# CentralCSP vs Report URI: which CSP monitoring platform should you choose in 2026?

> A factual comparison of CentralCSP and Report URI: pricing (€39.99 vs $65.99 entry), EU vs US data processing, retention, report types, script inventory, PCI DSS 6.4.3/11.6.1 features, alerting and API access.

- Canonical: https://info.centralcsp.com/articles/centralcsp-vs-report-uri/
- Published: 2026-08-09
- Language: en
- Publisher: CentralCSP (https://centralcsp.com)

Report URI, founded by Scott Helme in 2015, is the best-known name in CSP violation reporting: 42,000+ monitored domains, trillions of processed reports. CentralCSP is the younger European challenger. Both do the same core job. They turn the stream of violation reports coming from your visitors' browsers into a policy you can trust and evidence you can show an auditor. Where they differ sharply is price, data residency, and what's included at each tier.

All Report URI figures below come from its published pricing and documentation as of August 2026. CentralCSP figures are those of [its September 2026 relaunch](https://centralcsp.com/en/blog/changelog), which replaced the old plan lineup. Check current pages before purchasing.

## At a glance

| | CentralCSP | Report URI |
| --- | --- | --- |
| Entry price | €39.99/mo (Start), 3 sites, 250k reports | $65.99/mo (Starter), 1 domain, 100k events |
| Top self-serve tier | €349.99/mo (Scale), 30 sites, 10M reports | $329.99/mo, 5 domains, 2M events |
| Free tier / trial | 14-day trial on Start, seven free tools | 30-day trial (free tier removed Feb 2025) |
| Company / HQ | CentralSaaS, France | Report-URI Ltd, UK |
| Data processing | OVH, France (EU) | Cloudflare edge, then DigitalOcean + Azure, US |
| Retention | 90 days, every plan | 15 → 90 days, by tier |
| Sites | 3 → 30 | 1 → 5 domains |
| Report types | 12 browser report types on one endpoint (CSP, hashes, SRI, NEL, crash, COOP/COEP...) | CSP, NEL, crash, deprecation, COOP/COEP, plus CT, DMARC, TLS-RPT |
| Script inventory | Every plan (CVE matching from Scale) | Script Watch, Business tier ($197.99) and up |
| PCI DSS 6.4.3 / 11.6.1 | Scale (€349.99) and up | Business tier ($197.99) and up |
| Policy generation | Builder from real traffic on every page, evidence per source | CSP Wizard from ~7 days of real traffic |
| Alerting | Slack, Teams, Google Chat, Telegram, email, signed webhooks, unlimited, from Business | Email, generic webhooks |
| API / export | REST API (read and manage) plus MCP server from Business | Summary reports only, no raw data download per its data protection doc |
| Over-quota behavior | Ingestion stops, usage emails at 80% and 100%, per-site caps | Reports dropped, unrecoverable until quota resets |

## Pricing: about 40% cheaper at the entry point, with more in the box

Report URI simplified its pricing in 2025 into four tiers and removed its free tier, which at the time served 98% of its users. Entry is now **$65.99/month** for one domain, 100,000 events and 15-day retention. The PCI DSS suite and all the Watch products (script, data, frame, policy monitoring) start at the **$197.99/month Business tier**, and the top self-serve tier is $329.99 for 5 domains and 2 million events.

CentralCSP has had three self-serve plans since September 2026. **Start at €39.99/month** covers 3 sites, 5 users and 250,000 reports, with all 12 report types, the script inventory, the CSP Builder and 90-day retention included. Against Report URI's entry tier that is about 40% cheaper for two and a half times the reports, three sites instead of one, and six times the retention. **Business at €129.99** goes to 10 sites and 2 million reports and adds alerting, the REST API and the MCP server. Report URI sells the same 2 million events for $329.99 on its top self-serve tier, with 5 domains: identical monthly volume at about 40% of the price. **Scale at €349.99** is the compliance tier, 30 sites and 10 million reports, with the Technologies feature (CVE detection), the PCI DSS v4 module, SSO and the audit log.

