Overview
Bot detection and anti-fraud platform from Imperva, formerly Distil Networks (acquired by Imperva in 2019). Injects a JavaScript SDK that collects behavioural signals, device characteristics, and network metadata to distinguish bot traffic from real visitors. Cookies are set first-party on the customer's domain (the __uzm* family) even though the script and data collection are operated by Imperva. The security purpose typically supports a legitimate-interest legal basis under GDPR Article 6(1)(f) and the strictly-necessary exemption under ePrivacy Article 5(3), but organisations should still document the legitimate-interest assessment and include bot detection in their privacy notice.
Detection capabilities
- Signature count
- 2
- Detection methods
- network
- Property types
- hostnamepathname
Performance impact
Performance Impact
- Script size
- 40 KB
- Requests per page
- 3
Common mistakes
- 1Not disclosing bot detection + device fingerprinting in the privacy notice - even though it serves a security purpose, it involves collecting detailed behavioural and fingerprinting signals from all visitors
- 2Assuming the security exemption automatically applies in every EU member state - the ePrivacy Article 5(3) strictly- necessary exemption is interpreted differently across DPAs; some require explicit information disclosure even when consent itself is not needed
- 3Treating __uzm* cookies as third-party when they are first-party (script-set on the customer's own domain) - this changes the CMP categorisation
- 4Failing to document the legitimate-interest balancing test for the depth of data collected
Related services
Scan your site for Imperva Advanced Bot Protection
Run a free ConsentMark scan to see how Imperva Advanced Bot Protection is loading on your site, whether it respects consent, and where governance gaps exist across your wider tag estate.
Start a free scan