DeFi Security Alliance

Privacy

Privacy Policy

This policy describes the information processed when you visit defisec.info or submit one of its forms. It also explains the analytics, anti-bot and rate-limit services used by the site.

Last updated:

Processing summary

Website
defisec.info
Form destination
alliance@defisec.info
Analytics
Ahrefs Web Analytics
Bot protection
Cloudflare Turnstile
Local rate-limit window
10 minutes

Form submissions

When you submit a form, your browser sends the fields shown in that form to an endpoint on defisec.info. The fields may include your name, email address, message and any other information you choose to enter.

After validation, the endpoint sends the submission by email to alliance@defisec.info. This implementation does not place form contents in an application database. A submission may remain in the recipient mailbox until it is handled or deleted.

Cloudflare Turnstile

Forms use Cloudflare Turnstile to identify automated traffic. The browser sends browser and environment signals to Cloudflare. On submission, the defisec.info server sends the Turnstile token and source IP address to Cloudflare Siteverify to validate the challenge.

Cloudflare states that Turnstile does not access, store or transmit information entered into a form. See the Turnstile documentation and Turnstile privacy addendum.

Ahrefs Web Analytics

Public pages load Ahrefs Web Analytics. Ahrefs describes processing the page URL, referring URL, language, page views, link clicks and form-submission events. It also derives browser, device and operating system information from the user agent, and approximate city and country from the IP address.

Ahrefs states that raw IP addresses are discarded rather than stored. It uses a daily salted hash for visitor counting and does not use cookies or persistent identifiers by default. Read the Ahrefs Web Analytics data description.

Security controls and technical records

The form endpoint checks the request origin, validates field lengths and uses a hidden anti-spam field. It also limits a source to five submission attempts within ten minutes.

Rate-limit state contains attempt timestamps under a SHA-256 hash of the source IP address. Timestamps older than ten minutes are removed when the state is processed again. The application may record an operational error and request identifier when form delivery fails, but its error messages do not include submitted form contents.

CDN, hosting and email systems may keep their own request, security or delivery logs. Their retention is controlled outside the form application.

Retention and contact

The website code does not set a fixed deletion period for emails created from form submissions. Rate-limit timestamps expire from active state after the ten-minute window described above.

For a privacy question or a request concerning information sent through a form, email alliance@defisec.info. Include the email address used, the approximate submission date and the page containing the form so the message can be located.