New: export PCI DSS v4 evidence from real browser traffic.

Client-side security

Your server is locked down. Your users' browsers aren't.

CentralCSP is a client-side security platform for security and engineering teams. One response header, no agent, collects every signal browsers report, turned into live monitoring, a script inventory, and real-time alerts.

The CentralCSP dashboard: a site's security score, its CSP violation trend over time, and the most recent client-side alerts.

The threats

The attack runs in your users' browser.

These threats execute client-side, after the page has left your servers. At that layer you have almost no visibility and nothing watching.

  1. Magecart and formjacking

    A skimming script slips onto your checkout and quietly copies card data as customers type it.

  2. Supply-chain script compromise

    A trusted third-party script gets hijacked and starts serving malicious code from a source you allowed.

  3. Cross-site scripting (XSS)

    Injected script runs in your users' session, stealing data and rewriting the page in front of them.

  4. Malicious redirects

    A tampered script sends users to a fraudulent page or fake payment form, away from your site.

  5. Data exfiltration

    A script quietly ships user data to an attacker's server, with no trace of where it went.

  6. Clickjacking

    A hidden overlay tricks users into clicking something they never intended to.

Why CentralCSP

Client-side doesn't have to be the blind spot.

Without CentralCSP

Server-side defenses like WAF and SIEM can't see what runs in the browser after the page is delivered.

  • No client-side visibility
  • Third-party scripts uninventoried
  • Tampered scripts go unnoticed
  • Dependency CVEs invisible
  • Nothing watching, no alerts
  • No protection against client-side attacks

With CentralCSP

We monitor your policy and reports to give you the clearest overall view, and the actions to improve your security posture.

  • Full client-side visibility
  • Every script inventoried and sourced
  • Alerts on potential issues
  • Known CVEs flagged in your scripts
  • Real-time monitoring
  • Effective protection against client-side attacks

Real time

See what real browsers report, as it happens.

We collect signals from your clients' browsers, in real time, so you get alerted when something goes wrong.

Real-user coverage

Reports come from actual browser traffic, continuous monitoring from your production traffic.

All browser signals

Full Reporting-API support, all signals collected with a single header.

Live in minutes

Add one header and reports start flowing. No agent, no code changes.

One dashboard for every signal coming from your pages.

Every script loaded, every Reporting-API report type, in one place.

Trusted by teams across the world

From e-commerce checkouts to healthcare and SaaS, teams rely on us for their client-side security.

1.5B
reports ingested
82.5k
websites analyzed
1000+
websites monitored
Full
Reporting-API support

The platform

Every layer of client-side security, covered.

Six capabilities on one platform: collect the signals, understand them, enforce a policy, and prove it.

Monitoring

Every report type browsers can send, collected from your real visitors with a single header.

  • 12 report types, one header
  • Real production traffic
  • Zero performance impact
  • Live violation feed
See CSP monitoring

Alerting

Custom rules watch your reports and ping the right channel the moment something changes.

  • 5 channels plus webhooks
  • Custom alert rules
  • New origins and spikes
  • Routing per website
See real-time alerts

CSP builder

Stop hand-writing policies. We build an enforceable CSP from what your traffic actually loads.

  • Generated from real reports
  • Report-only first, enforce when clean
  • Directive-by-directive control
  • Catches what a crawler misses
See the CSP builder

PCI DSS evidence

Auditor-ready evidence for requirements 6.4.3 and 11.6.1, sourced from real browser traffic.

  • Payment-page script inventory
  • Justification workflow
  • Auditor-ready exports
See PCI DSS evidence

Supply-chain

Know every script you ship and every script your scripts pull in, with advisories the moment one gains a CVE.

  • Script SBOM per site
  • Known-CVE detection
  • New-script alerts
  • Hash-change tracking
See supply-chain protection

API and MCP

Everything in the dashboard is available to your own tooling, or to your AI agents over MCP.

  • Full REST API
  • Built-in MCP server
  • Exports and reports
  • Automate site onboarding
See the API and MCP server

How it works

From browser signal to hardened front end

The reports are already coming from every browser. We collect them, show them live, turn them into an enforced policy, and flag the moment something changes.

