What this site stores in your browser.
Last updated 9 September 2026
What this website stores in your browser
This notice sets out what may be set in your browser when you visit this website, who sets it, and what you can do about it. It is short and specific, because a security company should be able to tell you plainly what its own website does.
Essential cookies set by the hosting platform
This website is hosted on the Wix platform. Wix sets a small number of essential cookies that the site needs in order to work — to keep the site secure, to route your requests reliably and, where a cookie banner is shown, to remember the choice you make in it. These are set on every visit, cannot be switched off without affecting how the site works, and are not used to identify or track you across other websites.
Because the site runs on Wix, every page also loads code and images from Wix's own content networks, and an error-reporting script (Sentry) that Wix includes so that faults on the page can be diagnosed. Those services receive your IP address and browser details as a necessary consequence of serving you the page. They are part of how the site is hosted rather than something we have added on top.
What is actually set, and for how long
Measured on this site on 9 September 2026. Names and lifetimes are set by the platforms that create them and can change without notice to us; if you find something here that no longer matches, tell us and we will re-measure.
- ssr-caching — cyberti.com.au, expires the same day. Records which cache served the page. Set by Wix on every visit.
- server-session-bind — cyberti.com.au, expires when you close the browser. Keeps your requests on one server. Set by Wix on every visit.
- hs — cyberti.com.au, expires when you close the browser. Platform security. Set by Wix on every visit.
- XSRF-TOKEN — cyberti.com.au, expires when you close the browser. Protects forms against cross-site request forgery. Set by Wix on every visit.
- svSession — cyberti.com.au, 400 days. A random identifier Wix uses to recognise the same browser returning to this site. It does not carry your name or email, and it is not shared with other websites, but it is a persistent identifier and it lasts more than a year.
- consent-policy — cyberti.com.au, set only once you make a choice in the cookie banner, so that we do not ask again on every page.
- Google Analytics and Hotjar each set their own identifiers when their tags load — Google's under names beginning _ga, Hotjar's under names beginning _hj. See the analytics section above for what they record and for how long.
- LinkedIn sets bcookie and bscookie (one year), lidc (one day), JSESSIONID and lang (session) and __cf_bm (thirty minutes) — on our news page only, and only because that page embeds LinkedIn posts.
Analytics tools, where we use them
We use Google Analytics and Hotjar. Both load through Google Tag Manager on every page of this site, on every visit, before you choose anything in the cookie banner and irrespective of what you choose in it — the tags are currently installed as essential code on the hosting platform, which loads them ahead of the consent step. We are telling you plainly rather than leaving the banner to imply otherwise. Google Analytics measures pages viewed, scroll depth, outbound and download clicks and form interactions, and retains it for 14 months. Hotjar records a session replay of every visit, including mouse movement, clicks and typing; digits and email addresses are masked automatically, other text you type is not.
- No advertising, remarketing or conversion tracking, and no social media pixels.
- No advertising or remarketing profiles, and nothing that follows you from this website to another site we control. Our analytics tools do build a record of your individual visit — see the analytics section above and the table below — and the LinkedIn content on our news page is subject to LinkedIn's own tracking, which we do not control.
- Fonts are served from the hosting platform's own content network, not a third-party font service, so viewing a page does not send a request to a font provider.
Third-party content on the news page
Our news page embeds posts from our LinkedIn company page using LinkedIn's own embed, and shows headlines from a third-party security publisher. Each embedded post is a small LinkedIn page running inside our page, so opening our news page opens a connection to LinkedIn — it is not just an image. LinkedIn receives your IP address, your browser details and the address of the page you are on, and it sets its own cookies in your browser as soon as the page loads, without waiting for you to click anything. When we measured this on 9 September 2026 those cookies were bcookie and bscookie (LinkedIn browser identifiers, one year), lidc (routing, one day), JSESSIONID and lang (session), and __cf_bm (LinkedIn's bot protection, thirty minutes). LinkedIn also loads its own bot-defence provider inside the embed, which receives the same connection details. What LinkedIn does with any of this is governed by LinkedIn's privacy policy, not ours, and we cannot switch it off while showing the posts. The headline images come from the publisher's own image host, which is Google's Blogger content network. If you would rather not connect to LinkedIn at all, do not open our news page — every other page on this site is unaffected.
What the cookie banner actually does
The cookie banner on your first visit is the hosting platform's consent tool. Your choice is stored in an essential cookie so that we do not ask again on every page, and it controls anything the platform itself classifies as non-essential. It does not currently switch off the analytics tags described above, because those are installed as essential code — see that section for exactly what they do. We are working to bring the two into line.
Server logs
As with any website, the infrastructure that serves these pages keeps standard technical logs — including IP address, browser type, the page requested and the time of the request. These are not cookies and they are not created by anything running in your browser.
We use these logs to operate the site securely and reliably, to troubleshoot faults and to detect abuse. We do not use them to build a profile of you.
If this changes
If we introduce any non-essential technology in future, it will load only after you have accepted it, and we will update this notice and our Privacy Policy before it goes live — describing what is set, what it does and how long it lasts.
We will not introduce advertising or marketing tracking on this website without saying so here first.
Changing your mind
Clearing this site's data in your browser settings removes your stored choice and brings the banner back next time. Because the analytics tags load ahead of the banner, blocking them reliably means using a browser setting or extension that blocks Google Analytics and Hotjar. Nothing on this site breaks if you do — we have checked.
Most browsers also let you block or delete cookies for any website through their privacy settings, and to browse in a private or incognito window that discards cookies when you close it.
Questions about this notice
If you have a question about this notice, email us at info@cyberti.com.au.
How we handle personal information more generally is set out in our Privacy Policy.
Written to be kept to, not to be clicked past
These pages are short and plainly worded on purpose, so what they describe stays close to what we actually do — not a list of everything a lawyer could think to disclaim.
Ready to see your attack surface the way an attacker does?
Book a walkthrough with an Australian-based security engineer. No scripted demo, no obligation.
Both forms deliver to info@cyberti.com.au.