FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Imunify360

Imunify360

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Imunify360 do?

Imunify360 is a server-side security suite by CloudLinux that protects Linux web servers against malware, brute-force, vulnerability exploitation and bot traffic. It runs on the hosting infrastructure and does not normally set cookies on visitors' browsers, although the optional CAPTCHA challenge layer can integrate with Google reCAPTCHA which does. For most European hosting providers and webmasters, Imunify360 has a low privacy footprint and relies on legitimate interest as its legal basis.

What is Imunify360

Imunify360 is a comprehensive security stack for Linux web servers offered by CloudLinux. It combines a web application firewall (WAF) with proactive defence, a malware scanner with one-click clean-up, brute-force protection, intrusion detection, IP reputation filtering and an optional CAPTCHA challenge for suspicious visitors. It is widely deployed by European hosting companies (cPanel-based shared hosting providers, VPS operators) and self-managed servers.

What data Imunify360 processes

For each incoming HTTP request, Imunify360 inspects the source IP, User-Agent, request path, query parameters, headers and (for POST traffic) the body. It maintains a local IP reputation cache plus a connection to the CloudLinux threat intelligence service. Malware scanning is performed on files inside the web roots and email mailboxes. None of this processing is exposed to the visitor''s browser; no cookies are set by default.

GDPR and ePrivacy implications

Imunify360 processes personal data (IP, request payload that may contain identifying information). The legal basis is legitimate interest (Art. 6(1)(f) GDPR), reinforced by the Art. 32 GDPR obligation to maintain security of processing. ePrivacy does not apply to server-side inspection; it only becomes relevant when the optional CAPTCHA layer (Google reCAPTCHA) is used, because reCAPTCHA itself sets cookies and transmits data to Google.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Threat intelligence and US transfers

Imunify360 sends suspicious request fingerprints, IP reputation data and malware sample hashes to CloudLinux Inc. servers in the United States. This transfer is covered by Standard Contractual Clauses in the CloudLinux EULA / DPA. The data minimisation is good: only hashes and metadata, not raw request bodies, are transmitted upstream.

NIS2 and security obligations

For essential and important entities under the EU NIS2 Directive, Imunify360 fits into the broader cybersecurity risk management framework. Document its deployment in your information security management system (ISMS), tie it to incident response runbooks, and ensure the logs (Imunify360 incident log) are retained for the period required by NIS2 reporting obligations.

Practical compliance checklist

1. Sign the CloudLinux DPA. 2. Document Imunify360 in your Record of Processing Activities under security. 3. Disclose the US threat intelligence transfer in your privacy notice. 4. If reCAPTCHA is enabled, treat it as a separate processor with consent obligations. 5. Configure incident logs retention to match NIS2 requirements. 6. Test the false-positive workflow so legitimate visitors are not unfairly blocked.

GDPR consent category

Essential

Websites using Imunify360 must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) and legal obligation under Art. 32 GDPR to ensure the security of processing. No browser-side consent is normally required because Imunify360 itself sets no cookies; reCAPTCHA challenges if enabled require separate consent
Risk levellow
Applicable regulationsGDPR, NIS2 Directive, ePrivacy Directive (only if reCAPTCHA layer is used)

DPIA considerations

Imunify360 processes IP addresses, request headers, request bodies (for WAF inspection), and uploaded files (for malware scanning). All processing happens on the customer's server; only suspicious patterns and IP reputation submissions are sent back to CloudLinux. Key DPIA considerations: (1) IP and request inspection is personal data processing under GDPR; (2) the legal basis is legitimate interest for security plus legal obligation under Art. 32; (3) threat intelligence sharing transmits hashed payloads to CloudLinux in the US, covered by SCCs; (4) if the CAPTCHA layer is enabled and uses Google reCAPTCHA, additional cookies and US transfers apply; (5) NIS2 Directive (EU) increases the importance of documented incident response. A streamlined DPIA is sufficient for typical hosting deployments.