At that compliance level Report URI's Business tier is the cheaper line item, $197.99 against €349.99, and a team with one low-traffic domain that only wants the PCI suite will pay less there. Look at what the line item buys, though: 750,000 events on 3 domains versus 10 million reports on 30 sites, roughly a seventh of the per-report price. This is the one place in the comparison where the absolute number favors Report URI.

Both platforms stop ingesting at the monthly cap and neither bills overage, so a traffic spike (or an attack, precisely when you need visibility) can cost you the rest of the month on either. What differs is the warning. CentralCSP emails you at 80% and 100% of the workspace quota and lets you cap each website separately, so one noisy property cannot eat the budget of the one you care about. Report URI's published behavior is blunter: over-quota reports are dropped, unrecoverable until the reset.

## Data residency: EU vs US processing

This is the cleanest architectural difference between the two platforms, and for European banks, insurers and healthcare companies it is often the deciding one.

CSP violation reports are generated by your users' browsers and carry document URLs, referrers and browser context. **CentralCSP states that all client and end-user data is stored and processed on OVH servers in France and never leaves the European Union**, under a published DPA, with violation reports kept 90 days.

Report URI is a UK company, but its published data protection documentation describes ingestion at the Cloudflare edge (with IP addresses stripped, a genuinely good design) and storage on **DigitalOcean and Microsoft Azure infrastructure in the United States**, covered by Standard Contractual Clauses. Geographic hosting is available, but only on Enterprise plans. The same document states that customers cannot download their data, only summary reports are available. If your DPO requires transfer impact assessments for US processors, that's paperwork CentralCSP simply doesn't generate.

## Building a policy vs monitoring everything

Both platforms build policies from **real user traffic** rather than crawling. That's the right approach, since crawlers can't see authenticated pages or geo-gated content. From there the workflows diverge. Report URI's CSP Wizard runs on ~7 days of report-only traffic with an allow/block button per suggestion. CentralCSP's Builder works from what real browsers reported across every page visitors opened, directive by directive, shows the evidence next to every value it proposes (how many browsers, which pages, last seen), keeps browser-extension noise out of the allowlist and never waves an inline script through with `'unsafe-inline'`. Its Chrome extension (free, local-only, rated 5.0 on the Web Store) can prototype a policy against a live site in minutes without an account, before any traffic exists, which is territory a traffic-only wizard can't reach.

Report URI's pitch used to be breadth: NEL, deprecation, crash reports, Certificate Transparency, DMARC aggregates, TLS-RPT, COOP/COEP. Since September 2026 CentralCSP collects the whole browser-side set on one `Reporting-Endpoints` header, on every plan: `csp-violation`, `csp-hash`, `integrity-violation`, `connection-allowlist`, `network-error`, `crash`, `deprecation`, `intervention`, `permissions-policy-violation`, `document-policy-violation`, `coop` and `coep`. What Report URI keeps to itself is Certificate Transparency and the email-domain reports (DMARC, TLS-RPT), which are not client-side security. And the products that make CSP *actionable* there (Script Watch, Policy Watch, the PCI suite) still sit behind the $197.99 Business tier. Collecting a report type is not the same thing as doing something useful with it.

