Privacy Policy

Last updated: August 23, 2026

1. Data Collection

Enkidux WAF processes HTTP request data (IP addresses, user agents, request paths) as part of its security inspection. This data is stored locally in a SQLite database on your infrastructure. We do not collect, transmit, or store your request data on our servers.

2. License Verification

Enkidux verifies commercial licences entirely on your own infrastructure. A licence is a signed document that the agent validates locally against a public key compiled into the binary. Nothing is transmitted to us when you activate a licence or at any point afterwards: there is no verification server, no licence check-in, and no usage reporting. The software runs correctly with no outbound network access at all.

3. Threat Intelligence

The optional threat intelligence feed export feature shares anonymized data (attacker IP + attack type + confidence score). No personally identifiable information (PII), request bodies, or user data is included in threat feeds.

4. ProxyCheck API

When API mode is set to "always" or "smart", Enkidux sends visitor IP addresses to ProxyCheck.io for risk assessment. This is governed by ProxyCheck.io's own privacy policy. You can set API mode to "never" to disable this entirely.

5. Data Retention

Threat logs and reputation data are stored in your local SQLite database indefinitely. You control retention via database management. Cache entries expire based on your configured TTL (default: 7 days).

6. Contact

For privacy inquiries: privacy@enkidux.pro