# CentralCSP > Client-side security monitoring: see what runs in your users' browsers, catch threats in real time, and turn visibility into protection. ## Full content - [llms-full.txt](https://centralcsp.com/llms-full.txt): full Markdown of every English page. ## English > Client-side security monitoring: see what runs in your users' browsers, catch threats in real time, and turn visibility into protection. - [Client-side security & CSP monitoring - CentralCSP](https://centralcsp.com/en/): Monitor Content Security Policy and every client-side threat from real browser traffic. One header, no agent, EU-hosted. Start a free 14-day trial. ([Markdown](https://centralcsp.com/en.md)) - [About CentralCSP - the client-side security team](https://centralcsp.com/en/about/): Two cybersecurity engineers making the client side secure, from a first CSP scanner to a platform ingesting billions of browser reports. Meet CentralCSP. ([Markdown](https://centralcsp.com/en/about.md)) - [Contact CentralCSP - talk to sales or book a demo](https://centralcsp.com/en/contact/): Talk to CentralCSP sales, book a client-side security demo, or reach support. EU-hosted in France on OVH, we usually reply within 24 hours. ([Markdown](https://centralcsp.com/en/contact.md)) - [Data Processing Agreement - CentralCSP](https://centralcsp.com/en/legal/dpa/): The data processing agreement covering how CentralCSP, the EU-hosted client-side security platform, processes personal data on your behalf. ([Markdown](https://centralcsp.com/en/legal/dpa.md)) - [Legal Notice - CentralCSP](https://centralcsp.com/en/legal/mentions-legales/): Statutory publisher, hosting, and mediation information for centralcsp.com and the CentralCSP service. ([Markdown](https://centralcsp.com/en/legal/mentions-legales.md)) - [Privacy Policy - CentralCSP](https://centralcsp.com/en/legal/privacy/): How CentralCSP, the EU-hosted client-side security platform, collects, uses, and protects your personal data. ([Markdown](https://centralcsp.com/en/legal/privacy.md)) - [Terms of Service - CentralCSP](https://centralcsp.com/en/legal/terms/): The terms governing your use of CentralCSP, the EU-hosted client-side security platform. ([Markdown](https://centralcsp.com/en/legal/terms.md)) - [CSP violation & script change alerts in Slack, Teams](https://centralcsp.com/en/platform/alerting/): CSP and script-change alerts in Slack, Teams, Telegram, email or a signed webhook, the moment a report lands. Detection and alerting for PCI DSS 11.6.1. ([Markdown](https://centralcsp.com/en/platform/alerting.md)) - [CSP API and MCP server for AI agents and CI/CD](https://centralcsp.com/en/platform/api-mcp/): Read CSP violations, script inventories and metrics over a REST API, gate deploys from CI, or connect Claude Code and Cursor to the built-in MCP server. ([Markdown](https://centralcsp.com/en/platform/api-mcp.md)) - [CSP generator: build a strict policy from real traffic](https://centralcsp.com/en/platform/csp-builder/): Build a strict Content Security Policy from real browser reports, not a one-page crawl. Prune extension noise, then move from report-only to enforced safely. ([Markdown](https://centralcsp.com/en/platform/csp-builder.md)) - [CSP violation monitoring and 12 browser report types](https://centralcsp.com/en/platform/monitoring/): One endpoint collects all 12 browser report types: CSP violations, script hashes, NEL, crashes. Deduped, classified, EU-hosted. ([Markdown](https://centralcsp.com/en/platform/monitoring.md)) - [PCI DSS 6.4.3 & 11.6.1: payment page script inventory](https://centralcsp.com/en/platform/pci-dss/): Inventory every payment page script from real browser traffic, justify each one, alert on change, and export QSA evidence for 6.4.3 and 11.6.1. No agent. ([Markdown](https://centralcsp.com/en/platform/pci-dss.md)) - [Client-side supply chain & Magecart script monitoring](https://centralcsp.com/en/platform/supply-chain/): Magecart and supply-chain protection: inventory every script real browsers run, its version and CVEs, and get alerted when one changes. No agent, no proxy. ([Markdown](https://centralcsp.com/en/platform/supply-chain.md)) - [CentralCSP pricing - client-side security plans](https://centralcsp.com/en/pricing/): Compare CentralCSP plans for client-side security and CSP monitoring. Every paid plan is EU-hosted with all browser report types. 