Technical audit · 2026-05-26

bundesheer.at

Austrian Armed Forces

Website of the Austrian Armed Forces — 34 requests, 1 domain. Zero external requests, zero cookies, zero trackers. Typo3 on a Cloudflare CDN. The policy covers only server logs and technically necessary cookies.

Timeline of the leak

+0 ms · load
All 34 requests to [www.bundesheer.at](https://www.bundesheer.at). CSS, JS, fonts, images, video — all local.

Context

Österreichisches Bundesheer (ÖBH) is Austria’s armed forces, subordinate to the Bundesministerium für Landesverteidigung (BMLV). HAR: 34 requests, 1 domain. Typo3 CMS, Cloudflare CDN/WAF.

One domain, zero trackers

34 requests, all to [www.bundesheer.at](https://www.bundesheer.at). Khand and icomoon fonts, Bootstrap icons, a video file — all hosted locally. Captcha is implemented via Typo3 powermail (server-side PNG generation). Cloudflare is used only as a WAF, with no external requests to Cloudflare analytics.

Policy — minimal and correct

The BMLV policy describes data processing across seven categories: the website, military service obligations, personnel, contracts, civilian service, media, and social networks. The section on the website covers only server logs and technically necessary cookies — no analytics, no trackers. A DPO is listed with contact details.

Conclusion

34 requests, 1 domain, zero violations. The armed forces — alongside BFA and BMI — show one of the cleanest profiles among Austrian state authorities.

Evidence
Original (audit)
HAR file: at/bundesheer-at-2026-05-26.har
SHA-256: 2d62136b4b05ec4f0446c8428e84e1bb0242789818d797bf01ccd6fe9774ca60
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.