FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. PerimeterX

PerimeterX

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does PerimeterX (HUMAN Security) do?

PerimeterX, now part of HUMAN Security, is a bot mitigation and fraud prevention platform that distinguishes real users from automated traffic. It sets first party security cookies and runs client side JavaScript that collects device, browser and behavioural signals to score each visit. Because it relies on device fingerprinting and persistent identifiers, it raises specific ePrivacy and GDPR considerations even though it serves a security purpose. Signals are processed in the United States under the EU US Data Privacy Framework.

What PerimeterX (HUMAN Security) Is

PerimeterX is a bot mitigation and fraud prevention service that is now part of HUMAN Security, following the 2022 merger. It helps websites and applications tell genuine human visitors apart from automated traffic such as scrapers, credential stuffing tools and fake account bots. The service runs client side JavaScript that collects device, browser and behavioural signals, then scores each request on the server side to decide whether to allow, challenge or block it. It is widely deployed on login pages, checkout flows and APIs where automated abuse causes real financial harm. Because the protection is woven into the request path, it operates on every visitor rather than only on those who interact with a particular feature. This combination of persistent identifiers and large scale scoring is exactly what gives it both its security value and its privacy sensitivity.

Cookies and Data Collected

PerimeterX sets a small family of first party cookies in the website operator domain. The _pxvid visitor identifier persists for up to one year and acts as a stable device reference, while the _pxhd device hash helps check fingerprint consistency across sessions, and the short lived _px3 token carries a signed risk verdict that refreshes frequently. Alongside these cookies the client script reads device and browser signals such as canvas, WebGL and audio characteristics, navigator properties and connection level TLS and HTTP fingerprints. It also collects behavioural biometrics including mouse movement, scrolling and keystroke timing throughout the session. These signals together build a device fingerprint and behavioural profile that the backend uses to assign a bot or human verdict. The exact cookie set and durations can vary by deployment and product configuration.

GDPR and ePrivacy Implications

The signals PerimeterX processes, including device identifiers and behavioural patterns, are personal data under the GDPR because they single out and recognise individual users and devices. Security and fraud prevention can be a legitimate interest under Article 6(1)(f), and the recitals expressly recognise fraud prevention as a valid interest, but the controller must still run and document a balancing test. The ePrivacy Directive adds a separate layer because reading information from and storing information on a user device generally requires consent unless it is strictly necessary for a service the user has explicitly requested. Regulators such as the CNIL treat device fingerprinting the same way as cookies for this purpose. Whether the strictly necessary exemption applies is fact specific and tends to be read narrowly, so many deployments cannot assume it covers all of the collection. This tension between a legitimate security purpose and the ePrivacy storage and access rule is the central compliance question for the tool.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements and CMP Integration

Many operators argue that the security cookies and signals strictly necessary to keep a login or payment flow safe fall within the ePrivacy exemption, and so place them in a strictly necessary category that loads without prior consent. That position is defensible only where the collection is genuinely limited to security and is not reused for analytics, advertising or profiling. Any signal collection that goes beyond protecting the requested service, or that is reused for other purposes, should be gated behind consent in your consent management platform. A practical approach is to classify PerimeterX as a security control, document why each cookie and signal is necessary, and ensure your CMP reflects that classification transparently. You should also describe the device fingerprinting plainly in the cookie notice so users understand that more than simple cookies are involved.

International Data Transfers

HUMAN Security is headquartered in the United States and operates its services from there, so signals collected from European visitors are transferred to the United States for processing. HUMAN self certifies under the EU US Data Privacy Framework and its UK and Swiss extensions, which provides an adequacy based transfer mechanism for organisations that participate. Where the framework does not cover a particular transfer, Standard Contractual Clauses are used as a fallback safeguard. As a controller you should confirm the current certification status, record the chosen transfer mechanism in your records of processing, and complete a transfer impact assessment where your risk approach requires one. Keeping evidence of these mechanisms is important because the legal landscape for transatlantic transfers has changed several times.

Practical Compliance Steps

Start by signing a data processing agreement with HUMAN Security and mapping exactly which cookies and signals are collected on your site. Document your legitimate interest assessment for fraud prevention and decide, per page or flow, whether the strictly necessary exemption truly applies or whether consent is needed. Update your privacy notice and cookie policy to name the security cookies, explain the device fingerprinting and behavioural analysis, and state that signals are processed in the United States. Configure your consent management platform so that any non essential collection is blocked until the user agrees. Set appropriate retention expectations and confirm with the vendor how long identifiers such as the visitor cookie persist. Finally, review the configuration periodically so your documentation stays aligned with how the product is actually deployed.

GDPR consent category

Essential

Websites using PerimeterX (HUMAN Security) must obtain user consent under GDPR regulations.

