Security logs stay on the protected website.
Site administrators control and review the local logs generated by their installation.
How the BitFire WordPress security plugin handles local security logs, bot verification, reputation checks, and security-related data.
Site administrators control and review the local logs generated by their installation.
Administrators may also delete plugin logs sooner under their own policies.
Security information is processed for protection, classification, and abuse prevention.
BitFire is a WordPress security plugin owned and operated by BitSlip6, LLC. This Privacy Policy explains how BitFire handles security-related data when the plugin is installed on a WordPress website.
BitFire is designed to protect WordPress websites from malicious bots, automated attacks, exploit attempts, malware activity, unauthorized file changes, suspicious requests, and other security threats. Data processed by BitFire is used for security, abuse prevention, bot verification, threat classification, and site protection.
BitFire stores security log data locally on the website where the plugin is installed. This may include:
BitFire filters request data to remove or reduce sensitive values such as credit card numbers, passwords, tokens, nonces, authentication secrets, and similar security-sensitive fields.
Local security logs are used by site administrators to review attacks, investigate suspicious activity, troubleshoot security issues, and understand how the plugin is protecting the site. Local logs are reviewable only by the website's administrators. BitFire does not provide public access to these logs.
Standard retention for local security log data
BitFire stores local security log data for security review and investigation purposes. Local log data is removed from the server after 30 days.
Website administrators may also delete plugin logs manually according to their own site policies, hosting practices, or compliance requirements.
BitFire verifies non-human visitors, crawlers, and bots using reverse DNS data to help authenticate the claimed origin of known bots.
Unknown bots, suspicious IP addresses, and bot-related request data may be checked against BitFire's central IP and bot reputation database. These checks are used to determine whether a visitor should be allowed, blocked, or placed into restricted access mode.
The BitFire reputation system is owned and operated by BitFire.
BitFire may send filtered and anonymized sample request data from bots to BitFire servers for classification, reputation analysis, and security research.
This bot-related data is used to improve bot detection, identify malicious automation, classify suspicious traffic, and build aggregate IP and bot reputation data that helps protect other BitFire customers.
BitFire does not use this data to identify human visitors. BitFire does not collect human browser activity for advertising, profiling, resale, or visitor identification purposes.
BitFire may temporarily process security log data on the local website as part of normal firewall and attack detection functionality. This local processing may include request metadata associated with normal website traffic.
BitFire does not transmit human visitor browsing data or human visitor IP addresses to BitFire servers for tracking, advertising, profiling, or marketing purposes.
Any local processing of visitor request data is performed for website security, abuse prevention, attack investigation, and firewall operation.
BitFire is designed to filter sensitive request values before storing or transmitting security samples. This includes filtering data that appears to contain passwords, credit card numbers, authentication tokens, nonces, secrets, and similar sensitive fields.
BitFire does not sell personal data.
BitFire does not share human visitor data with advertisers, data brokers, or marketing platforms.
Aggregate bot reputation data may be used across BitFire customers to improve detection of malicious bots, scanners, exploit tools, abusive automation, and suspicious IP activity.
Website administrators may request that BitFire purge data associated with their host system from BitFire's systems, including IP addresses, user-agent strings, and site data.
BitFire does not use subprocessors to process plugin security data.
BitFire infrastructure is hosted in Vultr SOC 2 data centers located in:
BitFire integrates with BitFire servers for security classification, bot reputation, and related plugin functionality. BitFire also uses DNS resolution as part of bot verification and security checks.
BitFire does not rely on third-party advertising networks or tracking services as part of its security logging or bot reputation functionality.
The BitFire service does not use cookies. This helps maintain maximum compatibility across the web servers protected by the plugin.
Requests from client systems to the BitFire service do not produce additional tracking data beyond the information normally present in a standard access log.
Website administrators are responsible for configuring BitFire appropriately for their website, reviewing local logs as needed, and ensuring that their own website privacy policy accurately describes the security tools and logging practices used on their site.
Because BitFire runs on the website owner's WordPress installation, local log files remain under the control of the website owner and their hosting provider.
BitFire uses security logging, request filtering, bot verification, and reputation-based controls to help protect WordPress websites from malicious activity.
No security tool can guarantee complete protection against every threat. Website administrators should keep WordPress, plugins, themes, server software, and credentials properly maintained and updated.
Changes to this Privacy Policy will be communicated in BitFire plugin release notes and by updating this page. The latest modification date is shown at the top of the policy.
For privacy or security questions related to BitFire, contact our support team.