Start by seeing what actually runs in your users’ browsers. Connect your domains and let the platform map every piece of front-end code across pages, environments, and sessions. You’ll get a living catalog of first-, third-, and deeper-party tags and libraries, with source domains, versions, runtime actions, cookie and storage access, and where each item appears. Use this map to sort critical marketing pixels from opportunistic widgets, spot dormant or duplicate vendors, and baseline normal behavior before you make changes. From there, you can group scripts by business purpose, page type, or region to prepare targeted controls.
Next, turn that visibility into protection with policies you can actually operate. Build allow and deny rules by page, script, domain, method, or event. For example: allow analytics to read page metadata but block keystroke capture; allow form-fill libraries to run on support pages but not on checkout; permit calls to approved APIs while stopping unknown cross-domain posts. Start in observe mode to confirm nothing breaks, then switch to enforce for high-risk routes. If the system detects sensitive-data access or unusual exfiltration patterns, it will alert your team and apply the rule you’ve chosen—block, quarantine, or require approval—without waiting on a deployment. You can also create maintenance windows, break-glass exceptions, and rollback plans so marketers and developers ship safely without delays. more
Core
Custom
PCI DSS compliance functionality with requirements 6.4.3 and 11.6.1
PCI DSS Req. 6.4.3 and 1.6.1
PCI DSS compliance status dashboard
Payment page script inventory with justification, authorization, integrity assurance, and change alerts
Security-impacting header management and change alerts
PCI DSS audit reports
Automated script authorization policies for PCI DSS
Script Analyzer (deep dive into scripts behavior): Payment page scripts
Integrations with third-party tools (e.g., email, Slack, Jira, Splunk, DataDog, PagerDuty, and API): Outbound-only
Essential Support
Advanced Support: Add-on
Premium
Custom
Includes features of Core plan, plus
Script mitigation and granular blocking: Payment page only
Automated mitigation policies: Payment page scripts
Automated allowlisting of script incidents and actions
Integrations with third-party tools (e.g., email, Slack, Jira, Splunk, DataDog, PagerDuty, and API): Inbound & outbound
Elite
Custom
Includes features of Premium plan, plus
Script mitigation and granular blocking: Entire site
Full client-side script visibility and control
Automated mitigation policies: Entire site
Full site incidents, actions, and risk
Full site script and domain inventory and monitoring
Full site reporting (periodic reports, cookie reports)
Alerting to risky script actions
Script Analyzer (deep dive into scripts behavior): Entire site
Comments