14-day free trial. ([Markdown](https://centralcsp.com/en/pricing.md)) - [Monitor every client site from one dashboard, for agencies](https://centralcsp.com/en/solutions/agencies/): One dashboard for your whole client portfolio, with no agent to install on their sites. Portfolio pricing, white-label reports, resell it in your care plans. ([Markdown](https://centralcsp.com/en/solutions/agencies.md)) - [CSP reporting without an SDK, for developers](https://centralcsp.com/en/solutions/developers/): Add one response header, no SDK and no agent, then debug violations with source-level context: the file, the line and the script that actually tripped them. ([Markdown](https://centralcsp.com/en/solutions/developers.md)) - [Pass the vendor security assessment: EU-hosted, SSO, RBAC](https://centralcsp.com/en/solutions/enterprise/): We answer your vendor questionnaire with you: data residency in France, SSO, RBAC and an audit log, with the evidence linked for your review. ([Markdown](https://centralcsp.com/en/solutions/enterprise.md)) - [State of the Web 2026: client-side security report | CentralCSP](https://centralcsp.com/en/state-of-the-web/): An anonymized census of client-side security across 761,345 domains: configuration quality averages 96.6 out of 100, security 29.2, and what to fix first. ([Markdown](https://centralcsp.com/en/state-of-the-web.md)) - [Website security score - free benchmark vs 500,000+ sites](https://centralcsp.com/en/tools/compare/): Scan any domain for free and score its CSP, security headers and attack resistance out of 100 against the best-configured sites and 500,000+ others. ([Markdown](https://centralcsp.com/en/tools/compare.md)) - [Free CSP evaluator & validator - grade your policy](https://centralcsp.com/en/tools/csp-evaluator/): Paste a Content-Security-Policy and get a 0-100 grade: every directive checked, unsafe-inline, wildcards and JSONP bypasses flagged, fixes ranked by severity. ([Markdown](https://centralcsp.com/en/tools/csp-evaluator.md)) - [Free CSP hash generator - inline script & style SHA-256](https://centralcsp.com/en/tools/csp-hash/): Paste an inline script or style, get its SHA-256, 384 or 512 CSP hash and a ready-to-paste script-src line. Drop unsafe-inline. Nothing leaves your browser. ([Markdown](https://centralcsp.com/en/tools/csp-hash.md)) - [CSP scanner - free Content Security Policy checker by URL](https://centralcsp.com/en/tools/csp-scanner/): Free CSP scanner: enter a URL, see the Content-Security-Policy it sends, scored 0 to 100, with a fix for every unsafe-inline, wildcard and gap. No signup. ([Markdown](https://centralcsp.com/en/tools/csp-scanner.md)) - [Free CSP Chrome extension: build & test, no deploy](https://centralcsp.com/en/tools/extension/): Free Chrome extension: stream live CSP violations, swap in a policy in Report-Only or Enforce, and build a strict header against real pages. No deploy. ([Markdown](https://centralcsp.com/en/tools/extension.md)) - [Reporting API checker - free Reporting-Endpoints test](https://centralcsp.com/en/tools/reporting-api/): Free Reporting API checker: scan any URL's Reporting-Endpoints, Report-To, CSP report-uri and NEL, and find the reports browsers silently drop. No signup. ([Markdown](https://centralcsp.com/en/tools/reporting-api.md)) - [Free HTTP security headers checker & fixes](https://centralcsp.com/en/tools/security-headers/): Scan any URL's HTTP security headers free: CSP, HSTS, X-Frame-Options, Permissions-Policy, cookies. Get a score out of 100 and a fix per finding. No signup. ([Markdown](https://centralcsp.com/en/tools/security-headers.md)) - [SRI hash generator - free Subresource Integrity tool](https://centralcsp.com/en/tools/sri-hash/): Paste a CDN script or stylesheet URL and get its Subresource Integrity hash: SHA-256, 384 or 512, a ready-to-paste tag, and a CORS check. Free, no signup. ([Markdown](https://centralcsp.com/en/tools/sri-hash.md)) - [Documentation](https://centralcsp.com/en/docs/llms.txt): every documentation page, indexed separately. - [Blog](https://centralcsp.com/en/blog/llms.txt): every