What Fortt Sees vs What Fortt Collects
Fortt was designed with radical transparency: you should always know exactly what we see and what we store about your requests. This page shows:-
The raw data Fortt can see when your backend forwards a
/verifyrequest - The minimal subset of data we actually store
- Why each piece is necessary
- Privacy guarantees
1. What Fortt Sees From a Request
When your server forwards a request to Fortt via:2. What Fortt Actually Stores
We only store the minimal fields required for bot detection, fraud scoring, and network intelligence. Here is exactly what we persist:3. Why We Store These Fields
| Field | Why we store it | Sensitive? |
|---|---|---|
| IP | Needed to detect VPNs, datacenters, bad ASNs and velocity attacks | IPs are not personal data by GDPR when used this way |
| ASN | Strong indicator of bot activity (datacenters, proxies, scrapers) | ❌ Not sensitive |
| Country | Helps detect impossible travels / geo anomalies | ❌ Not sensitive |
| User-Agent | Detect headless browsers / automation tools | ❌ Not sensitive |
| visitorId (hashed) | Identify continuity from same device | ✔ anonymized |
| Fingerprint signals | Detect spoofed environments or rotated devices | ✔ not reversible |
| Signal breakdown | Transparency + debugging + accuracy tuning | ❌ not personal |
| Score + bands | Determine bot likelihood | ❌ not personal |
| Timestamp | Traffic analysis, velocity, replay scanning | ❌ not personal |
4. What Fortt Never Stores
To be absolutely clear: We do not store:- Personal data (name, email, phone, CPF, address)
- Account information
- Payment information
- Business logic parameters
- Form data from your website
- Cookies or session tokens
- Authentication secrets
- Internal identifiers (userId, orderId, etc.)
5. Side-by-Side Comparison
What We See
(Raw request context your backend forwards)What We Save
(Minimal dataset required for fraud detection)Security Guarantees
✔ Data is encrypted at rest
PostgreSQL + Redis with full encryption.✔ Data is encrypted in transit
TLS 1.2+ enforced.✔ No cross-customer correlation
Each project is isolated — your traffic stays yours.✔ Logs have short retention
We automatically purge old entries unless otherwise configured.✔ Fully anonymized device identifiers
visitorId is non-PII and cannot be reversed.
In Summary
You can safely use Fortt knowing:- We see only what is needed to score risk
- We store an even smaller subset
- None of your user’s personal information is collected
- Your application’s internal data remains completely private
- Everything is encrypted, isolated, and purged regularly