Sample consent text

Our servers are protected by Imunify360 (CloudLinux). When you access this site, Imunify360 inspects your request to block malicious traffic. This processing is based on our legitimate interest in security under Art. 6(1)(f) GDPR and our legal obligation to protect data under Art. 32 GDPR. No cookies are set on your browser by Imunify360 itself. If the optional CAPTCHA challenge is shown, separate Google reCAPTCHA terms apply.

Technical details

Tracking methodServer-side security software running on the web hosting infrastructure. Processes HTTP request metadata (IP, User-Agent, payload) but does not set browser cookies for end users by default; integrates with optional reCAPTCHA challenge layer that does
Server locationCloudLinux Inc., headquartered in the United States. Runs locally on the customer's server; cloud threat intelligence database hosted in the US
Cookieless tracking availableYes
Data transferred outside the EUSuspicious request fingerprints, attack signatures, and malicious IP submissions are sent to CloudLinux servers in the US for threat intelligence sharing. Transfers are covered by Standard Contractual Clauses in the Imunify360 EULA / DPA.

Third-party domains contacted

imunify360.comcloudlinux.comupdates.imunify360.comiplists.imunify360.com

Cookies placed

NameTypeDurationPurpose
imunify360_xsStrictly necessarySessionSet only when the optional CAPTCHA challenge is triggered. Maintains the challenge session until the visitor is verified.
imunify360_temp_testStrictly necessary1 dayTest cookie used to verify cookie support before issuing a CAPTCHA challenge to a suspicious visitor.

Imunify360 is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Does Imunify360 set cookies on visitors' browsers?

No, not by default. Imunify360 is server-side and inspects requests at the web server level. Cookies appear only if the optional CAPTCHA challenge layer is enabled and configured to use Google reCAPTCHA, which sets its own cookies and is subject to separate consent.

Do I need visitor consent to use Imunify360?

No. Imunify360 itself does not set cookies or access information on the visitor's device, so Art. 5(3) ePrivacy does not apply. The lawful basis for processing IP and request data is legitimate interest plus the Art. 32 GDPR security obligation.

What is the legal basis for processing personal data via Imunify360?

Legitimate interest under Art. 6(1)(f) GDPR (network and information security), supported by the legal obligation under Art. 32 GDPR to ensure the security of processing. For essential or important entities under NIS2, the legal obligation aspect is reinforced.

Is data transferred to the United States?

Yes, hashed signatures and IP reputation submissions are sent to CloudLinux Inc. in the US. Transfers are covered by Standard Contractual Clauses in the CloudLinux DPA. The data minimisation is good: only metadata and hashes, not full request bodies.

Do I need a DPIA?

A streamlined DPIA is sufficient for typical hosting deployments. Run a more detailed DPIA if you process special category data, operate as a critical NIS2 entity, or use Imunify360 in combination with reCAPTCHA and behavioural rate-limiting.

How do I implement Imunify360 in compliance?

Sign the CloudLinux DPA, document Imunify360 in your Record of Processing Activities under security, disclose the US threat intelligence transfer in your privacy notice, configure log retention to match NIS2 obligations, test the false-positive workflow, and treat the optional reCAPTCHA layer as a separate processor with its own consent requirements.

What alternatives to Imunify360 exist?

EU-friendly WAF alternatives include ModSecurity with OWASP CRS (open source, self-hosted), BitNinja (Hungary, EU), Wordfence (US, plugin for WordPress), Sucuri (US, cloud-based WAF) and the WAF capabilities of Cloudflare or Bunny.net. For a fully EU stack, ModSecurity self-hosted plus fail2ban is the canonical choice.

How do I update my privacy notice?

Add an entry in your privacy notice describing the server security processing under Art. 6(1)(f) GDPR and Art. 32, naming CloudLinux Inc. as a processor for threat intelligence sharing with the US transfer disclosed. No cookie policy entry is needed unless the optional reCAPTCHA layer is enabled.