Turn raw signals into a realtime picture

Every report lands in a live dashboard that turns the browser's raw signals into insight your team can act on, as it happens.

  • A realtime feed of every report
  • Insight from real production traffic
  • Trends and breakdowns at a glance

Integrations

Get alerted where your team already works.

Send client-side alerts straight to the channels your team already lives in.

  • Microsoft Teams
  • Slack
  • Google Chat
  • Telegram
  • Email
  • Webhooks

For developers

Use our security scanners and tools for free. Fix your configuration and check your Reporting-API setup. When you're ready, turn on continuous monitoring.

  • Security headers scanner.
  • Content-Security-Policy scanner / evaluator.
  • Reporting-API configuration checker.
  • Chrome extension, Content-Security-Policy builder.
See the developer tools

For agencies

Add client-side monitoring to your care plans and watch every client site from one dashboard. Get alerted before your clients notice, and hand over reports showing your professional client-side security posture.

  • One dashboard for every client site, alerted before clients notice.
  • Professional reports, priced for a portfolio, not per app.
  • Integrate with your existing tools and processes.
See how agencies use CentralCSP

Workflow

Built to run at scale.

The full client-side workflow, across all your sites and teams.

Detect every script

Every script running on your pages, surfaced from real browser traffic across all your sites, not a sampled crawl.

Triage what matters

Automatic alerts surface the signals that matter, new origins, hash changes, violation spikes, and reach your team in the channels they already use.

Prove compliance

Auditor-ready PCI DSS v4 evidence, exported from real browser traffic and kept as a continuous archive. No more guessing, proofs.

Govern the policy

Build your policy from real reports, lock the allowlist to what you trust, and catch anything new the moment it appears.

For compliance and PCI DSS v4

Meet PCI DSS v4 6.4.3 and 11.6.1 with continuous monitoring of the scripts on your sensitive pages, sourced from real browser traffic.

  • Authorization, make sure all scripts running on your pages are authorized.
  • Inventory, maintain an authorized list of all scripts running on your pages.
  • Integrity, enforce integrity and get notified when a script is tampered with.
  • Alert on new scripts, origins, and hashes.
  • Detect CVEs in scripts running on your pages.
  • Export audit-ready evidence.
See the PCI evidence workflow

For enterprise

Enterprise-grade platform, built to meet the security and compliance requirements of regulated teams.

  • SSO, integrate seamlessly with your existing identity provider.
  • Support, dedicated support to help you with any question or issue.
  • SLA, ensure a high level of availability and performance.
  • RBAC, work as a team and ensure colleagues access only what they need.
  • EU-hosted, data never leaves the EU, hosted in France on OVH.
  • Scalable, the platform evolves with your needs.
See the enterprise case
Wavestone 2026 French Cybersecurity Startup Radar

Recognition · 2026

Featured in the Wavestone Cybersecurity Startup Radar

Wavestone selected CentralCSP for its 2026 radar mapping the most promising cybersecurity startups in France, a strong signal that client-side security is becoming a priority for the whole industry.

See the 2026 startup radar

Pricing

Plans and pricing for client-side security.

EU hosting, all report types, and 90-day retention come standard on every paid plan. Pay annually and get two months free.

Save 2 months by paying yearly

The platform

Reports are just the starting point.

Inventory, monitoring and alerting are built on top of them, turning visibility into action.

One platform, every feature you need

The full client-side security suite, built on the reports browsers already send. Every layer of your client side, covered. One platform for every script, page, and policy you ship.

Start free trial
Product preview

Script inventory

Every third-party script on your pages, mapped to its source and checked for known CVEs.

Payment-page monitoring

Watch your checkout and payment forms. Continuous monitoring built for PCI DSS 6.4.3.

Alerts & channels

Route new origins, hash changes, and specific event spikes to the channel your team already lives in.

FAQ

Frequently asked questions

Everything you need to know about client-side security with CentralCSP.

Start monitoring today.

Add one header and reports start flowing. No agent, no code changes. 14-day free trial.