Changelog
CentralCSP Team ·
Last update:
Today we replaced the CentralCSP website, dashboard, and documentation with a new version, and we changed our plans. If you are an existing customer, your plan, your price, and your reporting endpoints do not change. You now sign in at app.centralcsp.com. Everything else in this post is new capability.
CentralCSP started as a Content Security Policy (CSP) reporting tool. You added one header, we collected the violation reports, and we helped you build a policy from them. That is still the core of the product. But the product is moving from CSP reporting to client-side security, everything your users' browsers can tell you about your site, and the old platform was not the base to build that on.
So we rebuilt it, and not only to support new report types. The new platform handles report volumes the old one could not, runs entirely in the EU, in France on OVH, and ships a redesigned interface that looks better and is faster to work in. The site, the dashboard, and the docs were all rebuilt on the same foundation, a client-side security platform built on the browser Reporting API.
What shipped on September 13
- A new dashboard at app.centralcsp.com, rebuilt around every browser report type, not only CSP.
- Monitoring for 12 browser report types through the same single header you already send.
- Alerting on six channels with custom rules and no monthly alert caps.
- A script inventory with SBOM, version, and CVE detection on every paid plan.
- A rebuilt PCI DSS v4 module with payment page monitoring and auditor-ready evidence exports.
- A full REST API and a built-in MCP server, so your agents can do anything you can click.
- A new documentation site, a new website, and both in English and French.
- New plans, Start, Business, and Scale. Existing customers keep their current plan and price.
One header, every report type
The old CentralCSP ingested two report types, CSP violations and script hashes. The new monitoring ingests 12, through the same Reporting-Endpoints header you already have in production:
Reporting-Endpoints: default="https://MyEndpoint.report.centralcsp.com"Beyond CSP violations and script hash reports, the platform now collects network errors (NEL), browser crashes, deprecations, interventions, COOP and COEP violations, Permissions-Policy, Document-Policy, and Integrity-Policy violations, and Connection-Allowlist reports. Each type gets its own dashboard, filters, and a report explorer for the raw payloads.
The reasoning is simple. Your server logs stop at your server. These reports are the only signal that comes from your users' browsers, and CSP violations are just one of them. If a checkout script changes, a third party starts failing, or a browser starts crashing on one page, the browser reports it. Now we catch all of it.
Alerting that fits your stack
The old alerting supported Slack, Teams, email, and webhooks, three rule families, and a monthly alert quota per plan. The new alerting supports six channels, Slack, Microsoft Teams, Google Chat, Telegram, email, and signed webhooks, with 14 rule types across all report types. New origin on a page, script hash change, violation spike, known CVE in a loaded script, changes on a payment page, and more.
Alert quotas are gone. On plans that include alerting, alerts are unlimited.
Know every script your visitors run
The script inventory now builds a client-side SBOM from the hashes browsers report, with library and version detection, lifecycle status, and CVE matching. When a script you load ships a known vulnerability, you see it, and you can alert on it. Per-page attribution and hash change tracking come with it. Read more on the supply-chain page.
PCI DSS v4 evidence, rebuilt
The PCI DSS module is now a full compliance area. You declare your payment pages, the platform inventories the scripts that run there, and you authorize and justify each one. When a justified script changes, the change is flagged for re-review and can trigger an alert. Evidence for requirements 6.4.3 and 11.6.1 exports as CSV and PDF, written for the person who reads it, your assessor.
The same wording applies as before. CentralCSP helps you meet 6.4.3 and 11.6.1 by producing the evidence; it does not certify compliance. The module is included on Scale and Enterprise plans.
An API, and an MCP server
Everything in the dashboard is now on a REST API, sites, reports, script inventory, metrics, alert rules, members, and the audit log. Next to it sits a built-in MCP server, so Claude Code, Cursor, or any MCP client can query your reports, inspect your script inventory, and manage alert rules with scoped, revocable tokens. The API and MCP reference documents both. Both are included from the Business plan up.
New docs, and everything in French
The documentation moves to its own site with three sections, Platform for the product, Web Security for the standards (the Reporting API, CSP and every directive, COOP, COEP, Permissions-Policy, NEL, and the rest), and API and MCP for the reference. The blog moves from /articles to /blog.
The website, the dashboard, and the docs are now fully available in French. All data is hosted in France on OVH and never leaves the EU.
Eight free tools, and the State of the Web
The CSP scanner, evaluator, hash and SRI calculators, and the Chrome extension stay. Three tools join them, a security headers scanner, a Reporting API checker, and Compare your site, which benchmarks your configuration against the dataset behind our annual State of the Web report, built from 521,442 scanned domains. All free, no account.
New plans
The old Starter, Advanced, Pro, and Corporate plans are no longer sold. The new lineup is three self-serve plans plus Enterprise, priced in EUR, with annual billing at ten times the monthly price (two months free). See the full comparison on the pricing page.
| Plan | Price | Reports per month | Websites | Users |
|---|---|---|---|---|
| Start | €39.99/mo | 250,000 | 3 | 5 |
| Business | €129.99/mo | 2,000,000 | 10 | 25 |
| Scale | €349.99/mo | 10,000,000 | 30 | 100 |
| Enterprise | Custom | Custom | Custom | Custom |
The entry price is higher than the old Starter plan, and the entry plan is much bigger. Start includes 250,000 reports per month where Starter included 15,000, five users instead of one, all 12 report types, CVE detection, and the script inventory. Business adds the API, the MCP server, and unlimited alerting. Scale adds the PCI DSS v4 module, SSO, and the audit log. Every paid plan includes 90-day retention and EU hosting.
What stays the same on every plan, the single-header setup, custom reporting subdomains, the policy builder, unlimited scans, and 90-day retention.
If you are an existing customer
Nothing changes on your bill. Your current plan, price, quotas, and features are grandfathered for as long as you keep your subscription. The new plans apply to new signups from September 13.
Your account, websites, historical reports, policies, and alert rules are migrated automatically. Your reporting endpoints keep working unchanged, there is nothing to redeploy. The one visible change, you now sign in at app.centralcsp.com.
You also get the new platform. Your plan keeps every feature it includes today and gains all 12 report types, with their dashboards and the report explorer, the first time you log in. Features introduced with the new plans, like the MCP server or the PCI DSS v4 module, follow the new lineup; you can switch plans from the billing page if you want them.
Questions you may have
What are the new CentralCSP plans?
Start, Business, and Scale, plus Enterprise on quote. The pricing page has the full comparison table.
Will my price change?
No. Existing subscriptions keep their current price and quotas indefinitely. If you want the new plans, you can switch from the billing page, and switching is permanent.
Do I need to change my reporting header?
No. Your endpoint and your custom subdomain keep working exactly as before.
Where did the docs and old articles go?
The docs live on the new documentation site and the blog moved from /articles to /blog. Old article and docs URLs redirect to their new equivalents, so existing bookmarks and links keep working.
Can I move to a new plan?
Yes, from the billing page in the dashboard. Compare what you would gain on the pricing page first, because you cannot move back to a retired plan.
Is my data affected by the migration?
No. Reports, policies, and settings are migrated automatically, and retention stays at 90 days. Data is hosted in France on OVH.
What comes next
This release is the foundation, one platform for every signal browsers report about your site. Next we build on it, more report types as browsers ship them, deeper analysis, and more evidence for the people you answer to.
Log in at app.centralcsp.com to see your sites on the new platform, or start a free trial if you are new. If something looks wrong after the migration, contact us and we will fix it.