﻿---
title: "Client-side security & CSP monitoring - CentralCSP"
description: "Monitor Content Security Policy and every client-side threat from real browser traffic. One header, no agent, EU-hosted. Start a free 14-day trial."
url: "https://next.centralcsp.com/en/"
lang: "en"
---

Client-side security

# Your server is locked down. Your users' browsers aren't.

CentralCSP is a client-side security platform for security and engineering teams. One response header, no agent, collects every signal browsers report, turned into live monitoring, a script inventory, and real-time alerts.

[Start free trial](https://app.next.centralcsp.com) [Book a demo](https://next.centralcsp.com/en/contact/?topic=demo)

![The CentralCSP dashboard: a site's security score, its CSP violation trend over time, and the most recent client-side alerts.](https://next.centralcsp.com/assets/hero-dashboard-KiR2e_Kc.webp)

The threats

## The attack runs in your users' browser.

These threats execute client-side, after the page has left your servers. At that layer you have almost no visibility and nothing watching.

1.  ### Magecart and formjacking
    
    A skimming script slips onto your checkout and quietly copies card data as customers type it.
    
2.  ### Supply-chain script compromise
    
    A trusted third-party script gets hijacked and starts serving malicious code from a source you allowed.
    
3.  ### Cross-site scripting (XSS)
    
    Injected script runs in your users' session, stealing data and rewriting the page in front of them.
    
4.  ### Malicious redirects
    
    A tampered script sends users to a fraudulent page or fake payment form, away from your site.
    
5.  ### Data exfiltration
    
    A script quietly ships user data to an attacker's server, with no trace of where it went.
    
6.  ### Clickjacking
    
    A hidden overlay tricks users into clicking something they never intended to.
    

Why CentralCSP

## Client-side doesn't have to be the blind spot.

Without CentralCSP

Server-side defenses like WAF and SIEM can't see what runs in the browser after the page is delivered.

-   No client-side visibility
-   Third-party scripts uninventoried
-   Tampered scripts go unnoticed
-   Dependency CVEs invisible
-   Nothing watching, no alerts
-   No protection against client-side attacks

With CentralCSP

We monitor your policy and reports to give you the clearest overall view, and the actions to improve your security posture.

-   Full client-side visibility
-   Every script inventoried and sourced
-   Alerts on potential issues
-   Known CVEs flagged in your scripts
-   Real-time monitoring
-   Effective protection against client-side attacks

Real time

## See what real browsers report, as it happens.

We collect signals from your clients' browsers, in real time, so you get alerted when something goes wrong.

### Real-user coverage

Reports come from actual browser traffic, continuous monitoring from your production traffic.

### All browser signals

Full Reporting-API support, all signals collected with a single header.

### Live in minutes

Add one header and reports start flowing. No agent, no code changes.

## One dashboard for every signal coming from your pages.

Every script loaded, every Reporting-API report type, in one place.

## Trusted by teams across the world

From e-commerce checkouts to healthcare and SaaS, teams rely on us for their client-side security.

1.5B

reports ingested

82.5k

websites analyzed

1000+

websites monitored

Full

Reporting-API support

The platform

## Every layer of client-side security, covered.

Six capabilities on one platform: collect the signals, understand them, enforce a policy, and prove it.

### Monitoring

Every report type browsers can send, collected from your real visitors with a single header.

-   12 report types, one header
-   Real production traffic
-   Zero performance impact
-   Live violation feed

[See CSP monitoring](https://next.centralcsp.com/en/platform/monitoring/)

### Alerting

Custom rules watch your reports and ping the right channel the moment something changes.

-   5 channels plus webhooks
-   Custom alert rules
-   New origins and spikes
-   Routing per website

[See real-time alerts](https://next.centralcsp.com/en/platform/alerting/)

### CSP builder

Stop hand-writing policies. We build an enforceable CSP from what your traffic actually loads.

-   Generated from real reports
-   Report-only first, enforce when clean
-   Directive-by-directive control
-   Catches what a crawler misses

[See the CSP builder](https://next.centralcsp.com/en/platform/csp-builder/)

### PCI DSS evidence

Auditor-ready evidence for requirements 6.4.3 and 11.6.1, sourced from real browser traffic.

