Angriffsabwehr2 min read2 sections

Privacy & GDPR

What we store, what we never store, retention and deletion - and how anonymous abuse notifications work.

01

What we store

What we store

  • The reported IP address, its score, category, confidence and listing state (needed for the blacklist function).
  • Aggregate metadata: service type, hour of the signal, source type (anonymous / token / honeypot).
  • Optional: the reporter's self-created token ID (to show personal statistics).

What we do NOT store

  • Reporter IP addresses or hostnames (anonymous reports carry no reporter identity).
  • Raw log lines, usernames, passwords or any evidence content.
  • Exact timestamps (signals are displayed rounded to the hour).

Retention & deletion

Scores decay exponentially (half-life 3-30 days depending on signal type). Entries without new activity auto-delist and become inactive. The responsible abuse desk receives at most one anonymized notification per IP per 7 days.

02

Abuse notifications

When an IP is listed, we resolve the responsible provider via RDAP/whois and send one anonymized notification in X-ARF format (max. once per IP per 7 days). Notifications never contain reporter identities.

  • Tor exit nodes are flagged but never reported to abuse desks (shared infrastructure).
  • Mail servers on the dnswl.org whitelist get reduced weight for mail services - a whitelisted server can still be compromised, so we soften but do not silence.