Legal basisLegitimate Interest (GDPR Article 6(1)(f)) for bot mitigation, fraud prevention and account abuse protection, supported by a documented Legitimate Interest Assessment. Consent (Article 6(1)(a)) may be required under the ePrivacy Directive where device fingerprinting and storage go beyond what is strictly necessary for a service the user explicitly requested.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidelines on fingerprinting, TTDSG (Germany), LOPDGDD (Spain), EU US Data Privacy Framework

DPIA considerations

A Data Protection Impact Assessment is strongly recommended because PerimeterX combines persistent device fingerprinting, behavioural biometrics and large scale automated scoring of every visitor, which constitutes systematic monitoring under Article 35. The assessment should document the necessity and proportionality of fingerprinting for fraud prevention, the retention of visitor identifiers such as the one year _pxvid cookie, the transfer of signals to the United States, and the measures that limit reuse of the data beyond security. It should also weigh the legitimate interest in security against the impact on users who cannot easily opt out of a protective control.

Sample consent text

This site uses PerimeterX by HUMAN Security to protect against bots and fraud. It stores a security identifier on your device and analyses device and behaviour signals to tell humans from automated traffic. These signals are processed in the United States.

Technical details

Tracking methodFirst party security cookies combined with device and browser fingerprinting, TLS and HTTP signal analysis, and continuous behavioural biometrics (mouse, scroll and keystroke patterns) collected by client side JavaScript
Server locationUnited States (HUMAN Security, Inc., New York), with edge processing across a global network
Data transferred outside the EUSignals are processed in the United States. Transfers from the EEA, UK and Switzerland rely on the EU US Data Privacy Framework and the UK and Swiss extensions, backed by Standard Contractual Clauses where applicable.

Third-party domains contacted

perimeterx.netpx-cdn.netpx-cloud.nethumansecurity.com

Cookies placed

NameTypeDurationPurpose
_pxvidfirst party securityUp to 12 monthsPersistent visitor identifier that gives each device a stable reference so the service can recognise returning visitors and build session history for bot detection.
_pxhdfirst party securityUp to 12 monthsDevice hash used to check that the device fingerprint stays consistent across sessions and to support risk scoring.
_px3first party securityShort lived (refreshes during the session)Holds a cryptographically signed risk verdict token that confirms whether a request was assessed as human, refreshed frequently.
_pxdefirst party securitySessionCarries encrypted diagnostic and signal data used to validate the integrity of the security check.

PerimeterX (HUMAN Security) is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does PerimeterX set?

PerimeterX sets first party security cookies in the operator domain, typically a _pxvid visitor identifier that can last up to a year, a _pxhd device hash and a short lived _px3 token that carries a signed risk verdict. It also reads device and browser signals and behavioural patterns rather than relying on cookies alone. The exact names and durations can vary by deployment.

Is consent required to use PerimeterX?

It depends on how the tool is scoped. Where the security cookies and signals are strictly necessary to protect a login or payment the user requested, many operators rely on the ePrivacy strictly necessary exemption and load them without consent. Where collection goes beyond that or is reused for other purposes, consent is required and the activity should be gated in your consent banner.

What is the legal basis for PerimeterX?

The processing is usually based on legitimate interest under Article 6(1)(f) for fraud prevention and bot mitigation, supported by a documented balancing test. Separately, the ePrivacy Directive governs the storage and access on the device, which can still require consent even when the underlying processing rests on legitimate interest.

Does PerimeterX transfer data to the United States?

Yes. HUMAN Security operates from the United States, so signals from European visitors are transferred there for processing. Those transfers rely on the EU US Data Privacy Framework and its UK and Swiss extensions, with Standard Contractual Clauses used as a fallback where needed.

Is a DPIA needed for PerimeterX?

A Data Protection Impact Assessment is strongly advised because the tool combines persistent device fingerprinting, behavioural biometrics and automated scoring of every visitor, which amounts to systematic monitoring. The assessment should cover necessity, proportionality, retention of identifiers and the US transfer.

How do I implement PerimeterX compliantly?

Sign a data processing agreement, map the cookies and signals collected, and document your legitimate interest assessment. Update the privacy notice and cookie policy to describe the fingerprinting and US processing, and configure your consent management platform so that any non essential collection waits for consent.

What are the alternatives to PerimeterX?

Other bot mitigation and fraud prevention options include Cloudflare Bot Management, Akamai Bot Manager, DataDome and Arkose Labs. Each makes different trade offs on fingerprinting, hosting region and consent posture, so evaluate them against your data residency and privacy requirements.

How do I update my cookie policy for PerimeterX?

List the security cookies by name where possible, state their purpose and duration, and explain that device fingerprinting and behavioural analysis are also used. Note that signals are processed in the United States and identify the transfer mechanism, then review the wording whenever the configuration changes.