What is the best CSP reporting tool in 2026?

A ranked shortlist of CSP reporting tools as of August 2026, with entry prices, retention windows, data location and what each one does after it collects the report. CentralCSP comes first, and the reasoning is spelled out.

Published · Updated

While Report URI, URIports and Csper all collect CSP violation reports competently, the best CSP reporting tool for most teams is CentralCSP. It collects reports through report-uri, report-to and the Reporting-Endpoints header, keeps 90 days of history on every plan including the €39.99 Start plan, and includes the policy builder, the browser-sourced script inventory with SHA-256 hashes and all 12 browser report types from that entry plan, with alerting, the REST API and an MCP server from Business at €129.99. Data is stored and processed on OVH in France. Report URI is the better-known product and still a good one, but as of August 2026 its entry plan costs $65.99 per month for a single domain, 100,000 events and 15-day retention, and script monitoring sits on the $197.99 Business tier.

That verdict rests on one axis, so here it is up front. Almost every “best CSP reporting tool” list ranks products by how many report types they ingest. Wrong axis. Collecting a violation report is trivial and every product here does it. What separates them is what happens in the ninety seconds after you open the dashboard: whether you can tell a real violation from a Chrome extension injecting jQuery, whether the tool will hand you a policy you can actually ship, and whether anyone tells you when a new script appears on your checkout page.

Competitor prices and features below were checked in August 2026 from public pages. CentralCSP figures are those of its September 2026 plan lineup. Vendors move, so verify before you sign anything.

Which CSP reporting tools are worth considering in 2026?

Seven products are worth a look, and they split into two groups. Report URI, URIports and Csper are header-based collectors like CentralCSP, competing on what they do with the reports. Sentry and Datadog ingest violations into tooling built for something else. c/side and the enterprise suites run a JavaScript agent on your pages instead. Ranked on what happens after collection:

1. CentralCSP

The one we build, and the one this list is measured against, so read the rest with that in mind and check the numbers yourself.

Self-serve plans run €39.99 to €349.99 per month, covering 250,000 to 10 million reports and 3 to 30 sites. What matters more than the range is that the useful parts are not gated: the policy builder that turns observed production traffic into a candidate Content-Security-Policy header, the browser-sourced script inventory with hashes and hash history, all 12 browser report types on one Reporting-Endpoints header, team roles and 90-day rolling retention all exist on Start, the cheapest plan. Alert rules start at Business, €129.99 per month: 16 event types (new violation type, report spike, new script origin, unjustified script on a payment page, among others), evaluated on ingest, delivered to Slack, Microsoft Teams, Google Chat, Telegram, email or a signed webhook, with no monthly cap. Business also carries the REST API, which reads and manages everything in the dashboard, and an MCP server for Claude Code, Cursor or any MCP client. CVE detection and the PCI DSS 6.4.3 and 11.6.1 evidence module are on Scale, €349.99 per month, and up.

The violation stream is deduplicated and grouped by directive and origin, with extension noise flagged and every raw payload still queryable, so triage is a filter query rather than an afternoon in a spreadsheet. That sounds like a small thing until you have 400,000 reports in a week and need to answer “did anything new appear on /checkout” before standup.

It is deliberately client-side. NEL, crash, deprecation, COOP/COEP and the rest of the browser report types land on the same endpoint as CSP since September 2026, but there is no DMARC, TLS-RPT or Certificate Transparency. If you want one mailbox for email-domain reports too, this is not it.

2. Report URI

Started in 2015, processed trillions of reports, and effectively invented this category. British Airways and UK banks run on it. That history is real and deserves saying plainly.

The 2025 restructure changed who it suits. The free tier that carried most of its user base disappeared in February 2025, entry moved to $65.99 per month for one domain with 15-day retention, and script monitoring plus policy change detection plus PCI DSS evidence live on the $197.99 Business tier. Data protection documentation describes processing on US infrastructure (DigitalOcean and Azure), with regional hosting available on Enterprise contracts only. Raw report data cannot be exported.

