When “Biwak/1.0” shows up in your log.
As of 16 September 2026 · 4 min read
Biwak is a work tool for law firms and smaller businesses. It takes on a task, works through it and presents the result. If that task involves a page on the web — a statute, a commercial register extract, a product page a client has mentioned — it fetches it at that moment. No schedule, no queue, no collection being built up.
How to recognise us
Every request carries this identifier, unchanged and without a browser disguise in front of it:
Biwak/1.0 (+https://www.biwak.ai/bot; agent acting on behalf of a user)
Anyone can copy an identifier on its own. That’s why we also sign: every request carries the headers Signature, Signature-Input and Signature-Agent in line with RFC 9421, as the IETF draft Web Bot Auth specifies. The matching public key is published on this domain:
https://www.biwak.ai/.well-known/http-message-signatures-directory
If the signature verifies, the request really came from us; if it doesn’t, it didn’t — whatever the identifier says.
Cloudflare, Akamai and Stytch already check this method of their own accord. Anyone who doesn’t check it sees three headers they don’t recognise and ignores them; nothing can break as a result.
What we do and what we don’t
- We follow robots.txt. If it says something against us, that applies.
- We only read what is openly accessible without signing in. No credentials, no other people’s sessions, no paywalls.
- We don’t bypass security challenges. We don’t solve a puzzle meant to tell humans from machines — we tell the user that the page can’t be read from here.
- We don’t build an index or training material. Whatever was fetched serves the one question it belonged to.
- We don’t crawl your site. Only the address given is fetched; we don’t follow links from it on our own.
If you don’t want us
The quickest way needs no message to us and no waiting time — two lines in your robots.txt are enough:
User-agent: Biwak
Disallow: /
If you want it stricter, block on the server side by the identifier or by the presence of the signature. Both are unambiguous, and that is exactly the point: a visitor who identifies itself can also be shut out. If anything still gets through after that, it’s a bug on our side — write to us and we’ll fix it.
Contact
A real person replies, usually on the same working day, in German or English: kontakt@biwak.ai. The responsible person with name and address is listed in the legal notice, and the processing of personal data in the privacy policy. Biwak’s other commitments, and where they are enforced in the code, are on the Security and evidence page.
For a query, the time, the address fetched and the line from your log are useful. With those we can find the request again.
Questions people ask
Does Biwak collect data to train a model?
No. We don’t run a crawler, we don’t build an index and we don’t compile a text corpus for training. Biwak fetches a page when a person has, at that moment, asked a question that the page helps to answer. Then the request is over. We don’t train a model of our own, neither on your pages nor on any others.
How often does Biwak come, and how much load does that put on my server?
A request only ever arises from a person’s question, not from a schedule. There are at least 0.7 seconds between two requests from the same machine, a single request times out after eight seconds, and at most two megabytes are read. There is no crawl of your site structure: only the one address in question is fetched, and we don’t follow links from it on our own.
I don’t want this. How do I block Biwak?
Two lines in your robots.txt: “User-agent: Biwak” and below it “Disallow: /”. You don’t need to ask us or apply for anything. If you also want to be certain, block on the server side by the identifier or by the signature — both are unambiguous, precisely because we don’t hide. And if something still gets through, that’s a bug on our side and we want to hear about it.
Why doesn’t Biwak simply pose as a browser?
Because it doesn’t help and because it would be the wrong message. Until 16 September 2026, our identifier contained Chrome on a Mac with our name tacked on. Bot protection still recognises the data centre address and the connection fingerprint; so the line fooled nobody except the operator reading their log. For a product that promises law firms it will stick to the rules, that’s the wrong start.
Who is legally responsible for this request?
The request is made on the instructions of a specific person using Biwak, and within the scope of what they could have fetched themselves with a browser — public pages, no sign-in, no circumvention of a protective measure. If you need to know something about a specific request, write to us with the time and address; the legal notice names the responsible person with name and address.