Overview
Bot detection and anti-fraud platform from Imperva, formerly Distil Networks (acquired by Imperva in 2019). Injects a JavaScript SDK that collects behavioural signals, device characteristics, and network metadata to distinguish bot traffic from real visitors. Cookies are set first-party on the customer's domain (the __uzm* family) even though the script and data collection are operated by Imperva. How the security purpose bears on consent gating is a determination for the site operator and its advisers; the observable behaviour is behavioural and device-level collection from every visitor, so bot detection belongs in the privacy notice either way.
Detection capabilities
- Signature count
- 2
- Detection methods
- network
- Property types
- hostnamepathname
Performance impact
Performance Impact
- Script size
- 40 KB
- Requests per page
- 3
Common mistakes
- 1Not disclosing bot detection + device fingerprinting in the privacy notice - even though it serves a security purpose, it involves collecting detailed behavioural and fingerprinting signals from all visitors
- 2Assuming the security exemption automatically applies in every EU member state - the ePrivacy Article 5(3) strictly- necessary exemption is interpreted differently across DPAs; some require explicit information disclosure even when consent itself is not needed
- 3Treating __uzm* cookies as third-party when they are first-party (script-set on the customer's own domain) - this changes the CMP categorisation
- 4Leaving the depth of data collected undocumented in the privacy notice - the SDK gathers behavioural signals, device characteristics and network metadata from every visitor
Related services
Scan your site for Imperva Advanced Bot Protection
Run a free ConsentMark scan to see how Imperva Advanced Bot Protection is loading on your site, whether it respects consent, and where governance gaps exist across your wider tag estate.
Start a free scan