New: CentralCSP v2 is out, with full Reporting-API support. Read the changelog

Alerts

Your site changed. Your team already knows.

Add a rule once. When a real visitor's browser reports the change, the message is already in the channel that owns that page.

  • Fires on ingest

    Not a nightly sweep

  • Six destinations

    Chat, email or webhook

  • Routed per site

    And per team

  • No agent

    One response header

Set up your first alert rule takes about ten minutes.

Triggers

What's worth interrupting someone for.

An alert rule is an event a browser reported, a page scope, one or more channels and a cooldown. New origin, script change detected by hash, payment-page tamper detection: the source is always the browser's own report, never a crawler or an injected agent.

  • A new origin appears

    A script loaded from a host you have never seen. Magecart and formjacking skimmers open exactly here: a new host, then a card form quietly reporting to it.

  • A script changed

    A file you execute no longer matches yesterday's hash. Your build did it, or somebody else did.

  • Something touched a payment page

    Card-data pages get their own rules, because PCI DSS 11.6.1 asks you to alert on changes to them.

  • A known CVE turns up

    A library you load has a published advisory. You hear it with the version and the CVE id. See how the script inventory finds them.

  • Reports spike

    Violations jumped after the 4pm deploy. Something broke at scale, and the browsers said so first.

  • A silent signal wakes up

    A directive that reported nothing all quarter started talking. Worth a look before it is worth an incident.

These six are the ones worth interrupting someone for. The full event catalogue is larger: every event a rule can watch, with scope and cooldown.

Channels

This is what an alert looks like.

The same rule, reaching three teams where they already work. Every rule picks its own destination, so a checkout incident and a marketing-site warning never land in the same thread.

  • #payments-security

    Just now

    New origin on your checkout

    A script started loading from a host that has never appeared in your reports.

    Page
    /checkout
    Origin
    cdn.pixel.io
    Browsers
    412
  • Frontend

    2 min ago

    A script you load has changed

    The file no longer matches the hash it had yesterday.

    Script
    widget.min.js
    Hash
    sha384-9Qk2…
    Page
    /product/*
  • security@example.com

    1 h ago

    Known CVE in a script you load

    The library inside it has a published advisory.

    Library
    jquery 3.4.1
    Advisory
    CVE-2020-11023
    Sites
    3

Every destination a rule can reach

  • Slack
  • Microsoft Teams
  • Google Chat
  • Telegram
  • Email
  • Webhooks

Setup

Configured once, then it runs without you

Channels, rules and delivery history live on one screen. Connect a destination, point rules at it, then check afterwards what actually went out.

Every rule reaches the team that owns the page

Add a channel, Slack, Teams, Google Chat, Telegram, email or a webhook, then choose which events reach it. A new origin on checkout goes to the payments team, a broken directive on the blog goes to whoever ships the blog.

Start free trial
The alerting screen: the connected channels on one side, and the rules deciding which events reach which channel.

One message, not four hundred

Reports arrive deduped and grouped, and every rule takes a cooldown, so a bad deploy interrupts someone once.

Delivery history per channel

Every attempt is recorded with its status and the reason it failed, and transient failures are retried. No guessing whether a message went out.

API and MCP

Rules are a REST resource, and the same operations run over the built-in MCP server. Onboarding a hundred sites is a loop.

Further reading

Set up your first rule

Every event a rule can watch, every channel it can reach, and what happens when a delivery fails.

FAQ

Frequently asked questions

Channels, speed, noise and compliance, answered.

Set one rule today. Forget about it until it matters.

Add the header, connect a channel, pick the change worth a message. 14-day free trial, no agent to deploy.