STRATO web hosting: separate anonymized customer logs and security logs
At STRATO, a distinction must be made between the anonymized logs provided to customers and separate security processing. The hosting comparison lists six weeks for customer logs and up to seven days for full IP addresses for attack detection.
Requirements
Access to the STRATO customer account and knowledge of the activated statistics and security functions.
Setting
Deactivate unnecessary visitor statistics. Do not equate security logs with normal access logs, but document purpose and storage separately.
Test
After test calls, check which data is visible in the customer area and whether your own applications also store IP addresses.
Dismantling
If statistics are required, just reactivate the required function and check the resulting data again.
Other log levels
Setting this level alone does not exclude other logs. In addition, What does my hosting provider store about website visitors? and check web server, proxy/CDN, security and provider separately.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.