Skip to content
Witen

Data and privacy

What data Witen receives

Local protection works without a Witen account. Connecting to the Witen network includes security-event reporting. Check the fields for your product before you connect.

Connected security events

ProductShared security data
WordPressClient IP, event category, and time, request URLs and methods, user agent, referrers, query information, and attempted usernames on relevant login events. Connection and inventory reports identify the site and its installed software versions.
MatomoPublic client IP, event category, and time, request path and method, and receipts for requests denied by Matomo. Shared events exclude usernames, query strings, fragments, cookies, request bodies, tracked visitor data, and scanned files.
WardenParsed security observations from configured log sources, including source IP, event category, and time, and available evidence such as request paths, attempted login identities, and client fingerprints. Reports include server identity, status, and enforcement outcomes.

Connections use an installation identifier and credential and send periodic status reports. A path or attempted login identity can contain personal information. Review your privacy notice and consent requirements for the log sources you enable.

WordPress and Matomo can also deliver events to a local Warden through separately configured settings. A connected Warden can forward those events to Witen.

Data that stays on your installation

Routine file scans inspect local files without uploading file contents. WordPress has a separate, optional sample-submission feature that is off by default; enabling it can upload selected samples. Local IP rules, login windows, and security logs support protection and troubleshooting. Matomo’s local log can contain attempted usernames even though its shared events exclude them.

Local blocking counters are separate from what is reported to Witen. Review the product guide for retention and storage settings, and protect backups as carefully as the original data.

External threat intelligence

Witen builds its own intelligence from what it observes. External feeds are used for comparison and benchmarking. Their listings, classifications, and scores do not contribute to Witen’s native reputation, confidence, or enforcement decisions.

Historical comparisons keep apart when Witen checked a source and the timestamps the source supplied, and tell a confirmed absence from a source that was unavailable or unchecked.

Stop future reporting

Turn off the Witen connection and any separate Warden event delivery. On Warden, remove configured enrollment and sensor credentials and restart the service. Local protection can remain active.

Disconnecting cannot retract events already delivered. See Disconnect or remove Witen and the privacy policy for account data requests.