Privacy
Privacy Policy
This policy describes the information processed when you visit defisec.info or submit one of its forms. It also explains the analytics, anti-bot and rate-limit services used by the site.
Last updated:
Processing summary
- Website
- defisec.info
- Form destination
- alliance@defisec.info
- Analytics
- Ahrefs Web Analytics, Yandex Metrica and first-party event counts
- Bot protection
- Cloudflare Turnstile
- Local rate-limit window
- 60 seconds
Form submissions
When you submit a form, your browser sends the fields shown in that form to an endpoint on defisec.info. The fields may include your name, email address, message and any other information you choose to enter.
After validation, the endpoint sends the submission by email to alliance@defisec.info. Form contents move through a delivery queue and are not placed in the status database. A submission may remain in the queue while delivery is retried and in the recipient mailbox until it is handled or deleted.
First-party event counts
The site counts form opens, submission attempts, accepted or failed submissions, auditor selections, comparison opens and directory filter actions. It also counts profile and source-link clicks and download-link clicks. The records may contain the page path, form type, selected auditor, request type, technical status, public resource ID, active filter names and result count. They do not contain names, email addresses, message text, form field values or IP addresses.
Cloudflare Turnstile
Forms use Cloudflare Turnstile to identify automated traffic. The browser sends browser and environment signals to Cloudflare. On submission, the defisec.info server sends the Turnstile token and source IP address to Cloudflare Siteverify to validate the challenge.
Cloudflare states that Turnstile does not access, store or transmit information entered into a form. See the Turnstile documentation and Turnstile privacy addendum.
Ahrefs Web Analytics
Public pages load Ahrefs Web Analytics. Ahrefs describes processing the page URL, referring URL, language, page views, link clicks and form-submission events. It also derives browser, device and operating system information from the user agent, and approximate city and country from the IP address.
Ahrefs states that raw IP addresses are discarded rather than stored. It uses a daily salted hash for visitor counting and does not use cookies or persistent identifiers by default. Read the Ahrefs Web Analytics data description.
Yandex Metrica and Session Replay
Yandex Metrica measures visits and interactions to help us improve navigation and the directories. It can use cookies and browser identifiers. On content pages, Session Replay (Webvisor) records page content and interactions such as clicks and scrolling.
We disable Session Replay and click maps on the audit request, membership, participation, correction and Audit Builder form pages. We mark text-entry fields to exclude their values from recordings. Page addresses and referrers supplied in our Metrica initialization exclude query strings and fragments. Automatic link tracking is off.
Our first-party events do not include your contact details, search text or project brief. Yandex operates its own analytics systems; see its privacy policy and Session Replay settings. Blocking analytics does not prevent access to the site or its forms.
Security controls and technical records
The form endpoint checks the request origin, validates field lengths and uses a hidden anti-spam field. It also limits a source to five submission attempts within 60 seconds.
Cloudflare applies the rate limit at the edge. The application keeps a minimal delivery journal with the request identifier, form type, page path, selected auditor, request type, status, attempt count and technical error code. The journal contains no submitted contact details or message text and expires after 90 days.
CDN, hosting and email systems may keep their own request, security or delivery logs. Their retention is controlled outside the form application.
Retention and contact
The website code does not set a fixed deletion period for emails created from form submissions. Operational delivery rows expire after 90 days. Cloudflare controls queue, security and platform log retention under its service policies.
For a privacy question or a request concerning information sent through a form, email alliance@defisec.info. Include the email address used, the approximate submission date and the page containing the form so the message can be located.