blog post, indexed separately. ## Français > Surveillance de la sécurité côté client : visualisez ce qui s'exécute dans les navigateurs de vos utilisateurs, détectez les menaces en temps réel et transformez cette visibilité en protection. - [Sécurité côté client et surveillance CSP - CentralCSP](https://centralcsp.com/fr/): Surveillez votre Content Security Policy et les menaces côté client depuis le trafic réel des navigateurs. Un en-tête, sans agent, hébergé en France. ([Markdown](https://centralcsp.com/fr.md)) - [À propos de CentralCSP - sécurité côté client](https://centralcsp.com/fr/about/): Deux ingénieurs cybersécurité qui sécurisent le côté client, d'un premier scanner CSP à une plateforme traitant des milliards de rapports. ([Markdown](https://centralcsp.com/fr/about.md)) - [Contacter CentralCSP - ventes, démo ou support technique](https://centralcsp.com/fr/contact/): Contactez l'équipe CentralCSP : ventes, démo de sécurité côté client ou support. Hébergé en France chez OVH, réponse généralement sous 24 heures. ([Markdown](https://centralcsp.com/fr/contact.md)) - [Accord de traitement des données - CentralCSP](https://centralcsp.com/fr/legal/dpa/): L'accord de traitement des données de CentralCSP : comment la plateforme de sécurité côté client hébergée dans l'UE traite vos données personnelles. ([Markdown](https://centralcsp.com/fr/legal/dpa.md)) - [Mentions légales - CentralCSP](https://centralcsp.com/fr/legal/mentions-legales/): Informations légales sur l'éditeur, l'hébergeur et la médiation pour centralcsp.com et le service CentralCSP. ([Markdown](https://centralcsp.com/fr/legal/mentions-legales.md)) - [Politique de confidentialité - CentralCSP](https://centralcsp.com/fr/legal/privacy/): Comment CentralCSP, la plateforme de sécurité côté client hébergée dans l'UE, collecte, utilise et protège vos données personnelles. ([Markdown](https://centralcsp.com/fr/legal/privacy.md)) - [Conditions d'utilisation - CentralCSP](https://centralcsp.com/fr/legal/terms/): Les conditions régissant votre utilisation de CentralCSP, la plateforme de sécurité côté client hébergée dans l'UE. ([Markdown](https://centralcsp.com/fr/legal/terms.md)) - [Alertes CSP et changement de script dans Slack ou Teams](https://centralcsp.com/fr/platform/alerting/): Alertes CSP et changement de script dans Slack, Teams, Telegram, e-mail ou webhook signé, dès l'arrivée du rapport. Détection et alerte PCI DSS 11.6.1. ([Markdown](https://centralcsp.com/fr/platform/alerting.md)) - [API CSP et serveur MCP pour vos agents IA et CI/CD](https://centralcsp.com/fr/platform/api-mcp/): Lisez les violations CSP, l'inventaire de scripts et les métriques via l'API REST, bloquez un déploiement en CI ou branchez Claude Code au serveur MCP. ([Markdown](https://centralcsp.com/fr/platform/api-mcp.md)) - [Générateur de CSP stricte à partir des rapports navigateur](https://centralcsp.com/fr/platform/csp-builder/): Générez une Content Security Policy stricte à partir des rapports des navigateurs, pas d'un crawl. Écartez le bruit, puis passez du report-only au blocage. ([Markdown](https://centralcsp.com/fr/platform/csp-builder.md)) - [Surveillance des violations CSP et rapports navigateur](https://centralcsp.com/fr/platform/monitoring/): Un seul endpoint collecte les 12 types de rapports navigateur : violations CSP, hash de scripts, NEL, crashs. Dédupliqués et hébergés en France. ([Markdown](https://centralcsp.com/fr/platform/monitoring.md)) - [Scripts de paiement : inventaire PCI DSS 6.4.3 et 11.6.1](https://centralcsp.com/fr/platform/pci-dss/): Inventoriez chaque script de vos pages de paiement depuis le trafic réel, justifiez-le, soyez alerté des changements, exportez les preuves QSA. Sans agent. ([Markdown](https://centralcsp.com/fr/platform/pci-dss.md)) - [Surveillance des scripts tiers et protection Magecart](https://centralcsp.com/fr/platform/supply-chain/): Magecart et supply chain côté client : inventoriez chaque script exécuté par vos visiteurs, sa version et ses CVE, alerte au moindre changement. Sans agent. ([Markdown](https://centralcsp.com/fr/platform/supply-chain.md)) - [Tarifs CentralCSP - sécurité côté client](https://centralcsp.com/fr/pricing/): Comparez les offres CentralCSP de