New: export PCI DSS v4 evidence from real browser traffic.

For agencies

Every client site. One security dashboard.

Monitor the scripts, policies and headers of your whole portfolio from one place, and turn client-side security into a service your clients pay for. EU-hosted.

Fifteen sites is fifteen attack surfaces

  • No time to babysit

    You ship sites weekly. Nobody on the team has hours to review raw violation reports per client.

  • Clients want proof

    "Are we secure?" deserves better than a shrug. You need something credible to show, in plain words.

  • PCI landed on your desk

    Your merchant clients forward the auditor's questionnaire to you. 6.4.3 and 11.6.1 are now your job.

For your portfolio

Agency features, built in.

Everything you need to run security for a book of clients, included in one plan.

Your whole portfolio, at a glance

Every client site on one screen: security score, report volume, open advisories. Green means move on. Red means you knew before the client did.

  • Health and score per site
  • CVE flags on client scripts
  • Drill into any site in one click
See portfolio monitoring

Scoped to how agencies work

Sites grouped per client, access scoped per project, alerts routed per team. Your juniors see their clients, not your whole book.

  • Per-client groups
  • Team access per project
  • Alert channels per client
See alert routing

Nothing to install

One response header per client site and reports flow from real visitor browsers.

  • 12 report types, one header
  • Real production traffic
  • Zero performance impact
See how collection works

CSP builder

Build and refine each client's policy from what their traffic actually loads.

  • Generated from real reports
  • Report-only first, enforce when clean
  • Catches what a crawler misses
See the CSP builder

PCI DSS evidence

Auditor-ready 6.4.3 and 11.6.1 evidence for every merchant client.

  • Payment-page script inventory
  • Justification workflow
  • Auditor-ready exports
See PCI DSS evidence

Supply-chain

Know every script your clients ship, and get flagged the moment one gains a CVE.

  • Script SBOM per site
  • Known-CVE detection
  • New-script alerts
See supply-chain protection

How it works

A new client takes five minutes

No agent, no SDK, no code changes on client sites. Browsers report natively.

  1. 01 - Add

    Create the site in your dashboard.

    Group sites per client, invite your team, set who sees what.

  2. 02 - Connect

    Paste one response header.

    Reports start flowing from real visitor browsers immediately. Zero performance impact.

  3. 03 - Deliver

    Route alerts, share the evidence.

    Send each client's incidents to the right channel and forward monthly proof that their site is watched.

The dashboard

Everything happens in one place.

Reports, scores, alerts and evidence for every client site, behind one login.

  • Live reports from real visitors
  • Every client site in one place
  • Alerts routed per client
  • Auditor-ready PCI evidence
250+
agency sites monitored
1.5B
reports ingested
82.5k
websites analyzed
Full
Reporting-API support
With our workflow fully integrated, every website is wired to the right team, new scripts are detected automatically and tracked directly in each client's Slack channel. It has streamlined our entire process.
Operations manager, web agency

Built to be resold

The client-facing layer is included: reports, alerts and exports you can hand straight to your clients.

Reports your clients actually read

Scores, trends and incidents in plain language. Forward the monthly evidence, keep the retainer conversation short.

Start now
Monthly client report

Alerts where each client lives

Slack, Teams, Google Chat, Telegram, email or webhook, routed per client.

Scans and CVE detection included

Automated scanning and script advisories ship in the Pro plan, not a higher tier.

API and MCP

Pull anything into your own tooling and reports, or drive it with AI.

FAQ

Frequently asked questions

Running client-side security for a portfolio, answered.

Put your portfolio under watch this afternoon.

Start with one client site, add the rest when you're convinced.