CentralCSP puts its depth into the job that matters here. The violation stream is deduplicated, grouped by directive and origin, extension noise flagged, and every raw payload stays queryable, so a question like "which pages loaded this script last Tuesday" is a filter, not an export request. Retention is 90 days on every plan, where Report URI's entry tier keeps 15. The script inventory, also on every plan, lists every script that executed per page with its SHA-256 hash and hash history, sourced from `csp-hash` reports rather than an agent. Scale adds the Technologies view: library and exact version identified from the script content, matched to CVEs, tagged up to date, outdated, dormant or deprecated. Alerting from Business covers 16 event types (new violation type, report spike, new script origin, unjustified script on a payment page, new vulnerability, among others), evaluated on ingest rather than on a schedule, delivered to Slack, Microsoft Teams, Google Chat, Telegram, email or HMAC-signed webhooks into PagerDuty, Splunk, Datadog or Jira, with no monthly cap. And your data stays yours: from Business the REST API reads and manages everything the dashboard shows, raw reports included, and the MCP server exposes the same to Claude Code, Cursor or any MCP client, where Report URI's own data protection documentation says customers get summary reports only.

## Is there any case for Report URI?

A narrow one. If you specifically need DMARC, TLS-RPT or Certificate Transparency collection in the same tool as CSP, Report URI bundles them and CentralCSP doesn't. You'll pay at least $65.99/month for the bundle and still be on US infrastructure with no raw export. Its decade of history and UK-bank customer list are real, and so is the architecture that decade produced: 2025's restructure raised entry pricing roughly 5× and dropped the free tier that most of its users were on.

## The verdict

For the actual job, deploying a CSP you can enforce, watching every script your visitors' browsers run, and proving it to whoever asks, CentralCSP is the better tool at every tier: about 40% cheaper at the entry point with two and a half times the reports and six times the retention, the same 2 million monthly volume at about 40% of Report URI's top self-serve price, roughly a seventh of the per-report price at the compliance tier (10 million reports and 30 sites on Scale versus 750,000 events and 3 domains on Report URI's Business tier), 90-day retention on every plan, twelve report types on one endpoint, six alert channels without a cap, a REST API and an MCP server from Business, EU processing without an Enterprise negotiation, and a policy builder that shows its evidence. Deploy the trial header on a staging property and you'll have your own violation data to judge it by within a day. If these two are not yet your shortlist, [the eight checks that decide a CSP reporting tool in 2026](/articles/best-content-security-policy-reporting-tool-2026/) sets out the criteria before any vendor name enters the room.

## Frequently asked questions

### What is the main difference between CentralCSP and Report URI?

Both collect CSP violation reports and build policies from real traffic. CentralCSP is a French platform hosted on OVH in France, starting at €39.99/month for 3 sites and 250,000 reports, with all 12 browser report types, the script inventory and 90-day retention on every plan, alerting and the API from Business (€129.99) and PCI DSS tools from Scale (€349.99). Report URI is a UK company processing data on US infrastructure, starting at $65.99/month for one domain, 100,000 events and 15-day retention, with script monitoring and PCI features reserved for its $197.99/month Business tier (August 2026 figures).

### Is there a free way to try either platform?

Report URI removed its free tier on February 1, 2025 and offers a 30-day trial. CentralCSP offers a 14-day free trial on its Start plan, plus seven permanently free tools that need no account (CSP scanner, CSP evaluator, security headers scanner, Reporting API checker, CSP and SRI hash generators, site comparison) and a Chrome extension that runs entirely locally.

### Which platform is better for PCI DSS 6.4.3 and 11.6.1?

Both map their features to the two requirements. Report URI bundles its PCI DSS suite (Script Watch, Policy Watch, inventory reports) from its Business tier at $197.99/month for 3 domains and 750,000 events. CentralCSP's PCI DSS v4 module (payment page declaration, per-script justification, dated change timeline, CSV and PDF evidence export) comes with its Scale plan at €349.99/month for 30 sites and 10 million reports. Report URI's tier is the cheaper line item, CentralCSP's covers ten times the sites at roughly a seventh of the per-report price.

### Where is CSP violation data stored on each platform?

CentralCSP states that all client and end-user data is stored and processed on OVH servers in France and never leaves the European Union. Report URI ingests at the Cloudflare edge and, per its published data protection documentation, stores data on DigitalOcean and Microsoft Azure infrastructure in the United States, with geographic hosting available on Enterprise plans.
