GDPR
Dokumentasjonen beskriver SCaptcha 2.3.0. Konfigurasjonsavhengige funksjoner er merket separat.
Scope
SCaptcha runs inside your WoltLab Suite installation. In normal operation, SoftCreatR does not receive verification data. Optional features and logging in your installation still need to be assessed separately.
Kjerneverifisering
Hver utfordring bruker et uavhengig, kryptografisk tilfeldig salt på 32 byte. WoltLab-installasjonen validerer salt, hash, algoritme, løsning og HMAC i økten som utstedte den. Utfordringen utløper etter 60 sekunder og krever ingen ekstern CAPTCHA-leverandør.
Valgfri proxyinformasjon
Deaktivert som standard. Når den aktiveres, sender SCaptcha den offentlige IP-adressen til proxycheck.io for tegn på proxy, VPN eller Tor. SCaptcha 2.3.0 sender tag=0 som standard; administratoren kan aktivere leverandørlogging. IP-adressen overføres uansett.
Logging at proxycheck.io
SCaptcha 2.3.0 sends tag=0 to proxycheck.io by default. Operators can opt in to provider-side positive-detection logs. The public IP address is transmitted for the lookup either way, and provider failure is not treated as a clean result.
Sikkerhetsinformasjonskapsler
Markøren før innsending og valgfritt tekst- eller lydbevis varer i 5 minutter. Under-Attack bruker en signert, brukeragentbundet kapsel i 5–30 minutter (10 som standard). Sentinel kan lagre et serverbestemt avslag i 10 minutter og er deaktivert som standard.
Optional browser checks
Behavior checks are off by default. The code contains pointer, movement, and scrolling checks, plus optional canvas, WebGL, and audio routines. Evaluation happens in the browser; results can affect local scoring and SCaptcha logs. This documentation therefore makes no blanket no-fingerprinting claim.
Analyse og lagring
Forespørselsanalyse er aktivert som standard og kan lagre koblingsbare driftsdata, blant annet IP, brukeragent, forespørsel, nettverk, sted, begrunnelser og innsendt telemetri. Lagringstiden er 90 dager som standard og kan settes fra 1 til 3 650. Deaktivering sletter ikke eksisterende rader eller eksporter.
Responsibility and data processing
In a normal self-hosted installation, SoftCreatR does not process visitor data on your behalf. If you enable proxycheck.io or another external service, assess and document that relationship separately. Your hosting and support setup can create additional roles.
Deployment checklist
Enable only the options you need. Update privacy and cookie notices, restrict access to analytics and logs, and test the actual form integration before launch.