New: CentralCSP v2 is out, with full Reporting-API support. Read the changelog

For agencies

Every client site. One security dashboard.

Monitor the scripts, policies and headers of your whole portfolio from one place, and turn client-side security into a service your clients pay for. EU-hosted.

Fifteen sites is fifteen attack surfaces

  • No time to babysit

    You ship sites weekly. Nobody on the team has hours to review raw violation reports per client.

  • Clients want proof

    "Are we secure?" deserves better than a shrug. You need something credible to show, in plain words.

  • PCI landed on your desk

    Your merchant clients forward the auditor's questionnaire to you. 6.4.3 and 11.6.1 are now your job.

For your portfolio

Agency features, built in.

Everything you need to run security for a book of clients, included in one plan.

Your whole portfolio, at a glance

Every client site on one screen: security score, report volume, open advisories. Green means move on. Red means you knew before the client did.

  • Health and score per site
  • CVE flags on client scripts
  • Drill into any site in one click
See portfolio monitoring

Scoped to how agencies work

Access scoped per site, alerts routed per team. Your juniors see the sites they work on, not your whole book.

  • Roles scoped per member and per site
  • Team access without shared logins
  • Alert channels per site
See alert routing

Nothing to install

One response header per client site and reports flow from real visitor browsers.

  • 12 report types, one endpoint
  • Real production traffic
  • Zero performance impact
See how collection works

CSP builder

Build and refine each client's policy from what their traffic actually loads.

  • Generated from real reports
  • Report-only first, enforce when clean
  • Catches what a crawler misses
See the CSP builder

PCI DSS evidence

Auditor-ready 6.4.3 and 11.6.1 evidence for every merchant client.

  • Payment-page script inventory
  • Justification workflow
  • Auditor-ready exports
See PCI DSS evidence

Supply-chain

Know every script your clients ship, and get flagged the moment one gains a CVE.

  • Script SBOM per site
  • Known-CVE detection
  • New-script alerts
See supply-chain protection

How it works

A new client takes five minutes

No agent, no SDK, no code changes on client sites. Browsers report natively.

  1. 01 - Add

    Create the site in your dashboard.

    Add each site, invite your team, set who sees what.

  2. 02 - Connect

    Paste one response header.

    Reports start flowing from real visitor browsers immediately. Zero performance impact.

  3. 03 - Deliver

    Route alerts, share the evidence.

    Send each client's incidents to the right channel and forward monthly proof that their site is watched.

The dashboard

Everything happens in one place.

Reports, scores, alerts and evidence for every client site, behind one login.

  • Every report type
  • Enforced vs report-only
  • Crashes and network errors too
  • Deprecated APIs flagged early
250+
agency sites monitored
1.5B
reports ingested
82.5k
websites analyzed
Full
Reporting-API support

Pricing

One subscription. A line item in every care plan.

Business covers your whole portfolio in one dashboard: automated scanning, API & MCP and alerting are all in the plan. Resell the monitoring to each client at your own rate.

  • Every client site in one dashboard
  • Automated scanning on every site
  • Alerting, API and MCP included
  • EU-hosted client data
Recommended

Business

Automate it and wire it into your stack.

€129.99/ mo
  • Applications10
  • Users25
  • Reports / month2,000,000

Everything in Start, plus:

  • Alerting to six channels
  • Unlimited alerts
  • API & MCP
Get started
With our workflow fully integrated, every website is wired to the right team, new scripts are detected automatically and tracked directly in each client's Slack channel. It has streamlined our entire process.
Operations manager, web agency

Built to be resold

The client-facing layer is included: reports, alerts and exports you can hand straight to your clients.

Each client alerted in their own channel

Add a channel per client, Slack, Teams, Google Chat, Telegram, email or webhook, then choose which events reach it. A new script origin on a checkout page lands with the people who own that site.

Start now
The alerting screen: one delivery channel per client, and rules deciding which events reach which channel.

Evidence you can forward

Payment-page script inventory and PCI DSS exports, ready to hand to the client.

Scans and alerting included

Automated scanning and alerting on six channels ship with Business. CVE detection arrives with Scale.

API and MCP

Pull anything into your own tooling and reports, or drive it with AI.

FAQ

Frequently asked questions

Running client-side security for a portfolio, answered.

Put your portfolio under watch this afternoon.

Start with one client site, add the rest when you're convinced.