FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Imperva

Imperva

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Imperva do?

Imperva is a leading web application firewall (WAF) and DDoS protection provider used by European banks, governments, retailers and SaaS companies to defend their web infrastructure. It sits in front of the customer's website as a reverse proxy or DNS-routed CDN, inspecting every HTTP request for attacks. Imperva sets a small number of strictly necessary security cookies (such as the incap_ses_<id> and visid_incap_<id> cookies) which are exempt from prior consent under Art. 5(3) ePrivacy.

What is Imperva

Imperva (originally Incapsula) is a leading WAF, DDoS protection, bot management and API security provider. Deployed as a reverse proxy or DNS-routed CDN, it inspects every HTTP request before it reaches the origin server, blocking attacks (SQL injection, XSS, credential stuffing, layer 7 DDoS) and validating suspicious traffic with CAPTCHA challenges.

Cookies and data

Imperva typically sets incap_ses_<id> (session identifier for security context), visid_incap_<id> (visitor security identifier across sessions), and nlbi_<id> (load-balancing cookie). All are classified as strictly necessary for security. Imperva also processes IP, User-Agent, request bodies, headers and behavioural signals on the WAF level.

GDPR and ePrivacy

Imperva''s security cookies fall under the strictly necessary exemption of Art. 5(3) ePrivacy. They do not require prior consent. The processing of request data relies on legitimate interest (Art. 6(1)(f)) and the legal obligation in Art. 32 GDPR. EDPB guidance treats security cookies as strictly necessary as long as they remain proportionate.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and PoP routing

Imperva has European PoPs (Frankfurt, Paris, Dublin, London). You can request EU-only routing for traffic from European visitors. The central threat intelligence is in the US; aggregated and anonymised attack signatures are shared globally, covered by SCCs and EU-US DPF. For high-sensitivity deployments, document the routing and the threat-sharing in your security policy.

NIS2 and incident response

For essential and important entities under NIS2, Imperva is a key technical measure. Integrate Imperva alerts and logs into your SIEM and incident response runbook. Configure log retention to match NIS2 reporting obligations (significant incidents must be reported within 24 hours).

Practical compliance checklist

1. Sign the Imperva DPA. 2. Configure EU PoPs for European traffic. 3. Document Imperva in your Record of Processing Activities as a security measure. 4. Disclose Imperva in your privacy notice. 5. Integrate logs with your SIEM. 6. Map Imperva to your NIS2 incident response runbook. 7. Configure log retention to match obligations.

GDPR consent category

Essential

Websites using Imperva must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) and legal obligation under Art. 32 GDPR to ensure security of processing
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive (strictly necessary cookie exemption), NIS2 Directive

DPIA considerations

Imperva processes visitor IP, User-Agent, request URLs, request bodies and headers for inspection, plus aggregated threat telemetry. Key DPIA considerations: (1) cookies set are strictly necessary for security and may rely on the consent exemption of Art. 5(3) ePrivacy; (2) request inspection processes personal data, justified by legitimate interest and Art. 32 GDPR; (3) data may be processed in Imperva PoPs (some in EU, some elsewhere); (4) US threat intelligence sharing covered by SCCs; (5) NIS2 incident response obligations may apply. A streamlined DPIA is sufficient.

Sample consent text

Our site is protected against attacks and bots by Imperva. Imperva inspects each request and sets strictly necessary cookies (incap_ses_<id>, visid_incap_<id>) to remember which visitors have already passed security challenges. This processing is based on our legitimate interest in security and our legal obligation under Art. 32 GDPR.

Technical details

Tracking methodWeb application firewall and DDoS protection. Sits in front of the website as a reverse proxy or DNS-routed CDN. Sets a small number of security cookies for bot detection and challenge persistence
Server locationImperva, Inc., San Mateo, California, United States. Global PoPs including European cities (Frankfurt, Paris, Dublin, London)
Data transferred outside the EUVisitor IP, request metadata, security challenge results and aggregated threat telemetry are processed in Imperva PoPs and shared with the central Imperva threat intelligence in the US. Transfers covered by 2021 SCCs and EU-US DPF.

Third-party domains contacted

imperva.comincapdns.netincap.iocloudwaf.io

Cookies placed

NameTypeDurationPurpose
incap_ses_<id>Strictly necessarySessionImperva security session identifier used to recognise visitors that have already passed the WAF and bot challenges.
visid_incap_<id>Strictly necessary1 yearPersistent visitor identifier across sessions, used to maintain security context and prevent re-challenging trusted visitors.
nlbi_<id>Strictly necessarySessionLoad-balancing cookie that pins a visitor to the same Imperva PoP for consistent inspection.

Imperva is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Cookies Imperva sets?

incap_ses_<id>, visid_incap_<id>, nlbi_<id>. All strictly necessary for security.

Consent needed?

No, security cookies fall under the strictly necessary exemption of Art. 5(3) ePrivacy.

Legal basis?

Legitimate interest (Art. 6(1)(f)) and Art. 32 GDPR security obligation.

US transfers?

Threat intelligence is centralised in the US, covered by SCCs and DPF. Traffic can be EU-routed.

DPIA?

A streamlined DPIA is sufficient; full DPIA recommended for NIS2 critical entities.

Compliant deployment?

Sign DPA, EU PoP routing, document in Record of Processing Activities, integrate with SIEM, NIS2 runbook.

Alternatives?

EU-friendly WAF/DDoS: Cloudflare (US, EU PoPs), Akamai (US, EU PoPs), Fastly (US, EU PoPs), DataDome (France), Variti (Switzerland).

Policy updates?

Disclose Imperva as a security processor, mention the US threat intelligence transfer with SCCs, list the security cookies as strictly necessary.