# Security and privacy at Kavra

Source: https://kavralab.com/security/

**Kavra** detects fraud from technical and network signals, not from identity data: no names, emails or phone numbers are needed. Those signals can still be personal data under GDPR, so Kavra applies the legal basis per visitor region, keeps data isolated per customer, encrypts collection end to end and retains it for bounded periods.

## What Kavra processes

| Category | Examples | Notes |
|---|---|---|
| Network data | IP address, network owner, proxy, VPN, Tor and datacenter classification | We treat an IP address as personal data as a matter of policy |
| Device and browser signals | Graphics, screen, hardware and browser properties, automation artifacts | Used as evidence, never as the identifier |
| Interaction signals | How the page was used before the protected action, such as pointer and timing patterns | Used to tell people from scripts |
| Identity data | Names, emails, phone numbers | Not needed; Kavra does not ask for them |

## Roles and legal basis

When your site or app sends Kavra a check about one of your visitors, you are the controller and Kavra Lab (SIA ADVERTIMO) acts as your processor. For our own IP-intelligence reference data, we are the controller. Both roles are described in the [privacy policy](https://kavralab.com/privacy/).

The rules that apply follow the visitor, not your company. You declare your legal basis per region; Kavra applies it to each visitor from their network location and respects your consent manager. Where a persistent identifier is not permitted, the script does not read browser storage at all.

## How data is protected

- **Encrypted collection**: Browser evidence travels in an application-layer encrypted envelope on top of TLS, so intermediaries cannot read or alter it.
- **Tamper-resistant tokens**: Tokens are signed, single-use, short-lived and bound to one action. Replayed tokens are refused and reported.
- **Strict tenant isolation**: Every project has its own keys. There is no cross-customer tracking or linking of your visitors with anyone else's.
- **Pseudonymous identities**: Visitors appear under opaque, server-assigned IDs. Fingerprint values are keyed per project and used only as evidence.
- **Data minimization**: Addresses used for internal consistency checks are hashed in the browser with a per-session salt, location is kept coarse, and no third-party services are called from your visitors' browsers.
- **Access control**: Console roles (owner, operator, viewer), API keys that are shown once and can be revoked, and an audit log of every change.

## Where data is processed and how long it is kept

| Topic | Practice |
|---|---|
| Location | EU infrastructure as the baseline; service providers outside the EEA are disclosed in the privacy policy |
| Retention | Bounded periods, defined per data type in the privacy policy; not indefinite |
| Erasure | Deletion support for data-subject requests |
| Automated decisions | Kavra recommends and explains; your backend decides, which supports your obligations around automated decision-making |

## Certifications and procurement

We do not claim security certifications we do not hold. This page and the [privacy policy](https://kavralab.com/privacy/) describe our practices; they are not a statement that compliance has been independently verified. For procurement, we share a data processing agreement and security documentation with your team on request through the [contact form](https://kavralab.com/contact/).

Found a security issue? Report it through the contact form and choose "Something else"; it goes straight to the team.

## FAQ

### Does Kavra need names or emails?

No. Kavra assesses requests from technical and network signals. Those signals, such as IP addresses, can be personal data under GDPR, which is why the legal basis is applied per visitor region and the processing is described in the privacy policy.

### Is my visitors' data shared with other customers?

No. Every project is isolated with its own keys, and there is no cross-customer linking of visitors.

### Do I need a cookie banner for Kavra?

It depends on where your visitors are, and Kavra handles that per region. The bot check itself needs no cookie; where consent is required, Kavra works without a persistent identifier until consent is given. Your legal team makes the final call.

### Is Kavra certified under SOC 2 or ISO 27001?

We do not claim these certifications. We share our data processing agreement and security documentation on request so your team can assess our practices directly.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
