Skip to content
Forum Fortress

Privacy and network access

The plugin sends supported forum activity to Forum Fortress for spam checks. This page explains the required network access, processing regions and data handling.

Network access

The plugin connects to Forum Fortress when it submits checks and service requests.

If your server uses an outbound firewall, allow outbound HTTPS traffic on port 443 to hosts ending in:

*.ffapi.net

This is how the plugin asks Forum Fortress to check registrations, logins, posts, profile updates, and other supported forum actions.

If these outbound connections are blocked, the plugin may be unable to check activity or update its status.

Choose where live checks are processed

Forum administrators can choose the API route used for live forum checks:

  • Global routes each check to an available Forum Fortress edge location. Use it unless you need live checks to remain in a specific region.
  • United Kingdom only, European Union only, or United States only locks live checks to Forum Fortress edge servers in that area. The check data is processed and the decision is made in the selected area, which can help support your privacy and data-residency requirements.

Regional locking applies to live protection checks. Bootstrap, portal access, account management, and the central decision record continue through the Forum Fortress control system in the United Kingdom. The central system stores logged decisions there; raw personally identifiable fields are retained for no more than 5 days and then replaced with one-way hashes. Non-raw outcome and technical metadata may remain under the retention rules in the Privacy Policy.

If strict regional processing is required, keep Allow global emergency fallback disabled. Enabling it allows a regional check to use the Global API after a regional outage, so processing may then take place outside the selected area.

Privacy policy

Before installing Forum Fortress on a live community, you may need to update your forum's privacy policy depending on your jurisdiction and how your community is operated.

To provide the service, Forum Fortress receives the information needed to analyse forum activity for spam. This can include details such as usernames, email addresses, IP-related information, submitted post content, profile content, links, and other signals relevant to the check being performed.

Read the Privacy Policy before enabling the plugin on a live forum:

forumfortress.com/privacy

This documentation is not legal advice. If you are unsure what your forum needs to disclose, check the rules that apply to you.

Log retention and hashing

Forum Fortress keeps plaintext decision data for a short period so recent spam patterns can be reviewed, debugged, and acted on effectively.

Plaintext values such as post content, usernames, and email addresses in logged decisions are retained for 5 days. After that, those values are replaced with one-way hashed versions.

A hash is a fixed value derived from the original data. A hashed username, email address or content fragment appears as a long string of letters and numbers.

Hashing lets Forum Fortress recognise the same detail again in future without keeping the original plaintext value indefinitely. If the same username, email address, link, or content pattern is submitted again, Forum Fortress can compare it against both current plaintext data and previously hashed data to help form a decision.

A one-way hash does not reveal the original username, email address or post content. A value you already know can still be hashed and compared with it.

Checking hashed details

Signed-in customers can check known values or hashes using the Blocklist checker in the Forum Fortress portal.

The portal checker accepts both plaintext values and Forum Fortress hashes.

If you submit a hash, the checker can look for information linked to that hash, but it cannot reveal the original value. Forum Fortress cannot reverse a hash back into the original username, email address, or content.