Security controls you can reason about.
IVTB minimises the traffic data it needs, isolates publisher accounts and keeps sensitive provider credentials on the server. No security review replaces your own judgement — read the specifics below and the linked disclosure and privacy notices before you decide.
Data handling
Minimal browser storage
The publisher client relies on short-lived, signed decisions kept in first-party session storage. IVTB does not set an advertising cookie.
Visitor IP handling
Raw visitor IP addresses are used transiently for the risk lookup and token binding; they are not written to IVTB logs or the database. A secret-keyed hash may be retained for a limited period to support the decision it protects, and the hashing key can be rotated.
Provider responses
Raw responses from IP-intelligence providers are not persisted in logs. Only a normalized, provider-neutral outcome is retained for the decision.
Transport and isolation
Encrypted in transit
Every request to the API, dashboard and challenge surfaces is served over encrypted transport at the Cloudflare edge.
Tenant isolation
Sites and traffic data are scoped to the owning account. Authorization checks reject cross-tenant access attempts before any data is returned.
Server-held credentials
Intelligence-provider credentials are kept as encrypted server-side secrets. They are never exposed to the browser client or the publisher's page.
Fail-safe operations
Provider limits and circuit breakers
Intelligence lookups run against contracted monthly limits and circuit breakers. When a provider is unavailable or a budget is exhausted, IVTB degrades to a safe, configured fallback such as log-only operation rather than guessing.
Clear accountability
Sensitive account and billing changes generate audit events, so unexpected changes can be reviewed after the fact.
Security, in short.
For the full disclosure and privacy commitments, see the links below.
Security disclosure ↗Privacy notice ↗
Does IVTB store raw visitor IP addresses?+
No. Raw visitor IP addresses are used transiently for the risk lookup and token binding; they are not written to IVTB logs or the database. A secret-keyed hash may be retained for a limited period to support the decision it protects.
What happens if an intelligence provider is unavailable?+
IVTB applies provider limits and circuit breakers, then degrades to a safe, configured fallback such as log-only operation rather than blocking traffic on an unverifiable signal.
Can one publisher account see another publisher's data?+
No. Sites and traffic data are scoped to the owning tenant, and cross-tenant access attempts are rejected.
Review the controls, then start a trial.
Verify one domain, install one snippet and start with a clear three-day view of your traffic.