Comparison

A FingerprintJS alternative,
with the EU part solved.

Same job: recognise the device, catch the fraud. The difference is where your data lives, who can ever use it, and how long anyone keeps it. We are an Irish company running Irish infrastructure, contractually barred from touching advertising, with deletion enforced in the database rather than promised in a settings page. Below is the comparison in full, including what we have not built yet.

Side by side

Dimension
WhorlID
FingerprintJS Pro
Company jurisdiction
Irish company, Irish law, Irish supervisory authority. Your processor is inside the EU, not a US entity with an EU region.
US company. EU hosting regions are available; the contracting entity is not in the EEA.
Where the data sits
Servers, database, and backups in the European Union. No transfer mechanism needed for identification data, because none leaves.
Region selectable per account, and the region you get depends on the plan you buy.
Identifier scope
Scoped per project, in the schema. The same device visiting two of our customers gets two unrelated ids, so a cross-site profile cannot be built even by us.
Identifiers issued per account, on shared infrastructure.
Retention
Raw signals deleted at 30 days, events at 90, dormant profiles at 365, by a job running in the production database. You can verify the behaviour yourself.
A retention setting, longer by default, with the ceiling set by your plan.
Permitted use
Fraud, account security, and abuse detection only. Advertising and cross-site tracking are prohibited in the DPA, so the data cannot be repurposed later.
Acceptable use policy, and a product positioned across a wider set of use cases.
Compliance paperwork
DPA published in full, readable before you sign up, alongside a written position on lawful deployment. No SOC 2 or ISO 27001.
SOC 2 and ISO certifications, with the DPA supplied on request during procurement.
Accuracy claims
No production accuracy figure published, because we do not have consented labelled data yet. The fixture diagnostics we do have are published with their method and their limits.
A headline accuracy figure, without a published measurement method.
Signal breadth
About 25 signals: canvas, WebGL, audio, fonts, screen, hardware, locale, math. No VPN or proxy detection, browser only.
A wider signal set, including VPN and proxy detection, tampering detection, and native mobile SDKs.
Pricing
Free for 1,000, $39 for 25,000, $99 for 100,000. Every tier gets the whole product: no signal, region, or retention setting is held back to sell you the next plan.
Entry paid plan around $99 a month, with signals, regions, and retention gated by tier.
Who answers you
The person who wrote the matching engine. Bugs get looked at the same day, and a signal you need can land in the next release.
A support organisation, with response times attached to your plan.
Failure behaviour
Documented: a quota error or an outage means "no device signal", never "block this user". We would rather you let a real customer through than lock them out on our behalf.
Availability commitments backed by an SLA on enterprise plans.

Their column reflects their public documentation and pricing pages at the time this page was written, with no cherry-picking we are aware of. Vendors change: check theirs before you decide, and tell us if anything here has gone stale.

Switch if

  • Your DPO, your enterprise buyers, or your own customers ask where the data sits. "EU region available" is a hosting answer to a jurisdiction question, and it is the one that gets picked apart in a security review.
  • You want retention you can put in a contract and then verify, not a setting whose ceiling depends on your plan.
  • You want a vendor that is contractually incapable of turning your fraud signal into an advertising product two funding rounds from now.
  • You are fighting trial abuse, multi-accounting, card testing, or credential stuffing on the web, which is most fraud, and you are paying enterprise pricing for signals you never call.
  • You want the whole product on the cheapest paid tier, instead of discovering that the signal you actually need sits one plan up.
  • You would rather email the person who wrote the matching engine than file a ticket about it.

What we have not built yet

Every vendor has a gap list. Most keep it off the comparison page, which is exactly why yours only surfaces halfway through an integration. Here is ours.

  • VPN and proxy detection. We flag datacenter IPs, not consumer VPNs.
  • Native iOS and Android SDKs. Browser only for now.
  • SOC 2 and ISO 27001. If your procurement gate requires one, tell us early.
  • A production accuracy figure, until real integrations give us consented labelled data to measure against.

If none of those are load-bearing for the fraud you are fighting, the rest of this page is the argument. If one of them is, tell us which: it is how the roadmap gets ordered.

About accuracy numbers

Every vendor in this category quotes an accuracy percentage. Ask any of them how it was measured, on which population, over what time window, counting false merges how, and the number stops being comparable. Treat the confident figure as marketing until someone shows you the method.

Here is ours with the method attached. On a labelled fixture of 40 devices and 320 observations, the engine resolves 78% of repeat observations back to the right device, with one false merge across the fixture. That fixture is synthetic and it was used while tuning, so it does not reproduce browser upgrades, privacy tools, enterprise policies, shared machines, or deliberate spoofing. It is a regression diagnostic, not a production accuracy figure, and we say so rather than rounding it up into a headline. Real numbers get published when real integrations give us consented, labelled, time-separated data.

What is true for the whole category, us included: identification is probabilistic, browser signals are public JavaScript output that can be replayed or faked, and hardened anti-fingerprinting browsers defeat every vendor here by design. Any provider telling you otherwise is selling you a number, not a control. Use device intelligence as a risk input, not as proof.

Run both and compare the ids.

1,000 identifications a month, free, no card, no call. Put us beside whatever you use now on your own traffic. That is the only benchmark that settles it.

Compliance reading: deploying lawfully and the DPA.

A FingerprintJS alternative, built in the EU | WhorlID