Security

Security and privacy at Kavra

Kavra detects fraud from technical and network signals, not from identity data: no names, emails or phone numbers are needed. Those signals can still be personal data under GDPR, so Kavra applies the legal basis per visitor region, keeps data isolated per customer, encrypts collection end to end and retains it for bounded periods.

What Kavra processes

CategoryExamplesNotes
Network dataIP address, network owner, proxy, VPN, Tor and datacenter classificationWe treat an IP address as personal data as a matter of policy
Device and browser signalsGraphics, screen, hardware and browser properties, automation artifactsUsed as evidence, never as the identifier
Interaction signalsHow the page was used before the protected action, such as pointer and timing patternsUsed to tell people from scripts
Identity dataNames, emails, phone numbersNot needed; Kavra does not ask for them

When your site or app sends Kavra a check about one of your visitors, you are the controller and Kavra Lab (SIA ADVERTIMO) acts as your processor. For our own IP-intelligence reference data, we are the controller. Both roles are described in the privacy policy.

The rules that apply follow the visitor, not your company. You declare your legal basis per region; Kavra applies it to each visitor from their network location and respects your consent manager. Where a persistent identifier is not permitted, the script does not read browser storage at all.

How data is protected

  • Encrypted collection

    Browser evidence travels in an application-layer encrypted envelope on top of TLS, so intermediaries cannot read or alter it.

  • Tamper-resistant tokens

    Tokens are signed, single-use, short-lived and bound to one action. Replayed tokens are refused and reported.

  • Strict tenant isolation

    Every project has its own keys. There is no cross-customer tracking or linking of your visitors with anyone else's.

  • Pseudonymous identities

    Visitors appear under opaque, server-assigned IDs. Fingerprint values are keyed per project and used only as evidence.

  • Data minimization

    Addresses used for internal consistency checks are hashed in the browser with a per-session salt, location is kept coarse, and no third-party services are called from your visitors' browsers.

  • Access control

    Console roles (owner, operator, viewer), API keys that are shown once and can be revoked, and an audit log of every change.

Where data is processed and how long it is kept

TopicPractice
LocationEU infrastructure as the baseline; service providers outside the EEA are disclosed in the privacy policy
RetentionBounded periods, defined per data type in the privacy policy; not indefinite
ErasureDeletion support for data-subject requests
Automated decisionsKavra recommends and explains; your backend decides, which supports your obligations around automated decision-making

Certifications and procurement

We do not claim security certifications we do not hold. This page and the privacy policy describe our practices; they are not a statement that compliance has been independently verified. For procurement, we share a data processing agreement and security documentation with your team on request through the contact form.

Found a security issue? Report it through the contact form and choose "Something else"; it goes straight to the team.

FAQ

Frequently asked questions

Something else? Talk to our team.

Does Kavra need names or emails?

No. Kavra assesses requests from technical and network signals. Those signals, such as IP addresses, can be personal data under GDPR, which is why the legal basis is applied per visitor region and the processing is described in the privacy policy.

Is my visitors' data shared with other customers?

No. Every project is isolated with its own keys, and there is no cross-customer linking of visitors.

Do I need a cookie banner for Kavra?

It depends on where your visitors are, and Kavra handles that per region. The bot check itself needs no cookie; where consent is required, Kavra works without a persistent identifier until consent is given. Your legal team makes the final call.

Is Kavra certified under SOC 2 or ISO 27001?

We do not claim these certifications. We share our data processing agreement and security documentation on request so your team can assess our practices directly.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.