or read
04TrustSig Web

Stop bad actors, not customers

The check runs while the page is open, so the answer is already there when the request lands. There is no puzzle to fail, no image grid, and no accessibility complaint to answer.

  • One script tag and one server-side verify call.
  • Every call returns the device, the risk grade and the reasons behind it.
  • Free tier, public pricing, live the same day.
  • SDKs for React and Next.js, Node and edge runtimes, or plain HTTP.
See how TrustSig Web works
Signup submittedPass2 min agoChrome 124 on Windows 11Munich, DE
93/100Trust score on this submission
Weighted reasons
Hardware and platform agree+24
No driver or headless traces+22
Human pointer and typing profile+18
Residential network+6
Real user, nothing shown
05TrustSig Pro

Find the device behind the account

When the same person comes back under a new name, a fresh fingerprint looks like a fresh user. TrustSig Pro links that fingerprint back to the hardware it came from, and names the accounts already on it.

  • Spoof linkage against anti-detect browsers and rotated profiles.
  • Identity graph: alt accounts, shared devices, ban evasion.
  • Fraud engines for takeover, signup abuse, sharing and any business action.
  • Clusters, device timelines and bulk export for investigations.
See how TrustSig Pro works
New account, returning hardwareent_9a71c204Linkedjust nowSession 427 accounts on this devicemailbox variant
88/100Link confidence to the device
Weighted reasons
GPU decode profile unchanged+24
TLS fingerprint unchanged+22
Canvas and WebGL rewritten+24
Audio clock skew identical+18
Matched back to the hardware
06Also from TrustSig

Protect the code you ship

Client-side code is readable by anyone who wants it badly enough. TrustSig Protect compiles what you ship into a virtual machine and varies the output per build, so a break buys an attacker one release.

See TrustSig Protect
08Where it runs

Runs in the EU, and you keep the decision

One integration, one region.

  1. In the browserNothing is written to the deviceOne script tagNo cookie setIncognito-proof
  2. At the EU edgeYour data stays in one regionEU hosting onlyErasable vaultDPA on request
  3. In your backendYour server keeps the decisionOne verify callNo redirectNo hosted flow
09Two ways in

Ship today, or talk it through

TrustSig Web is self-serve. Pro is tuned to your traffic, so it starts with a conversation.

Self-serveStart with TrustSig Web

Create a key, add the script and read your first verdict the same afternoon.

Live in
an afternoon
Starts with
a free key
Pricing
published
GuidedStart with TrustSig Pro

Tell us what you are protecting and we set your team up with access.

  • Rotated fingerprints traced back to one machine
  • Alt accounts, shared devices and ban evasion in one graph
  • Fraud engines for takeover, signup abuse and payouts
Live in
a scoped rollout
Starts with
a call
Pricing
your traffic
10 Questions

TrustSig, answered

Web answers one question: is this a bot. It is self-serve and has a free tier. Pro goes deeper on the same collection: which parts of a device's telemetry are forged, which hardware a rotated fingerprint belongs to, which accounts share a device, and how all of it behaved over the last twelve months.

No. Most companies start with Web because automated signups and logins are the first thing that hurts. Teams with money moving through accounts, promos, trials or payouts tend to need Pro. They run on the same engine, so moving up is a configuration change.

Neither. The device identity is computed from telemetry and never written to the visitor's machine, so there is nothing stored to clear or consent to. Real users never see a puzzle, a checkbox or a delay.

EU infrastructure, with a DPA available. Personal data you choose to send, like an email attached to a user, lives in one erasable store and never reaches analytics or a webhook payload. IPs are pseudonymised at rest.

No. VPN, Tor and anti-fingerprinting markers are context, never evidence on their own, and privacy markers correlate with lower abuse rates rather than higher. Ambiguity routes to a step-up instead of a refusal.

Web is a script tag and one server call, so an afternoon is normal. Pro is the same shape with your own user ID added, which turns on the identity layer. New Pro projects run in a training window first: everything is scored and logged while the returned decision stays advisory.

Read your first device today

TrustSig Web scores your own traffic from a free key. Pro and Protect start with a conversation.

GDPREU-hostedDPA available
Your first verify call
device_iddvc_4f18ba7c91
93/100trust score
Allow