AVG
De documentatie beschrijft SCaptcha 2.3.0. Configuratieafhankelijke functies zijn afzonderlijk gemarkeerd.
Scope
SCaptcha runs inside your WoltLab Suite installation. In normal operation, SoftCreatR does not receive verification data. Optional features and logging in your installation still need to be assessed separately.
Kernverificatie
Elke challenge gebruikt een onafhankelijk, cryptografisch willekeurig salt van 32 bytes. De WoltLab-installatie valideert salt, hash, algoritme, oplossing en HMAC in de uitgevende sessie. De challenge verloopt na 60 seconden en vereist geen externe CAPTCHA-provider.
Optionele proxy-informatie
Standaard uitgeschakeld. Na inschakeling stuurt SCaptcha het openbare IP-adres naar proxycheck.io voor aanwijzingen over proxy, VPN of Tor. SCaptcha 2.3.0 stuurt standaard tag=0; de beheerder kan providerlogging inschakelen. Het IP-adres wordt in beide gevallen verzonden.
Logging at proxycheck.io
SCaptcha 2.3.0 sends tag=0 to proxycheck.io by default. Operators can opt in to provider-side positive-detection logs. The public IP address is transmitted for the lookup either way, and provider failure is not treated as a clean result.
Beveiligingscookies
De marker vóór verzending en het optionele tekst- of audiobewijs gelden 5 minuten. Under-Attack gebruikt een ondertekende, aan de user-agent gebonden cookie voor 5–30 minuten (standaard 10). Sentinel kan een serverbesluit tot weigering 10 minuten bewaren en staat standaard uit.
Optional browser checks
Behavior checks are off by default. The code contains pointer, movement, and scrolling checks, plus optional canvas, WebGL, and audio routines. Evaluation happens in the browser; results can affect local scoring and SCaptcha logs. This documentation therefore makes no blanket no-fingerprinting claim.
Analyse en bewaartermijn
Verzoekanalyse staat standaard aan en kan koppelbare operationele gegevens opslaan, waaronder IP, user-agent, verzoek-, netwerk- en locatievelden, redenen en verzonden telemetrie. De bewaartermijn is standaard 90 dagen en instelbaar van 1 tot 3.650. Uitschakelen verwijdert geen bestaande regels of exports.
Responsibility and data processing
In a normal self-hosted installation, SoftCreatR does not process visitor data on your behalf. If you enable proxycheck.io or another external service, assess and document that relationship separately. Your hosting and support setup can create additional roles.
Deployment checklist
Enable only the options you need. Update privacy and cookie notices, restrict access to analytics and logs, and test the actual form integration before launch.