-   Payment-page script inventory
-   Justification workflow
-   Auditor-ready exports

[See PCI DSS evidence](https://next.centralcsp.com/en/platform/pci-dss/)

### Supply-chain

Know every script you ship and every script your scripts pull in, with advisories the moment one gains a CVE.

-   Script SBOM per site
-   Known-CVE detection
-   New-script alerts
-   Hash-change tracking

[See supply-chain protection](https://next.centralcsp.com/en/platform/supply-chain/)

### API and MCP

Everything in the dashboard is available to your own tooling, or to your AI agents over MCP.

-   Full REST API
-   Built-in MCP server
-   Exports and reports
-   Automate site onboarding

[See the API and MCP server](https://next.centralcsp.com/en/platform/api-mcp/)

[Compare plan features](https://next.centralcsp.com/en/pricing/)

How it works

## From browser signal to hardened front end

The reports are already coming from every browser. We collect them, show them live, turn them into an enforced policy, and flag the moment something changes.

1.  Collect
    
2.  2 Monitor
    
3.  3 Protect
    
4.  4 Detect

1.  Collect Gather every browser report
    
2.  2 Monitor See it live on one dashboard
    
3.  3 Protect Harden your configuration
    
4.  4 Detect Get alerted on what matters

### Collect the signals browsers already send

Point one Reporting-API endpoint at CentralCSP and browsers start streaming reports from real production traffic. No agent, no SDK, no code change.

-   Live in minutes with one response header
-   Every report type, from real users
-   No agent, SDK, or code change

### Turn raw signals into a realtime picture

Every report lands in a live dashboard that turns the browser's raw signals into insight your team can act on, as it happens.

-   A realtime feed of every report
-   Insight from real production traffic
-   Trends and breakdowns at a glance

### Tighten your policy and headers & configuration

We turn the reports you collect into a tightened Content-Security-Policy and review your security-header configuration, so nothing is left loose.

-   A CSP built from real reports
-   Security-header gaps surfaced
-   Lock the allowlist to what you trust

### Catch changes the moment they happen

CentralCSP keeps a continuous inventory of every script on your pages and alerts you the instant something new or vulnerable appears.

-   Alerts when something needs attention
-   A live inventory of every script
-   Known CVEs and new origins flagged

Integrations

## Get alerted where your team already works.

Send client-side alerts straight to the channels your team already lives in.

-   Microsoft Teams
    
-   Slack
    
-   Google Chat
    
-   Telegram
    
-   Email
    
-   Webhooks
    

### For developers

Use our security scanners and tools for free. Fix your configuration and check your Reporting-API setup. When you're ready, turn on continuous monitoring.

-   Security headers scanner.
-   Content-Security-Policy scanner / evaluator.
-   Reporting-API configuration checker.
-   Chrome extension, Content-Security-Policy builder.

[See the developer tools](https://next.centralcsp.com/en/solutions/developers/)

### For agencies

Add client-side monitoring to your care plans and watch every client site from one dashboard. Get alerted before your clients notice, and hand over reports showing your professional client-side security posture.

-   One dashboard for every client site, alerted before clients notice.
-   Professional reports, priced for a portfolio, not per app.
-   Integrate with your existing tools and processes.

[See how agencies use CentralCSP](https://next.centralcsp.com/en/solutions/agencies/)

Workflow

## Built to run at scale.

The full client-side workflow, across all your sites and teams.

### Detect every script

Every script running on your pages, surfaced from real browser traffic across all your sites, not a sampled crawl.

### Triage what matters

Automatic alerts surface the signals that matter, new origins, hash changes, violation spikes, and reach your team in the channels they already use.

### Prove compliance

Auditor-ready PCI DSS v4 evidence, exported from real browser traffic and kept as a continuous archive. No more guessing, proofs.

### Govern the policy

Build your policy from real reports, lock the allowlist to what you trust, and catch anything new the moment it appears.

### For compliance and PCI DSS v4

Meet PCI DSS v4 6.4.3 and 11.6.1 with continuous monitoring of the scripts on your sensitive pages, sourced from real browser traffic.

