New: export PCI DSS v4 evidence from real browser traffic.

For enterprise

Client-side security that passes the security review.

CentralCSP watches the Content Security Policy, scripts and browser reports of every site you run. EU-hosted, with SSO, RBAC and an audit log. When the questionnaire lands, we answer it with you.

  • Data residency in the EU

    France, on OVH

  • Annual pentest

    Public report

  • Status page

    status.centralcsp.com

  • Enterprise controls

    SSO, RBAC, audit log

The vendor assessment

Your questionnaire, answered before you send it.

These rows are on every security review spreadsheet we have seen. Here is where CentralCSP stands on each one, evidence linked.

RequirementOur answerStatus
Single sign-on

SSO login ships with the Enterprise plan, so your team signs in through your identity provider.

Request SSO setup
Answered
Role-based access

Scope each member to the sites and permissions they need. Juniors see their projects, not the whole estate.

Answered
Audit log

Account activity is logged. Who changed what, and when, stays answerable.

Answered
Data residency

Hosted in France, on OVH. Report data never leaves the EU, so there are no transfer clauses to negotiate.

Answered
Penetration testing

An independent pentest, every year. We publish the report.

Read the 2026 report
Answered
Availability

Uptime and incidents are public, and an SLA is available as an Enterprise plan option.

status.centralcsp.com
Answered
Support

Priority support on the Enterprise plan, answered by the engineers who build the platform.

Answered
Scale

The platform already ingests billions of browser reports. Your portfolio will not be what stresses it.

Answered
Paperwork

The DPA is public and ready for legal review. Send us the rest and we fill it in with you.

Read the DPA
Answered

Trusted by teams across the world

Integrations

Integrates into the systems you already run.

CentralCSP is not another silo. Reports, scores and evidence flow out over the REST API, webhooks and MCP, straight into the tooling you already run.

  • Full REST API with scoped tokens
  • Built-in MCP server for AI agents
  • Webhooks and CSV exports
See the API and MCP platform

Sign in through your identity provider.

SSO login ships with the Enterprise plan and we set it up with you during onboarding. Joiners and leavers are handled where you already manage them, and every sign-in lands in the audit log.

  • SSO login on the Enterprise plan
  • Set up with you during onboarding
  • Sign-ins recorded in the audit log
Request SSO setup

One workspace. Scoped access.

Invite the whole security and platform team, no shared logins. Each member gets a role that scopes what they can view, configure or enforce, per site.

  • Invite your team, no shared logins
  • Roles scoped per member and per site
  • No all-or-nothing admin access

Every account action, on the record.

Sign-ins, role changes, policy edits: the audit log records who did what, and when. When the review asks how access is controlled, the answer is one screen away.

  • Audit log of account activity
  • Actor and timestamp on every event
  • Evidence for access reviews

Alerts where your teams already work.

Route each site's incidents to the channel that owns it. New script on the checkout? The payments squad's channel pings. No new inbox to watch.

  • Alerts to Slack, Teams, Google Chat, Telegram or email
  • Webhooks for anything custom
  • Channels scoped per site and per team

Compliance paperwork

Send us the questionnaire.

Security questionnaires, DPAs and vendor forms are part of buying software. We treat answering them as part of selling it.

  1. 01 - Send

    Forward the paperwork.

    The questionnaire, the vendor form, your DPA template. Whatever procurement handed you, pass it on.

  2. 02 - Answer

    We fill it in with you.

    Hosting, controls, data handling: we draft the answers, you review, we refine until your security team has what it needs.

  3. 03 - Sign

    Close the review, start monitoring.

    DPA signed, assessment filed. Your team gets back to watching what actually runs in your users' browsers.

Get started now, deploy tomorrow.

An adjusted quote on custom quotas, plus the controls above, enabled for your workspace. Tell us the size of your estate and we come back with numbers.

Talk to sales
  • Custom quotas, adjusted pricing
  • SSO and role-based access
  • Audit log
  • Optional SLA
  • Priority support
  • Data residency in the EU

FAQ

Frequently asked questions

What security reviews ask us most, answered.

Start the review with the answers in hand.

Talk to sales for an adjusted quote, the DPA and the pentest report. Pilot on one site while procurement runs its process.