Start by mapping what actually runs in your users’ browsers. Connect your site, let the platform crawl key flows (homepage, account, checkout), and it will auto-build a living catalog of every browser-side asset: direct and indirectly loaded JavaScript, tags in iframes, pixels, and the headers shaping behavior. You’ll see where code originates, which pages it touches, what storage it reads or writes (cookies, localStorage), which form fields it inspects, and which external hosts it contacts. Use the baseline view to spot anomalies, set alert thresholds, and subscribe teams to notifications in Slack or email so the right people are looped in when something changes.
When teams ship updates, keep speed and safety in balance. Marketers can propose a new analytics tag or A/B tool by pasting the URL; developers can submit a new widget version from staging. The sandbox previews real runtime behavior without exposing production data—network calls, data access, DOM interactions—so reviewers can approve with confidence. Add just-in-time rules: restrict calls to an allowed list of domains, require Subresource Integrity and nonces, limit cookie access, and tie approvals to owners with expiration dates. Low-risk updates can be auto-approved; anything flagged for unusual access patterns routes to a security queue. Once approved, push the policy live or export matching CSP and other header updates to your CDN or reverse proxy. more
Core
Custom
PCI DSS compliance functionality with requirements 6.4.3 and 11.6.1
PCI DSS Req. 6.4.3 and 1.6.1
PCI DSS compliance status dashboard
Payment page script inventory with justification, authorization, integrity assurance, and change alerts
Security-impacting header management and change alerts
PCI DSS audit reports
Automated script authorization policies for PCI DSS
Script Analyzer (deep dive into scripts behavior): Payment page scripts
Integrations with third-party tools (e.g., email, Slack, Jira, Splunk, DataDog, PagerDuty, and API): Outbound-only
Essential Support
Advanced Support: Add-on
Premium
Custom
Includes features of Core plan, plus
Script mitigation and granular blocking: Payment page only
Automated mitigation policies: Payment page scripts
Automated allowlisting of script incidents and actions
Integrations with third-party tools (e.g., email, Slack, Jira, Splunk, DataDog, PagerDuty, and API): Inbound & outbound
Elite
Custom
Includes features of Premium plan, plus
Script mitigation and granular blocking: Entire site
Full client-side script visibility and control
Automated mitigation policies: Entire site
Full site incidents, actions, and risk
Full site script and domain inventory and monitoring
Full site reporting (periodic reports, cookie reports)
Alerting to risky script actions
Script Analyzer (deep dive into scripts behavior): Entire site
Comments