-   Authorization, make sure all scripts running on your pages are authorized.
-   Inventory, maintain an authorized list of all scripts running on your pages.
-   Integrity, enforce integrity and get notified when a script is tampered with.
-   Alert on new scripts, origins, and hashes.
-   Detect CVEs in scripts running on your pages.
-   Export audit-ready evidence.

[See the PCI evidence workflow](https://next.centralcsp.com/en/platform/pci-dss/)

### For enterprise

Enterprise-grade platform, built to meet the security and compliance requirements of regulated teams.

-   SSO, integrate seamlessly with your existing identity provider.
-   Support, dedicated support to help you with any question or issue.
-   SLA, ensure a high level of availability and performance.
-   RBAC, work as a team and ensure colleagues access only what they need.
-   EU-hosted, data never leaves the EU, hosted in France on OVH.
-   Scalable, the platform evolves with your needs.

[See the enterprise case](https://next.centralcsp.com/en/solutions/enterprise/)

![Wavestone 2026 French Cybersecurity Startup Radar](https://next.centralcsp.com/assets/wavestone-radar-9dPM570-.jpg)

Recognition · 2026

## Featured in the Wavestone Cybersecurity Startup Radar

Wavestone selected CentralCSP for its 2026 radar mapping the most promising cybersecurity startups in France, a strong signal that client-side security is becoming a priority for the whole industry.

[See the 2026 startup radar](https://www.wavestone.com/en/insight/2026-french-cybersecurity-startup-radar/)

Pricing

## Plans and pricing for client-side security.

EU hosting, all report types, and 90-day retention come standard on every paid plan. Pay annually and get two months free.

Monthly Annual

Save 2 months by paying yearly

The platform

## Reports are just the starting point.

Inventory, monitoring and alerting are built on top of them, turning visibility into action.

### One platform, every feature you need

The full client-side security suite, built on the reports browsers already send. Every layer of your client side, covered. One platform for every script, page, and policy you ship.

[Start free trial](https://app.next.centralcsp.com)

Product preview

### Script inventory

Every third-party script on your pages, mapped to its source and checked for known CVEs.

### Payment-page monitoring

Watch your checkout and payment forms. Continuous monitoring built for PCI DSS 6.4.3.

### Alerts & channels

Route new origins, hash changes, and specific event spikes to the channel your team already lives in.

FAQ

## Frequently asked questions

Everything you need to know about client-side security with CentralCSP.

### What is client-side security, and why does it matter?

Server-side defenses like WAF and SIEM can't see what runs in your users' browsers. Client-side security watches the scripts, requests, and policy violations that happen after your page is delivered, where attacks like Magecart skimming, formjacking, and supply-chain script compromise actually execute.

### How does CentralCSP work without an agent or code changes?

CentralCSP is built on the browser's Reporting API. You add a single response header and reports start flowing from your real visitors' browsers, with no JavaScript agent, no SDK, and no changes to your application code.

### Does CentralCSP help with PCI DSS v4 compliance?

Yes. It continuously inventories the scripts on your payment and checkout pages and exports auditor-ready evidence for PCI DSS v4 requirements 6.4.3 and 11.6.1, sourced from real browser traffic rather than a sampled crawl.

### Where is my data hosted?

All data is hosted in France on OVH and never leaves the EU, so you keep full European data residency.

### Will CentralCSP slow down my site?

No. There's no client-side script to load. Browsers send reports natively through the Reporting API, so there is zero performance impact on your pages.

### How do alerts reach my team?

Route new origins, hash changes, and violation spikes to the channels your team already uses, including Microsoft Teams, Slack, Google Chat, Telegram, and email. A webhook can also be used for anything custom.

## Start monitoring today.

Add one header and reports start flowing. No agent, no code changes. 14-day free trial.

[Start free trial](https://app.next.centralcsp.com) [Book a demo](https://next.centralcsp.com/en/contact/?topic=demo)

---

Available in: [en](https://next.centralcsp.com/en/), [fr](https://next.centralcsp.com/fr/)
