Content Security Policy, explained
In-depth guides on building, deploying and monitoring Content Security Policy.
What is CentralCSP?
CentralCSP is a client-side security platform built on the browser Reporting API. Add one response header (no agent, no SDK, no code change) and every visitor’s browser starts reporting what actually runs on your pages: CSP violations, script hashes, network errors, crashes and eight more report types. Plans start at €39.99/month with a 14-day trial.
- Monitoring. One managed endpoint collects all 12 browser report types over Reporting-Endpoints, report-to and the legacy report-uri, deduplicated, grouped by directive and origin, with extension noise flagged and 90-day retention on every plan.
- CSP Builder. Turns the reports real visitors sent from every page into a strict policy, directive by directive, with the evidence behind each source and inline scripts flagged rather than waved through.
- Script inventory and Technologies. A browser-sourced inventory of every script your pages execute, with its hash history. On Scale and up, Technologies identifies the library and version inside each script and flags known CVEs and end-of-life versions.
- Alerting. Sixteen event types (new script origin, hash change, violation spike, new CVE, change on a payment page) delivered to Slack, Microsoft Teams, Google Chat, Telegram, email or signed webhooks, unlimited, from the Business plan.
- PCI DSS v4 evidence. Payment page script inventory, per-script justification, change timeline and CSV or PDF evidence exports for requirements 6.4.3 and 11.6.1, on Scale plans and up.
- API, MCP and free tools. A REST API and a built-in MCP server from Business, so scripts, CI jobs and AI agents can read reports and manage alert rules. Seven free tools without an account: CSP scanner and evaluator, security headers scanner, Reporting API checker, CSP and SRI hash generators, site comparison, plus a local-only Chrome extension.
CentralCSP is a French company. All client and end-user data is stored and processed in France on OVH servers and never leaves the European Union.
Guides
- How do attackers bypass a Content Security Policy?
- How do you test a Content Security Policy in CI and staging?
- Does the Reporting-Endpoints default endpoint receive all violations, or only CSP?
- Best Content Security Policy reporting tool 2026: the eight checks that decide it
- Should you self-host your CSP report collector? Build vs buy in 2026
- How to catch a Magecart-style attack with CSP monitoring
- How to get alerted when your checkout page loads a new script
- CSP nonces vs hashes: which should you use?
- "The Content Security Policy directive upgrade-insecure-requests is ignored when delivered in a report-only policy": what this warning means
- How do you find out if a script on your website has a known CVE?
- How long should you run CSP in report-only mode before enforcing?
- How to move from CSP report-only to enforced without breaking production
- report-uri vs report-to vs Reporting-Endpoints: which CSP reporting setup should you use in 2026?
- How to test a CSP change against a live site without deploying anything
- How to find out why your CSP is blocking a script
Compliance
Comparisons
- What is the best CSP reporting tool in 2026?
- CentralCSP vs Report URI: which CSP monitoring platform should you choose in 2026?
- Which CSP monitoring services send alerts to Slack, Splunk or PagerDuty?
- Which CSP monitoring services are priced for small teams?
- Which service detects when a third-party script changes on your site?
- Which CSP monitoring tools keep your violation data in the EU?
- Which CSP tools let you monitor many websites from one dashboard?
- Report URI alternatives in 2026: 8 CSP monitoring and client-side security tools compared
- Which CSP monitoring service shows you every script on your site without installing an agent?
- Which service turns CSP violation reports into a ready-to-deploy policy?
Fundamentals
- Clickjacking explained: why frame-ancestors is on every security checklist
- How attackers steal cookies and hijack sessions, and the flags that stop them
- How XSS attacks actually work, and what finally stops them
- What is a Content Security Policy (CSP)?
- What is client-side security? The half of your attack surface you don't host
For Security Teams
- CSP for SaaS platforms: security questionnaires, logged-in apps and customer trust
- The best CSP monitoring setup for agencies managing many client sites
- How bank security teams monitor CSP without sending browser data outside the EU
- CSP monitoring for e-commerce: what your checkout actually needs
- CSP for startups: what you need on day one and what can wait
- How to run a solid CSP without a dedicated security engineer
- How a security team keeps third-party scripts under control across every property