sécurité côté client et de surveillance CSP. Chaque offre payante est hébergée en France. Essai gratuit de 14 jours. ([Markdown](https://centralcsp.com/fr/pricing.md)) - [Tous vos sites clients dans un seul tableau de bord](https://centralcsp.com/fr/solutions/agencies/): Un seul tableau de bord pour tout votre portefeuille clients, sans agent à installer. Tarif au portefeuille, rapports en marque blanche, à revendre. ([Markdown](https://centralcsp.com/fr/solutions/agencies.md)) - [Rapports CSP sans SDK, pour les développeurs](https://centralcsp.com/fr/solutions/developers/): Ajoutez un en-tête de réponse, sans SDK ni agent, puis déboguez les violations avec le contexte source : le fichier, la ligne et le script en cause. ([Markdown](https://centralcsp.com/fr/solutions/developers.md)) - [Évaluation fournisseur : hébergement France, SSO, RBAC](https://centralcsp.com/fr/solutions/enterprise/): Questionnaire fournisseur rempli avec vous : données hébergées en France, SSO, RBAC et journal d'audit, preuves à l'appui pour votre dossier. ([Markdown](https://centralcsp.com/fr/solutions/enterprise.md)) - [État du Web 2026 : rapport sur la sécurité côté client | CentralCSP](https://centralcsp.com/fr/state-of-the-web/): Un recensement anonymisé de la sécurité côté client sur 761 345 domaines : qualité de configuration 96,6 sur 100, sécurité 29,2, et quoi corriger d'abord. ([Markdown](https://centralcsp.com/fr/state-of-the-web.md)) - [Score de sécurité d'un site web - comparatif gratuit](https://centralcsp.com/fr/tools/compare/): Scannez un domaine gratuitement : CSP, en-têtes de sécurité et résistance aux attaques notés sur 100, face aux sites les mieux configurés et à 500 000 autres. ([Markdown](https://centralcsp.com/fr/tools/compare.md)) - [Évaluateur CSP gratuit - vérifiez et notez votre politique](https://centralcsp.com/fr/tools/csp-evaluator/): Collez votre Content-Security-Policy et obtenez une note sur 100 : unsafe-inline, jokers et contournements JSONP signalés, correctifs priorisés. ([Markdown](https://centralcsp.com/fr/tools/csp-evaluator.md)) - [Générateur de hash CSP gratuit : script et style inline](https://centralcsp.com/fr/tools/csp-hash/): Collez un script ou style inline, obtenez son hash CSP SHA-256, 384 ou 512 et la ligne script-src à coller. Supprimez unsafe-inline. Calcul 100 % local. ([Markdown](https://centralcsp.com/fr/tools/csp-hash.md)) - [Scanner CSP gratuit - analyser la Content-Security-Policy](https://centralcsp.com/fr/tools/csp-scanner/): Scanner CSP gratuit : entrez une URL, voyez la Content-Security-Policy réellement envoyée, notée sur 100, avec un correctif par unsafe-inline ou wildcard. ([Markdown](https://centralcsp.com/fr/tools/csp-scanner.md)) - [Extension Chrome CSP gratuite : testez sans déployer](https://centralcsp.com/fr/tools/extension/): Extension Chrome gratuite : suivez les violations CSP en direct, testez une politique en Report-Only ou bloquante, générez un en-tête strict. Sans déploiement. ([Markdown](https://centralcsp.com/fr/tools/extension.md)) - [Vérificateur Reporting API gratuit - Reporting-Endpoints](https://centralcsp.com/fr/tools/reporting-api/): Vérificateur Reporting API gratuit : Reporting-Endpoints, Report-To, report-uri et NEL d'une URL, et les rapports que le navigateur abandonne en silence. ([Markdown](https://centralcsp.com/fr/tools/reporting-api.md)) - [Vérificateur d'en-têtes de sécurité HTTP - test gratuit](https://centralcsp.com/fr/tools/security-headers/): Testez les en-têtes de sécurité HTTP d'un site : CSP, HSTS, X-Frame-Options, Permissions-Policy, cookies. Score sur 100 et correctif par constat. Gratuit. ([Markdown](https://centralcsp.com/fr/tools/security-headers.md)) - [Générateur de hash SRI gratuit - Subresource Integrity](https://centralcsp.com/fr/tools/sri-hash/): Collez l'URL d'un script ou d'une feuille de style servie par un CDN : hash SRI SHA-256, 384 ou 512, balise prête à coller et vérification CORS. Gratuit. ([Markdown](https://centralcsp.com/fr/tools/sri-hash.md)) - [Documentation](https://centralcsp.com/fr/docs/llms.txt): toutes les pages de documentation, indexées séparément. - [Blog](https://centralcsp.com/fr/blog/llms.txt): tous les articles du blog, indexés séparément.