Imperva

Imperva

Web application security platform providing DDoS protection, WAF, and bot management. Client-side scripts perform device fingerprinting and behavioral analysis to distinguish human visitors from automated traffic. Challenge pages may appear to users flagged as suspicious before they can proceed to the site.

Overview

Imperva (formerly Incapsula, acquired by Thales Group in 2023) is a cybersecurity company providing Web Application Firewall (WAF), DDoS protection, bot management, CDN, and API security services. It is used by financial institutions, e-commerce platforms, healthcare organizations, and government agencies to protect web applications from automated attacks, application-layer DDoS, SQL injection, cross-site scripting, and credential stuffing. Imperva's architecture operates as a reverse proxy — all traffic to the protected website routes through Imperva's network before reaching the origin server, allowing threat detection and mitigation at the edge.

What This Script Does

Imperva's client-side presence serves security verification purposes: detecting automated browsers, bots, and scripted attacks that reach the website.

JavaScript challenge execution:

  • Imperva injects a JavaScript challenge that browsers must execute to prove they are a legitimate browser environment
  • The challenge tests for capabilities that headless browsers (Puppeteer, Playwright, PhantomJS) and automation frameworks typically lack or simulate poorly
  • Challenge results are evaluated server-side; legitimate browsers receive a session validation cookie; suspicious clients are blocked or presented with a CAPTCHA

Device fingerprinting data collected:

  • User agent string and parsed browser/OS/version details
  • Screen resolution, color depth, and pixel ratio
  • Installed browser plugins and fonts (via canvas fingerprinting)
  • WebGL renderer and vendor strings
  • Timezone offset and language settings
  • JavaScript engine performance timing (used to detect virtual environments)
  • Network connection type if available via the Network Information API

Behavioral signals analyzed:

  • Mouse movement patterns and velocity (distinguish human from scripted input)
  • Keystroke timing patterns
  • Touch event characteristics on mobile devices
  • Scroll behavior

Cookies set:

  • visid_incap_<site-id> — first-party persistent cookie, 1-year expiry, stores Imperva's visitor session validation token that grants access to the protected site; required to pass the security check
  • incap_ses_<port>_<site-id> — session-scoped cookie, stores the active security session token for the current browser session
  • nlbi_<site-id> — first-party persistent cookie, load balancing and bot score caching, 1-year expiry
  • These cookies are strictly necessary for the security service to function; without them, the protection layer cannot distinguish validated humans from bots on subsequent requests

Consent & Compliance

Imperva's cookies and data collection fall under the essential consent category. Under ePrivacy Directive Article 5(3), the exemption for cookies "strictly necessary" for a service explicitly requested by the user extends to security services that protect the integrity of the requested website. The EDPB and national DPAs have confirmed that security cookies used for bot detection, DDoS protection, and fraud prevention qualify as strictly necessary and are exempt from consent requirements.

Under GDPR, Imperva's processing of device fingerprinting and behavioral signals for security purposes is covered by legitimate interest under Article 6(1)(f) — the legitimate interest being the protection of the website and its users from cyberattacks and fraud. This is a well-established legitimate interest that consistently passes the balancing test.

Under CCPA, data collected for security purposes is not sold or used for advertising and does not trigger opt-out rights. Imperva is headquartered in San Mateo, California; EU data is processed through Imperva's EU infrastructure and covered by SCCs.

Should You Block This Without Consent?

No. Imperva provides essential security services. Its cookies (visid_incap_*, incap_ses_*, nlbi_*) are strictly necessary for the security layer to function — blocking them would disable bot protection, WAF enforcement, and DDoS mitigation, leaving the website unprotected. These cookies and data collection activities are exempt from consent requirements under ePrivacy and covered by legitimate interest under GDPR.

Visit website

Consent Categories

Essential

Also Known As

ImpervaIncapsulaWAF bot protectionDDoS protectionImperva CDN

Industries

Computer SecurityComputers Electronics and Technology

Tracked Domains (48)

