Human Client-side Defense
Visit Website
humansecurity.com
Loading

Human Client-side Defense

Hands-on control of browser scripts with rapid protection and PCI-ready reporting
Rating
Your vote:
No screenshots
Visit Website
humansecurity.com
Loading

Start by mapping what actually runs in your users’ browsers. Connect your site, let the platform crawl key flows (homepage, account, checkout), and it will auto-build a living catalog of every browser-side asset: direct and indirectly loaded JavaScript, tags in iframes, pixels, and the headers shaping behavior. You’ll see where code originates, which pages it touches, what storage it reads or writes (cookies, localStorage), which form fields it inspects, and which external hosts it contacts. Use the baseline view to spot anomalies, set alert thresholds, and subscribe teams to notifications in Slack or email so the right people are looped in when something changes.

When teams ship updates, keep speed and safety in balance. Marketers can propose a new analytics tag or A/B tool by pasting the URL; developers can submit a new widget version from staging. The sandbox previews real runtime behavior without exposing production data—network calls, data access, DOM interactions—so reviewers can approve with confidence. Add just-in-time rules: restrict calls to an allowed list of domains, require Subresource Integrity and nonces, limit cookie access, and tie approvals to owners with expiration dates. Low-risk updates can be auto-approved; anything flagged for unusual access patterns routes to a security queue. Once approved, push the policy live or export matching CSP and other header updates to your CDN or reverse proxy. more

Review summary

Features

  • Automated discovery and continuous catalog of browser-side code
  • Behavior profiling: network calls, form and storage access, DOM interactions
  • Policy engine with domain allowlists, data-access limits, and time-bound approvals
  • Sandbox preview of new or changed scripts before production rollout
  • Header guidance and export (e.g., CSP, SRI) for CDN/reverse proxy deployment
  • Real-time blocking, quarantine, and kill switch
  • Risk scoring, anomaly detection, and baselining
  • Integrations with Slack, Teams, Jira, ServiceNow, and SIEM platforms
  • Audit-ready reporting with ownership, versions, and change history
  • PCI-focused reporting for e-commerce script governance

How It’s Used

  • Protect checkout pages from skimming by blocking reads from card input fields
  • Govern marketing tags: preview behavior, restrict endpoints, and time-limit access
  • Control third-party libraries and shadow dependencies with ownership and approvals
  • SOC workflows: auto-create incidents with context and send normalized events to SIEM
  • Emergency response: quarantine a compromised supplier script without breaking the site
  • Compliance audits: export monthly attestations, integrity proofs, and policy posture
  • Release management: simulate CSP changes and enforce nonces/SRI before go-live
  • Data protection: limit cookie/storage access and flag unexpected PII selectors

Plans & Pricing

Core

Custom

PCI DSS compliance functionality with requirements 6.4.3 and 11.6.1
PCI DSS Req. 6.4.3 and 1.6.1
PCI DSS compliance status dashboard
Payment page script inventory with justification, authorization, integrity assurance, and change alerts
Security-impacting header management and change alerts
PCI DSS audit reports
Automated script authorization policies for PCI DSS
Script Analyzer (deep dive into scripts behavior): Payment page scripts
Integrations with third-party tools (e.g., email, Slack, Jira, Splunk, DataDog, PagerDuty, and API): Outbound-only
Essential Support
Advanced Support: Add-on

Premium

Custom

Includes features of Core plan, plus
Script mitigation and granular blocking: Payment page only
Automated mitigation policies: Payment page scripts
Automated allowlisting of script incidents and actions
Integrations with third-party tools (e.g., email, Slack, Jira, Splunk, DataDog, PagerDuty, and API): Inbound & outbound

Elite

Custom

Includes features of Premium plan, plus
Script mitigation and granular blocking: Entire site
Full client-side script visibility and control
Automated mitigation policies: Entire site
Full site incidents, actions, and risk
Full site script and domain inventory and monitoring
Full site reporting (periodic reports, cookie reports)
Alerting to risky script actions
Script Analyzer (deep dive into scripts behavior): Entire site

Comments

User

Your vote: