﻿---
title: "Client-side security for web agencies, all client sites"
description: "Monitor CSP, scripts and security headers across every client site from one dashboard, no agent to install. Resell it in your care plans. EU-hosted."
url: "https://next.centralcsp.com/en/solutions/agencies/"
lang: "en"
---

For agencies

# Every client site. One security dashboard.

Monitor the scripts, policies and headers of your whole portfolio from one place, and turn client-side security into a service your clients pay for. EU-hosted.

[Start now](https://app.next.centralcsp.com) [Talk to sales](https://next.centralcsp.com/en/contact/?topic=sales)

## Fifteen sites is fifteen attack surfaces

-   No time to babysit
    
    You ship sites weekly. Nobody on the team has hours to review raw violation reports per client.
    
-   Clients want proof
    
    "Are we secure?" deserves better than a shrug. You need something credible to show, in plain words.
    
-   PCI landed on your desk
    
    Your merchant clients forward the auditor's questionnaire to you. 6.4.3 and 11.6.1 are now your job.
    

For your portfolio

## Agency features, built in.

Everything you need to run security for a book of clients, included in one plan.

### Your whole portfolio, at a glance

Every client site on one screen: security score, report volume, open advisories. Green means move on. Red means you knew before the client did.

-   Health and score per site
-   CVE flags on client scripts
-   Drill into any site in one click

[See portfolio monitoring](https://next.centralcsp.com/en/platform/monitoring/)

### Scoped to how agencies work

Sites grouped per client, access scoped per project, alerts routed per team. Your juniors see their clients, not your whole book.

-   Per-client groups
-   Team access per project
-   Alert channels per client

[See alert routing](https://next.centralcsp.com/en/platform/alerting/)

### Nothing to install

One response header per client site and reports flow from real visitor browsers.

-   12 report types, one header
-   Real production traffic
-   Zero performance impact

[See how collection works](https://next.centralcsp.com/en/platform/monitoring/)

### CSP builder

Build and refine each client's policy from what their traffic actually loads.

-   Generated from real reports
-   Report-only first, enforce when clean
-   Catches what a crawler misses

[See the CSP builder](https://next.centralcsp.com/en/platform/csp-builder/)

### PCI DSS evidence

Auditor-ready 6.4.3 and 11.6.1 evidence for every merchant client.

-   Payment-page script inventory
-   Justification workflow
-   Auditor-ready exports

[See PCI DSS evidence](https://next.centralcsp.com/en/platform/pci-dss/)

### Supply-chain

Know every script your clients ship, and get flagged the moment one gains a CVE.

-   Script SBOM per site
-   Known-CVE detection
-   New-script alerts

[See supply-chain protection](https://next.centralcsp.com/en/platform/supply-chain/)

How it works

## A new client takes five minutes

No agent, no SDK, no code changes on client sites. Browsers report natively.

1.  01 - Add
    
    ### Create the site in your dashboard.
    
    Group sites per client, invite your team, set who sees what.
    
2.  MyEndpoint.report.centralcsp.com
    
    02 - Connect
    
    ### Paste one response header.
    
    Reports start flowing from real visitor browsers immediately. Zero performance impact.
    
3.     
    
    03 - Deliver
    
    ### Route alerts, share the evidence.
    
    Send each client's incidents to the right channel and forward monthly proof that their site is watched.
    

The dashboard

## Everything happens in one place.

Reports, scores, alerts and evidence for every client site, behind one login.

-   Live reports from real visitors
    
-   Every client site in one place
    
-   Alerts routed per client
    
-   Auditor-ready PCI evidence
    

250+

agency sites monitored

1.5B

reports ingested

82.5k

websites analyzed

Full

Reporting-API support

> With our workflow fully integrated, every website is wired to the right team, new scripts are detected automatically and tracked directly in each client's Slack channel. It has streamlined our entire process.

Operations manager, web agency

## Built to be resold

The client-facing layer is included: reports, alerts and exports you can hand straight to your clients.

### Reports your clients actually read

Scores, trends and incidents in plain language. Forward the monthly evidence, keep the retainer conversation short.

[Start now](https://app.next.centralcsp.com)

Monthly client report

### Alerts where each client lives

Slack, Teams, Google Chat, Telegram, email or webhook, routed per client.

### Scans and CVE detection included

Automated scanning and script advisories ship in the Pro plan, not a higher tier.

### API and MCP

Pull anything into your own tooling and reports, or drive it with AI.

FAQ

## Frequently asked questions

Running client-side security for a portfolio, answered.

### How do I monitor CSP across multiple client websites?

Add each site to your CentralCSP dashboard and set one response header per site. Reports from real visitor browsers flow into one portfolio view, grouped per client, with scores, inventories and alerts. No agent or code changes on client sites.

### Can I resell CentralCSP to my clients?

Yes. One subscription covers your portfolio, and you bill security monitoring inside your own care plans at your own price. Most agencies package it as a monthly add-on with the report as the deliverable.

### A client's auditor asked about PCI DSS 6.4.3 and 11.6.1. Can you handle it?

Yes. CentralCSP inventories the scripts on payment pages from real traffic, tracks justification, alerts on tampering, and exports auditor-ready evidence for both requirements.

### How is this different from a free CSP report collector?

A collector stores raw reports for one site. CentralCSP dedupes and classifies them across your whole portfolio, inventories scripts, flags known CVEs, alerts the right client channel and produces evidence you can forward. The difference is the hours you don't spend triaging.

### Where is my clients' data hosted?

In France, on OVH. It never leaves the EU.

## Put your portfolio under watch this afternoon.

Start with one client site, add the rest when you're convinced.

[Start now](https://app.next.centralcsp.com) [Talk to sales](https://next.centralcsp.com/en/contact/?topic=sales)

---

Available in: [en](https://next.centralcsp.com/en/solutions/agencies/), [fr](https://next.centralcsp.com/fr/solutions/agencies/)
