Technical audit · 2026-05-26

bfa.gv.at

Federal Office for Immigration and Asylum

Federal Office for Immigration and Asylum — 38 requests, 1 domain. Zero external requests, zero cookies, zero trackers. jQuery, Bootstrap, Font Awesome — all served locally. The site is transitioning to a new portal, AsyluminAustria.at.

Timeline of the leak

+0 ms · load
All 38 requests to [www.bfa.gv.at](https://www.bfa.gv.at). jQuery 2.2.4, Bootstrap, bxSlider, Lightbox2, Font Awesome 4.7 — all local.

Context

BFA (Bundesamt für Fremdenwesen und Asyl) is the Austrian authority handling asylum applications and managing immigration matters. HAR: 38 requests, 1 domain. The privacy policy opens with a notice: the information is current through June 12, 2026, and the site is transitioning to a new portal, AsyluminAustria.at.

One domain, zero trackers

38 requests, all to [www.bfa.gv.at](https://www.bfa.gv.at). jQuery, Bootstrap, Font Awesome, bxSlider — all hosted locally. Myracloud WAF/CDN — the same setup as on polizei.gv.at. Zero cookies, zero external services.

Sensitive context

BFA processes the data of asylum seekers — one of the most vulnerable categories of data subjects. This is precisely why the absence of any external trackers on this site is not merely good practice, but alignment with the data minimization principle under conditions of heightened sensitivity.

Conclusion

38 requests, 1 domain, zero violations. One of the cleanest profiles among Austrian government sites — and one of the cases where that matters most.

Evidence
Original (audit)
HAR file: at/bfa-gv-at-2026-05-26.har
SHA-256: 6925277286a28abae1ba4f61f60f683f1cffa94dcd7dbef2fda090f38c5be934
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.