FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Detectify

Detectify

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Detectify do?

Detectify is a Swedish External Attack Surface Management and web vulnerability scanner. Operated by Detectify AB in Stockholm, it crawls customer websites from cloud workers, simulates real attacker payloads from a crowd sourced research community and reports findings via a SaaS console.

What is Detectify?

Detectify is an External Attack Surface Management (EASM) and web vulnerability scanner founded in Stockholm in 2013. The product crawls internet exposed customer assets from cloud workers, fingerprints services and runs payloads contributed by an invite only crowd sourced research community (Detectify Crowdsource). Findings appear in the Detectify console with severity, exploit description and remediation guidance.

Cookies and data collected

Detectify does not embed any client side tag on customer websites. The console at detectify.com sets first party authentication cookies (detectify_session, csrf_token) for the customer team. The marketing site at detectify.com loads HubSpot, Google Analytics 4 and Segment, which set their own cookies subject to consent. Scanner workers fetch HTTP responses, headers, screenshots and DOM trees from the customer assets being assessed.

GDPR and ePrivacy implications

Detectify acts as a processor of the customer for the scanning service (Art. 28 GDPR). The console authentication cookies are strictly necessary. Marketing site analytics and CRM cookies fall under Article 5(3) of the ePrivacy Directive. Scans that traverse authenticated areas may expose user account data: customers must define scope carefully and obtain employees and end users awareness where appropriate.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

For the Detectify console, only strictly necessary cookies are set, and they are consent exempt. For the Detectify marketing site, HubSpot and Google Analytics cookies are gated behind their own consent banner. For the customer adopting Detectify, no consent is needed from website visitors because Detectify does not embed any code on the customer site; the scanner runs externally.

Data residency and transfers

Detectify AB is a Swedish company and the core platform runs on AWS EU regions (Frankfurt, Ireland). Scanner workers are distributed globally to verify geo dependent exposure. Customer support, marketing analytics and certain sub processors operate in the United States. Detectify signs SCCs and publishes a sub processor list and DPA addendum.

Practical compliance steps

Sign the Detectify DPA, define scanning scope explicitly to avoid touching user account data unintentionally, configure SSO for the console, document Detectify as a processor in your record of processing, and inform DPO and security teams about findings handling. No update to your public cookie policy is required for the scanner alone.

GDPR consent category

Essential

Websites using Detectify must obtain user consent under GDPR regulations.

Legal basisStrictly necessary cookies on the Detectify console (authentication, CSRF) do not require consent. Analytics and marketing cookies on the public marketing site require consent under Art. 6(1)(a) GDPR. Scanning customer assets is performed under the customer's instruction as a processor under Art. 28 GDPR.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), CCPA

DPIA considerations

Detectify scans customer owned assets and discovers vulnerabilities, configuration issues and exposed data. The processing acts on assets, not on end users of the customer site, so a DPIA is rarely required for the scanner itself. It may be appropriate where Detectify findings include personal data exposures that the customer must triage and remediate, or where scanning includes authenticated areas with user accounts.

Sample consent text

We use Detectify to scan our own websites for vulnerabilities. Detectify does not embed any code on this website; the scanner runs externally from Detectify AB infrastructure in the European Union. No personal data of visitors is shared with Detectify as part of routine scanning.

Technical details

Tracking methodExternal SaaS vulnerability scanner that crawls customer websites from cloud workers; web app at detectify.com sets first party authentication cookies for the customer console and runs analytics and marketing scripts on the marketing site; does not embed any tag on customer websites.
Server locationSweden (Detectify AB, headquartered in Stockholm). Production infrastructure runs on AWS, primarily in EU regions (Frankfurt, Ireland) with scanner workers distributed worldwide to test geographically dependent assets. Marketing site and analytics tools may use US sub processors (Segment, HubSpot, Google Analytics 4).
Data transferred outside the EUDetectify AB is a Swedish company and the core scanning infrastructure is EU based, which makes Detectify a low risk option for European customers. However, the customer facing console at detectify.com loads analytics and CRM scripts from US sub processors (Segment, HubSpot, Google), and customer support traffic is processed by Zendesk in EU and US. Standard Contractual Clauses are signed.

Third-party domains contacted

detectify.comapp.detectify.comassets.detectify.comapi.detectify.com

Cookies placed

NameTypeDurationPurpose
detectify_sessionStrictly necessary (console authentication)SessionMaintains the authenticated user session in the Detectify console
csrf_tokenStrictly necessary (CSRF protection)SessionProtects authenticated requests against CSRF attacks
OptanonConsentFunctional (Detectify marketing site consent)1 yearRecords the consent state for marketing analytics cookies on detectify.com

Detectify is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Detectify set?

On the Detectify console, only strictly necessary cookies (detectify_session, csrf_token). On the marketing site detectify.com, HubSpot, Google Analytics 4 and Segment cookies are loaded behind a consent banner. Detectify does not embed any tag on customer websites.

Is consent required for Detectify?

Not on the customer site itself, because Detectify does not embed any client side code. The Detectify marketing site has its own consent banner. The console runs on strictly necessary cookies, which are exempt.

What is the legal basis?

Detectify acts as a processor of the customer under Art. 28 GDPR for the scanning service, which itself relies on Art. 6(1)(f) legitimate interest in keeping the customer assets secure. Console authentication uses Art. 6(1)(b) contract.

Does Detectify transfer data outside the EU?

Core scanning and customer data live on AWS EU regions (Frankfurt, Ireland). Scanner workers are distributed globally to verify geographically dependent issues. Some marketing and support sub processors operate in the US under SCCs and the EU US Data Privacy Framework.

Do I need a DPIA?

Usually no: Detectify scans assets, not visitors. A DPIA may be appropriate if Detectify findings include personal data exposures requiring triage, or if scans target authenticated areas with user accounts at scale.

How do I implement Detectify compliantly?

Sign the Detectify DPA, define scanning scope explicitly, activate SSO for the console, document Detectify in your record of processing as a processor for security testing, and connect findings to your vulnerability management process.

Are there alternatives?

Yes: Acunetix (Liechtenstein), Qualys (US), Tenable (US), Probely (Portugal/EU), Intruder (UK), Snyk (UK/US), Burp Suite Enterprise (UK). EU origin scanners reduce transfer risk; non EU need SCCs and a TIA.

How do I update my cookie policy?

You do not need to update your public cookie policy because Detectify does not embed cookies on your website. If you log in to the Detectify console, the cookies are first party to detectify.com and managed by Detectify's own privacy policy.