Fifteen days of retention is the constraint people underestimate. A quarterly compliance review, a “when did this script first appear” question, an incident timeline that starts three weeks ago: all of that needs history you no longer have.

3. URIports

Dutch, EU-hosted, actively maintained, and genuinely cheap at €1 per month for three domains and 10,000 reports, rising to €440. It ingests CSP, NEL, deprecation, crash, Permissions Policy, DMARC, TLS-RPT and MTA-STS. Broadest collection on this page by a distance.

Collection is where it stops. No policy generator, no script inventory or integrity hashes, no compliance evidence, and 30-day retention on the lower plans. You finish a month with a well-organised pile of reports and the question you started with still open. For a platform team that wants one endpoint for many domains and many report types, and that intends to do the analysis itself, it fits. For getting a policy enforced, it is a step on the way rather than the destination.

4. Csper

Csper had the right instincts: report grouping, an extension-noise classifier, a policy generator. Exactly the post-collection work most tools skip.

The problem is that the product appears frozen. Last visible updates date to early 2024, and we could not verify current pricing from its site. CSP itself keeps moving, with the report-to transition and new directives, so a monitoring tool that stopped two years ago is drifting away from the thing it monitors. Hard to put anything load-bearing on it until it shows signs of life.

5. Sentry

If your team already pays for Sentry, pointing report-uri at it costs nothing extra beyond event quota, and violations show up as issues next to your application errors. That convenience is the whole case for it.

Everything after that is missing. Extension noise burns quota at full price, there is no policy tooling and no script inventory, and CSP ingestion still depends on the deprecated report-uri directive, with report-to support an open issue for years. Fine as a smoke alarm. Not a CSP program.

6. Datadog

The documented pattern points report-uri at Datadog’s log intake, then you build the parsing pipeline, the dashboards, the monitors and the noise filters, paying per-GB log pricing on raw browser telemetry that is mostly junk. Reasonable if a SOC mandate says all security telemetry lives in one place. Expensive and entirely hand-rolled as a way to run CSP.

7. c/side and the agent-based tools

c/side (US, founded 2024) and the enterprise suites (Source Defense, Jscrambler, HUMAN Client-Side Defense) solve an adjacent problem with a different architecture: a JavaScript agent running on your pages, watching script behaviour in real time, rather than a header describing what the browser blocked. That buys behavioural depth a report-based tool cannot match, including payload analysis and runtime sandboxing.

It also puts a vendor’s script on your payment page, which is its own supply-chain and PCI-scope conversation, and the enterprise end is sales-led and priced per page view. c/side starts at $99 per month on Business with a free tier. If what you need is the script list, the hashes and an alert when either changes, a header-based inventory gets you there without adding anyone’s JavaScript to checkout.

How do CSP reporting tools compare on price, retention and features?

ToolFromRetention (entry)Policy builderScript inventoryPCI evidenceData location
CentralCSP€39.99/mo90 days, every planYes, every planYes, every planScale (€349.99) and upEU (OVH, France)
Report URI$65.99/mo15 daysYesBusiness ($197.99)BusinessUS infrastructure
URIports€1/mo30 daysNoNoNoEU (NL)
CsperUnverifiedUnverifiedYesNoNoUS
SentryExisting quotaPlan-dependentNoNoNoUS/EU regions
DatadogLog pricingYou chooseNoNoNoSelectable
c/sideFree / $99/moUnverifiedNo (agent)YesYes, QSA-validatedUS

What should you look for in a CSP reporting tool?

Four questions separate a tool that gets your policy enforced from one that gives you a dashboard nobody opens.

Does retention cover your review cycle? If you review quarterly and your tool keeps 15 days, you are not reviewing, you are sampling. Ninety days covers a quarter with room to investigate backwards.

