Skip to content
CLOUD Act flagged on every listing
EU VETTED
Category

CAPTCHA & bot protection

In short CAPTCHA and bot-protection services decide whether a visitor is human before a form submits. Google reCAPTCHA is the default and is also the single most-flagged third-party script in EU cookie-consent audits, because it sets cookies and sends visitor data to Google LLC. The European options on EU Vetted are CaptchaFox (Germany), TrustCaptcha (Germany), ALTCHA (Czechia, MIT-licensed), captcha.eu (Austria), Friendly Captcha (Germany), mosparo (Switzerland, self-hosted), Prosopo (United Kingdom) and Botpoison. The distinction that matters here is between the widget path, meaning the chain your visitors' IP addresses actually travel through, and the vendor's own back office. CaptchaFox is the only vendor that names its widget-path processors publicly, and both of them are EU companies.
About this category
About CAPTCHA & bot protection

Showing all 8 alternatives in this category

Feature comparison

Beyond compliance: how these alternatives compare on the capabilities you actually use day to day.

Feature mosparo ALTCHA captcha.eu CaptchaFox Prosopo TrustCaptcha Botpoison Friendly Captcha
Self-hostable Yes Yes No No No No No No
No cookies or browser storage Yes Yes Yes Yes
Invisible challenge Yes Yes Yes Yes Yes Yes Yes Yes
Proof-of-work Yes Yes Yes Yes
Bot risk scoring Yes Yes Yes
WCAG accessibility conformance Yes Yes Yes Yes Yes Yes
CMS plugins Yes Yes Yes Yes Yes Yes Yes Yes
Free tier Yes Yes No No Yes No Yes Yes
SWITCHING GUIDES

Switching from US captcha & bot protection?

Side-by-side European alternatives (same hosting, ownership and CLOUD Act checks) for the US tools most often replaced in this category.

FAQ

Frequently asked questions

What is the best GDPR-compliant alternative to reCAPTCHA?
For a hosted service, CaptchaFox (Germany) has the cleanest published chain: its widget-path sub-processors are Hetzner (Germany) and bunny.net (Slovenia), both named on a public page, and its exposure is recorded as Minor. TrustCaptcha (Germany) is the cheapest EU-hosted option at €8 per month on Hetzner in Nuremberg, exposure Minor. If you can self-host, ALTCHA and mosparo remove the vendor from the data path entirely, which is stronger than any hosted promise.
Does using reCAPTCHA require a cookie banner?
In practice, yes. reCAPTCHA sets cookies and transmits visitor data to Google, so it is not a strictly necessary cookie in the sense that gets you out of the consent requirement, and it is routinely listed in the marketing or analytics category of consent tools. Cookie-free CAPTCHAs avoid the problem structurally: several vendors here set no cookies and write nothing persistent to the browser, so the form can be protected on a legitimate-interest basis under Art. 6(1)(f) instead of waiting for consent.
Which of these vendors publishes a DPA?
Only two: ALTCHA publishes a downloadable DPA PDF, and Prosopo publishes one as a readable page with its sub-processor list inside it. CaptchaFox and TrustCaptcha state that a DPA is included on every plan but issue it on request. Friendly Captcha's DPA URL is password-protected. captcha.eu and Botpoison publish none. mosparo needs none, because it is self-hosted and the association never processes your data.
What is the difference between the widget path and the rest of a vendor's stack?
The widget path is the chain a visitor's IP address and browser signals actually pass through when a form is protected. Everything else, billing, support ticketing, the vendor's own website analytics, touches your account data rather than your visitors. The distinction matters because a vendor can be entirely EU on the widget path and still use Stripe or Google in the back office. CaptchaFox is the only vendor here that separates the two publicly, listing Hetzner and bunny.net for the widget and Simple Analytics and Stripe for the service side.
Is a CAPTCHA an accessibility problem?
Traditional image and audio CAPTCHAs are, and since June 2025 the European Accessibility Act makes that a compliance question rather than a courtesy for many operators. Proof-of-work and invisible challenges avoid it by never asking the visitor to do anything: ALTCHA is built to WCAG 2.2 AA and EAA conformance, TrustCaptcha and Prosopo document accessibility, and Friendly Captcha claims WCAG 2.2 AA certified by TÜV, though without publishing a report or audit date.
Can I self-host bot protection instead of buying a service?
Yes, and it is the strongest posture in this category. mosparo (MIT, Swiss association) is self-hosted only and analyses form content on your own server, so no third party ever sees a visitor. ALTCHA (MIT) can be self-hosted as widget plus verification server, or bought as a managed Cloud tier. In both cases you take on operations, updates and security patching in exchange for having no processor chain at all.
Are the European CAPTCHA vendors themselves hosted in Europe?
Not all of them, and this is the finding of the category. CaptchaFox runs on Hetzner and bunny.net, TrustCaptcha on Hetzner in Nuremberg, both entirely EU. ALTCHA Cloud runs on AWS with an EU-only residency commitment. captcha.eu, despite the domain name, is served from Amazon S3 behind CloudFront with Microsoft 365 mail and Google ad measurement. Prosopo names AWS, Cloudflare and Hostwinds alongside Hetzner, Contabo, OVHcloud and bunny.net. Botpoison names AWS, Google Analytics, Sentry and Stripe. Check the hosting row on each listing rather than the flag on the logo.