areyouahuman.comMarketing
yjyztmj.x.incapdns.netEssential
k2pf5eb.x.incapdns.netEssential
a7fug.x.incapdns.netEssential
a3rx86v.x.incapdns.netEssential
73iibbb.x.incapdns.netEssential
afmroz9.x.incapdns.netEssential
rq7cuf9.x.incapdns.netEssential
6xqnd8u.x.incapdns.netEssential
z9n3yzg.x.incapdns.netEssential
ks4pdkw.x.incapdns.netEssential
p4hb75p.x.incapdns.netEssential
ug55z8o.x.incapdns.netEssential
ezvhzv6.x.incapdns.netEssential
7eb5opl.x.incapdns.netEssential
evj3x.x.incapdns.netEssential
fwbzswe.x.incapdns.netEssential
gpxjedw.x.incapdns.netEssential
gx85csa.x.incapdns.netEssential
l5dykax.x.incapdns.netEssential
ze2e5pr.x.incapdns.netEssential
2ty7q3s.x.incapdns.netEssential
36wi5hm.x.incapdns.netEssential
3exvfbh.x.incapdns.netEssential
4jjom9f.x.incapdns.netEssential
5iqik.x.incapdns.netEssential
5kbz76q.x.incapdns.netEssential
5t48cjc.x.incapdns.netEssential
7v2agdo.x.incapdns.netEssential
7xjpy4d.x.incapdns.netEssential
838ovnu.x.incapdns.netEssential
982gl.x.incapdns.netEssential
avgu9hk.x.incapdns.netEssential
bp5os9q.x.incapdns.netEssential
c4sxz.x.incapdns.netEssential
unjv837.x.incapdns.netEssential
vc24x.x.incapdns.netEssential
vhob6qi.x.incapdns.netEssential
wex83ti.x.incapdns.netEssential
ybi7tpc.x.incapdns.netEssential
27qfj.x.incapdns.netEssential
55uoh6v.x.incapdns.netEssential
r8toxbq.x.incapdns.netEssential
rc5q24h.x.incapdns.netEssential
o8acato.x.incapdns.netEssential
lkq544l.x.incapdns.netEssential
9tbwo6o.x.incapdns.netEssential
y4qyd.x.incapdns.netEssential

Frequently Asked Questions

Does Imperva require consent?

No. Imperva provides essential web application security through WAF, DDoS protection, and bot detection. Its cookies are strictly necessary for the security layer to function. The ePrivacy Directive exempts security cookies from consent, and GDPR covers the processing under legitimate interest.

What does Imperva set on a website?

Imperva sets visid_incap (1-year, session validation token), incap_ses (session duration, active security token), and nlbi (1-year, load balancing and bot score caching). These cookies are strictly necessary for distinguishing validated human visitors from bots on every subsequent request.

How does ConsentStack handle Imperva?

ConsentStack classifies Imperva as essential, so its cookies load without requiring visitor consent. This ensures WAF enforcement, DDoS mitigation, and bot detection remain fully operational. ConsentStack accurately reflects the strictly necessary status in your consent records.

Related Vendors

Firebase
Firebase
Firebase is Google's mobile and web application development platform offering authentication, real-time database, cloud functions, and analytics. Web SDK scripts initialize Firebase services and may track app events via Firebase Analytics, which is powered by Google Analytics 4. Widely used in single-page apps and PWAs for backend infrastructure and usage tracking.
Google
Google
Google is the dominant provider of web analytics, advertising, and infrastructure tools. Scripts like Google Analytics, Tag Manager, Ads, and reCAPTCHA collect behavioral data, manage tag firing, serve targeted ads, and detect bots. Sets persistent cookies to track users and correlate activity across sites.
Google Tag Manager
Google Tag Manager
Google Tag Manager is a tag management system that lets marketers deploy and update analytics and marketing scripts without code changes. The GTM container script loads synchronously in the page head and injects configured tags, triggers, and variables on behalf of other vendors. No data collection of its own — acts as a loader for other scripts.
Google Fonts
Google Fonts
Google Fonts is a free font hosting service that serves hundreds of typeface families via a global CDN. Stylesheets and font files load from fonts.googleapis.com and fonts.gstatic.com to deliver web fonts to visitors. No advertising or tracking functionality is included.
reCAPTCHA
reCAPTCHA
Google reCAPTCHA is a bot detection and spam prevention service protecting web forms, login pages, and checkout flows. Scripts analyze user behavior, mouse movements, and browser fingerprints to distinguish humans from bots. The invisible reCAPTCHA v3 scores interactions without requiring user challenges.
Sign in with Google
Sign in with Google
Sign in with Google is an OAuth-based authentication service that enables users to log into websites using their Google account credentials. Scripts load the Google Identity Services library, display sign-in buttons, and handle token exchange for secure authentication. Stores session tokens and authentication cookies to maintain login state across page visits.

Manage consent for Imperva

ConsentStack automatically detects and manages Imperva trackers so your site stays compliant with global privacy regulations.