CentralCSP

CentralCSP platform overview

How to set up and use CentralCSP. Connect a site, read its reports, build a PCI DSS script inventory, and alert on what changes.

Last update:

CentralCSP collects the reports browsers send about your pages, inventories the scripts running on them, and turns both into client-side security signal and PCI DSS v4 evidence.

The dashboard opens on report counters and a volume chart:

The CentralCSP dashboard with report counters and a browser reports over time chart

Start here

New to CentralCSP? Get started covers what it is, then takes you from an empty workspace to reports arriving.

Already collecting? Go straight to Reports.

The sections

The platform docs are organised into these sections:

SectionCovers
Get startedWhat CentralCSP does and the quickstart
WebsitesAdding a site, its endpoint, ingestion filters, usage, and access
ReportsAll 13 report types plus the raw Explorer
FeaturesPCI DSS, the script inventory, and alerting
TeamMembers, groups, and both role systems
SecurityWorkspace controls, audit logs, and retention
IntegrationsAPI keys and AI tools
BillingPlans, subscription, and quota
AccountYour profile and sign-in security

For the browser standards themselves rather than the product, see Web Security. To drive any of this from your own code or from an AI client, see the API and MCP reference.

Free tools, no account needed

These tools answer one question about a live site, with no account needed:

ToolAnswers
Security headers scannerWhich security headers and cookie flags a URL returns, graded
CSP scannerWhat a live page's Content-Security-Policy allows, and where it is weak
CSP evaluatorThe same review for a policy you have written but not deployed
Reporting API checkerWhether Reporting-Endpoints and report-to are wired up
CSP hash generatorThe hash that allowlists one inline script or style
SRI hash generatorThe integrity value for a script or stylesheet URL
Security comparisonHow a site's posture compares to others in its industry

Next steps

On this page