gnosis.aisi.gov.it
The journal of AISI — Italy's internal intelligence service. 15 requests, a single domain, not one external service. An old portal on Lotus Domino. Not a single cookie set, no analytics at all. The policy permits even more than the site does — there is no discrepancy, the site is simply extremely minimal.
Timeline of the leak
Context
gnosis.aisi.gov.it is the portal of the «Gnosis» journal, published by Italy’s Internal Information and Security Agency (AISI), part of the country’s national security system. The site runs on the Lotus Domino platform — an old architecture, but for that very reason extremely minimalist. The capture shows 15 requests, all to a single domain. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. Given whose publication this is, there is a special interest in privacy here. And the result is unambiguous: there is simply nothing to collect here.
Was there a consent banner
There is no banner, and it is not needed. On the site there are only technical session cookies, and in this capture not a single cookie appeared at all. There is no profiling, no third-party services. Since there is nothing to ask consent for, the absence of a banner here is natural.
Complete absence of trackers
Throughout the entire session — not a single external domain, not a single cookie, not a single analytics script. Only the site’s static resources: styles, images, the jQuery library — all from its own server. The connection is secure: the first request over the insecure protocol is immediately redirected to the secure one. This is the most minimal of the analysed sites: even the cleanest of the government portals had at least their own analytics, and here even that is absent.
The policy permits more than the site does
A curious detail on comparison. This portal’s policy is a general one — a single policy for the whole network of the intelligence community’s portals, written for an umbrella site. And it even allows the use of third-party YouTube and the collection of anonymous visit statistics. But the Gnosis journal specifically uses neither: no embedded videos, no analytics, not a single external request. That is, the site behaves more strictly than its own document allows. This is not a discrepancy in the usual sense — less privacy was promised, more was delivered — but it is worth noting: the boilerplate policy describes the network as a whole, not this extremely ascetic portal specifically.
What cannot be claimed from the capture
Honest caveats. The capture covers the journal’s home page; the behaviour of possible internal sections is not visible from here. The policy separately stipulates that navigation data may, if necessary, be used to establish identity in the course of investigating offences against the site — this is a standard security provision, and in an ordinary visit it does not manifest in any way. The exact server IP addresses are not preserved in the lightweight export, but this does not matter: the single domain belongs to the agency itself.
Conclusion
A clean result with no substantive caveats: no external domains, no trackers, no cookies, no analytics. For an intelligence service’s portal such asceticism is logical, but it is no less telling for that — it is a model of a site collecting nothing at all about the visitor beyond what is technically necessary. The policy even allows a little more than the site permits itself. The main takeaway for the reader: against the backdrop of portals that leaked data to Google and Meta from the first second, here there is not a single point where the visitor’s data would go anywhere — and this is exactly what an implementation utterly honest towards the user looks like.
35dcbe6db893f3e4f0a93969c3f1777866d99acdc52e009cd84618124a22b060