TrueAbuse

What the agent sends, in full.

You are putting this on a server, and the honest objection to a product like this is that it reads your logs. So rather than describing the payload, this page is the payload.

What leaves your machine

One event, in full. Every field the agent can send is in here; there is no second channel and nothing is collected in the background.

{
  "vm_id":        "vm-jkt-01",
  "ip":           "198.51.100.23",
  "jail":         "sshd",
  "action":       "ban",
  "timestamp":    "2026-02-14T03:27:25Z",
  "failures":     9,
  "log_lines":    [ "…the matching lines, 10 at most…" ],
  "origin_source": "socket",
  "agent_version": "1.4.0"
}
A web firewall event adds the rule id, the category, the method, the host and the request path. A mail event adds the score, the authentication results, the envelope sender, the subject and the recipient's domain.

What never leaves it

These are not settings you have to find and switch on. They are what the agent does.

How it travels

Where it lives once it arrives

What is sent on your behalf

Reports go out with your organisation's name and your reply address, so an abuse desk replying reaches you. A report held for want of evidence is never sent at all, and a contact that bounced or complained is suppressed rather than retried. If you remove an agent, the reports it already filed stay — they are the record of what was sent in your name, and an abuse desk may still write back about one.

Read the payload, then try it

Register one host, watch what it sends on the fleet page, and decide from there.

Open the portal How it works