Bans that survive a new fingerprint.
Anti-detect browsers change the fingerprint, not the machine. TrustSig Pro links the rewritten identity back to the hardware it left, and names which parts were forged.
Already in production
Publishing platforms, fintech and national charities across Europe already run TrustSig on their forms.
What a new profile cannot change
These are measured from the machine rather than read from what the browser reports, so a fresh profile does not move them.
Know which parts of the fingerprint moved
TrustSig Pro reports the association and its confidence rather than merging two device records into one, so your team weighs it.
{ "spoof": { "detected": true, "confidence": 88, "method": "linkage", "groups": ["canvas", "webgl_strings", "fonts"], "linked_entity_id": "ent_9a71c204" }, "canonical_entity_id": "ent_9a71c204", "decision": "REVIEW"}Enforcement that outlives the profile
Attach the ban to the canonical device, and an account that returns under a new mailbox and a new fingerprint still carries its old record.
- Devices you block stay on the reputation list for the length of the hotlist window.
- Accounts created on hardware tied to fraud fire their own detection, separate from the device verdict.
- Temporary bans expire on their own, so a shared or recycled device is not punished forever.
- Every device carries a timeline: what it presented, what fired and what changed, session by session.
- Trust
- 84 → 21
- Sessions
- 412
Bring us a profile that beats your current stack.
Talk to an expertSpoofed devices, answered
Two ways. Coherence: the presented fingerprint contradicts itself, such as a declared platform that disagrees with the GPU, the OEM fonts or the audio sample rate. Linkage: a device already matched to a known one shows up with a materially different fingerprint, and the report names which groups diverged.
The detection is not tool-specific. It targets what every fingerprint-rewriting stack has to do: override native APIs, randomise canvas output, forge platform strings and relocate the timezone. Those overrides leave measurable traces, and the rewritten fingerprint still renders on real hardware.
No. A spoof link is an association between two device records, with a confidence and the evidence behind it. It is never a silent merge of two identities, and what the link is worth is your call.
No. Randomised canvas and similar privacy markers are reported as context, and they correlate with lower abuse rates. A spoof verdict needs an incoherent fingerprint or a device presenting someone else's.
You ban an account and the device behind it. When that machine returns under a fresh fingerprint and a new email, the spoof link ties it back to the banned hardware. The ban carries over.
Ask the same platform a different question
Every page below runs on the same telemetry, the same device identity and the same detection catalog.
Test it against your own evaders
Tell us what you are seeing and how they come back. We will reply by email to set up access for your team.
- EU-hosted and GDPR-native
- Cookie-free device identity
- Training mode before anything enforces