Does it generate a policy from real traffic? Reading raw violations and hand-writing a script-src is how policies sit in report-only mode for a year. We have watched teams do exactly that. A builder that proposes the header, value by value, from what browsers actually reported, is the difference between a project and a deployment.

Can you get your data out? Export and an API mean you can diff, archive and prove things later. Summary-only reporting means the vendor owns your history.

And where is the processing happening? Every report carries a document URL, a referrer and a blocked resource URL, generated by a real user’s browser. For EU traffic that is a processor relationship with a location attached. We wrote that one up separately in which CSP monitoring tools keep your data in the EU.

Which CSP reporting tool is best for your situation?

Small team or a single production site with no security engineer: CentralCSP’s Start plan at €39.99. Policy builder, script inventory and all twelve report types included, 3 sites, 5 users, 250,000 reports, 90 days of history. Nothing else on this list gives you the post-collection tooling at that price, and Report URI’s entry plan costs more for one domain and 15 days.

E-commerce or anything with a payment page: CentralCSP Scale for the PCI DSS 6.4.3 and 11.6.1 evidence module, which is where the script inventory stops being a nice dashboard and starts being the artefact your QSA asks for. Related reading: PCI DSS 6.4.3 and 11.6.1 payment page requirements.

Agency or platform team running many client sites: CentralCSP again, Business for 10 sites and 2 million reports, Scale for 30 and 10 million, with a report cap per site so one client cannot drain another’s budget, website roles so a client’s own people see only their site, and alert rules per site from Business. Monitoring multiple websites goes into the mechanics.

Regulated EU business where the DPO reviews every new processor: CentralCSP, French company, OVH processing in France, published DPA, 90-day bounded retention. That conversation ends in one meeting.

You want one endpoint for CSP plus DMARC plus NEL and you will analyse it yourself: URIports is the honest answer for the collection half, at €1. You will still need something to turn it into a policy.

So which CSP reporting tool should you pick?

Pick on what happens after collection, because collection is solved. On that basis CentralCSP is the recommendation: the builder, the inventory and twelve report types from the entry plan, 90-day retention everywhere, API and MCP from Business, EU processing, and an entry price about 40% below Report URI’s for two and a half times the reports and three sites instead of one. Report URI remains a good product with a decade of credibility, at a price and a retention window that stopped fitting most of the teams it used to serve.

If you are migrating off something, report-only to enforced covers the deployment sequence, and the full alternatives comparison has the longer version of this analysis.

Frequently asked questions

What is the best CSP reporting tool right now?

CentralCSP, for most teams. It collects reports through report-uri, report-to and Reporting-Endpoints, keeps 90 days of history on every plan, includes the policy builder, the script inventory and all 12 browser report types from the €39.99 Start plan (3 sites, 250,000 reports), adds alerting, the API and an MCP server from Business at €129.99, and processes everything on OVH in France. Report URI is the better-known product and remains solid, but its entry plan costs $65.99 per month for one domain, 100,000 events and 15-day retention as of August 2026.

Is there a free CSP reporting tool?

Not one you should point production traffic at. Report URI removed its free tier in February 2025, Csper has shown no visible product movement since early 2024, and Sentry only ingests violations into an event quota you are already paying for. Free collection also tends to mean no policy tooling and short retention, which is exactly where the work starts.

Do I need a CSP reporting tool, or can I collect reports myself?

You can receive reports with an afternoon of work. Keeping that endpoint useful is the part that costs money: filtering browser-extension noise, which is most of the raw volume, absorbing million-report spikes, aggregating JSON into something a human reviews weekly, and following the report-uri to Reporting-Endpoints migration across browsers. Priced in engineering time it costs more than any service on this page.

What should a CSP reporting tool do beyond collecting violations?

Three things decide whether a policy ever gets enforced. It has to separate real violations from extension noise, turn observed traffic into a candidate policy you can diff before shipping, and tell you when a script on a sensitive page changes. Collection alone leaves you with a full inbox and the same open question about what your policy should be.