For enterprise
Client-side security that passes the security review.
CentralCSP watches the Content Security Policy, scripts and browser reports of every site you run. EU-hosted, with SSO, RBAC and an audit log. When the questionnaire lands, we answer it with you.

Data residency in the EU
France, on OVH
Annual pentest
Public report
Status page
status.centralcsp.com
Enterprise controls
SSO, RBAC, audit log
The vendor assessment
Your questionnaire, answered before you send it.
These rows are on every security review spreadsheet we have seen. Here is where CentralCSP stands on each one, evidence linked.
| Requirement | Our answer | Status |
|---|---|---|
| Single sign-on | SSO login ships with the Enterprise plan, so your team signs in through your identity provider. Request SSO setup | Answered |
| Role-based access | Scope each member to the sites and permissions they need. Juniors see their projects, not the whole estate. | Answered |
| Audit log | Account activity is logged. Who changed what, and when, stays answerable. | Answered |
| Data residency | Hosted in France, on OVH. Report data never leaves the EU, so there are no transfer clauses to negotiate. | Answered |
| Penetration testing | An independent pentest, every year. We publish the report. Read the 2026 report | Answered |
| Availability | Uptime and incidents are public, and an SLA is available as an Enterprise plan option. status.centralcsp.com | Answered |
| Support | Priority support on the Enterprise plan, answered by the engineers who build the platform. | Answered |
| Scale | The platform already ingests billions of browser reports. Your portfolio will not be what stresses it. | Answered |
| Paperwork | The DPA is public and ready for legal review. Send us the rest and we fill it in with you. Read the DPA | Answered |
Trusted by teams across the world
Integrations
Integrates into the systems you already run.
CentralCSP is not another silo. Reports, scores and evidence flow out over the REST API, webhooks and MCP, straight into the tooling you already run.
- Full REST API with scoped tokens
- Built-in MCP server for AI agents
- Webhooks and CSV exports
Sign in through your identity provider.
SSO login ships with the Enterprise plan and we set it up with you during onboarding. Joiners and leavers are handled where you already manage them, and every sign-in lands in the audit log.
- SSO login on the Enterprise plan
- Set up with you during onboarding
- Sign-ins recorded in the audit log
One workspace. Scoped access.
Invite the whole security and platform team, no shared logins. Each member gets a role that scopes what they can view, configure or enforce, per site.
- Invite your team, no shared logins
- Roles scoped per member and per site
- No all-or-nothing admin access
Every account action, on the record.
Sign-ins, role changes, policy edits: the audit log records who did what, and when. When the review asks how access is controlled, the answer is one screen away.
- Audit log of account activity
- Actor and timestamp on every event
- Evidence for access reviews
Alerts where your teams already work.
Route each site's incidents to the channel that owns it. New script on the checkout? The payments squad's channel pings. No new inbox to watch.
- Alerts to Slack, Teams, Google Chat, Telegram or email
- Webhooks for anything custom
- Channels scoped per site and per team
Compliance paperwork
Send us the questionnaire.
Security questionnaires, DPAs and vendor forms are part of buying software. We treat answering them as part of selling it.
01 - Send
Forward the paperwork.
The questionnaire, the vendor form, your DPA template. Whatever procurement handed you, pass it on.
02 - Answer
We fill it in with you.
Hosting, controls, data handling: we draft the answers, you review, we refine until your security team has what it needs.
03 - Sign
Close the review, start monitoring.
DPA signed, assessment filed. Your team gets back to watching what actually runs in your users' browsers.
Get started now, deploy tomorrow.
An adjusted quote on custom quotas, plus the controls above, enabled for your workspace. Tell us the size of your estate and we come back with numbers.
Talk to sales- Custom quotas, adjusted pricing
- SSO and role-based access
- Audit log
- Optional SLA
- Priority support
- Data residency in the EU
FAQ
Frequently asked questions
What security reviews ask us most, answered.
Start the review with the answers in hand.
Talk to sales for an adjusted quote, the DPA and the pentest report. Pilot on one site while procurement runs its process.
