Know who is on the other end.
Stop the bots, unmask spoofed devices, catch the ones that come back under a new fingerprint, and protect the code you ship. Real users see none of it.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
Four answers about the browser in front of you
Each one arrives with the evidence behind it.
- Human pointer
- Scripted input
- Claims
- Renders
- Cookies cleared
- Private window
- New account
- Your source
- What ships
Four products, one engine
Start where the pain is.
Every product reads the same telemetry
Pro asks more of it than Web does.
Stop bad actors, not customers
The check runs while the page is open, so the answer is already there when the request lands. There is no puzzle to fail, no image grid, and no accessibility complaint to answer.
- One script tag and one server-side verify call.
- Every call returns the device, the risk grade and the reasons behind it.
- Free tier, public pricing, live the same day.
- SDKs for React and Next.js, Node and edge runtimes, or plain HTTP.
Find the device behind the account
When the same person comes back under a new name, a fresh fingerprint looks like a fresh user. TrustSig Pro links that fingerprint back to the hardware it came from, and names the accounts already on it.
- Spoof linkage against anti-detect browsers and rotated profiles.
- Identity graph: alt accounts, shared devices, ban evasion.
- Fraud engines for takeover, signup abuse, sharing and any business action.
- Clusters, device timelines and bulk export for investigations.
Protect the code you ship
Client-side code is readable by anyone who wants it badly enough. TrustSig Protect compiles what you ship into a virtual machine and varies the output per build, so a break buys an attacker one release.
See TrustSig ProtectRead the work the detections came out of
We publish the teardowns, the tooling and the reasoning, including the parts that argue against us.
Runs in the EU, and you keep the decision
One integration, one region.
- In the browserNothing is written to the deviceOne script tagNo cookie setIncognito-proof
- At the EU edgeYour data stays in one regionEU hosting onlyErasable vaultDPA on request
- In your backendYour server keeps the decisionOne verify callNo redirectNo hosted flow
Ship today, or talk it through
TrustSig Web is self-serve. Pro is tuned to your traffic, so it starts with a conversation.
Create a key, add the script and read your first verdict the same afternoon.
- Live in
- an afternoon
- Starts with
- a free key
- Pricing
- published
Tell us what you are protecting and we set your team up with access.
- Rotated fingerprints traced back to one machine
- Alt accounts, shared devices and ban evasion in one graph
- Fraud engines for takeover, signup abuse and payouts
- Live in
- a scoped rollout
- Starts with
- a call
- Pricing
- your traffic
TrustSig, answered
Web answers one question: is this a bot. It is self-serve and has a free tier. Pro goes deeper on the same collection: which parts of a device's telemetry are forged, which hardware a rotated fingerprint belongs to, which accounts share a device, and how all of it behaved over the last twelve months.
No. Most companies start with Web because automated signups and logins are the first thing that hurts. Teams with money moving through accounts, promos, trials or payouts tend to need Pro. They run on the same engine, so moving up is a configuration change.
Neither. The device identity is computed from telemetry and never written to the visitor's machine, so there is nothing stored to clear or consent to. Real users never see a puzzle, a checkbox or a delay.
EU infrastructure, with a DPA available. Personal data you choose to send, like an email attached to a user, lives in one erasable store and never reaches analytics or a webhook payload. IPs are pseudonymised at rest.
No. VPN, Tor and anti-fingerprinting markers are context, never evidence on their own, and privacy markers correlate with lower abuse rates rather than higher. Ambiguity routes to a step-up instead of a refusal.
Web is a script tag and one server call, so an afternoon is normal. Pro is the same shape with your own user ID added, which turns on the identity layer. New Pro projects run in a training window first: everything is scored and logged while the returned decision stays advisory.
Read your first device today
TrustSig Web scores your own traffic from a free key. Pro and Protect start with a conversation.
dvc_4f18ba7c91










