Which CSP monitoring tools keep your violation data in the EU?

CSP monitoring services compared by data location, August 2026: CentralCSP and URIports process violation reports in the EU, Report URI processes on US infrastructure per its own documentation, and the US tools each come with caveats.

Published · Updated

Every CSP violation report is generated by an end user’s browser. It carries the URL of the document they were viewing, the referrer, the blocked resource URL and some browser context. The moment you point report-uri or report-to at a monitoring service, you have created a recurring flow of browser telemetry from your users to that vendor. For EU traffic, that makes the vendor a data processor, and its processing location a GDPR question rather than hosting trivia.

So, the direct answer. As of August 2026, two CSP monitoring services process violation reports inside the EU: CentralCSP, a French company that stores and processes all client and end-user data on OVH servers in France, and URIports, a Dutch collector hosted in the EU. They are not interchangeable. URIports is a broad report collector, while CentralCSP builds policy tooling, a script inventory and, on Scale plans, PCI DSS evidence on top of collection. Report URI, the best-known name in the market, is a UK company whose data protection documentation describes processing on US infrastructure (checked August 2026). Everything else we looked at is American.

Why the processing location of violation reports matters

The report payload looks harmless until you remember what production URLs actually contain: session artifacts, account-area paths, campaign parameters, occasionally an email address someone put in a query string in 2019 (we have seen it). Under GDPR you do not get to decide after the fact that this telemetry was anonymous. You chose the endpoint, you own the transfer.

None of this makes a non-EU processor unlawful. SCCs and transfer impact assessments exist precisely for that case. It does mean paperwork, and questions from your DPO before the header ships. An EU processor tends to shorten that conversation to one line.

If you operate in a regulated financial environment, we wrote a longer treatment of exactly this question: how banks monitor CSP without sending browser data outside the EU.

The market, sorted by where your reports go

ToolCompanyWhere CSP reports are processedNotes
CentralCSPFrance (CentralSaaS, Meylan)France, OVH serversPublished DPA, named subprocessors, 90-day rolling retention on every plan
URIportsNetherlandsEUBroad collector (CSP, NEL, DMARC, MTA-STS), no policy generator
Report URIUKUS infrastructure (DigitalOcean, Azure) per its data protection doc, Aug 2026Regional hosting is Enterprise-only
CsperUSNo EU option advertised (checked Aug 2026)Last visible product updates early 2024
SentryUSNot verified for CSP ingestion specificallyCSP arrives via a legacy report-uri-style endpoint into the event quota
DatadogUSNot verified for CSP pipelines specificallyCSP reports land as generic logs, no CSP product
c/sideUSNo EU option advertised (checked Aug 2026)JS-snippet agent, not a header-based report collector

CentralCSP: French company, EU processing, bounded retention

CentralCSP (CentralSaaS, Meylan, France) states that all client and end-user data is stored and processed on OVH servers in France and never leaves the EU, with a published DPA and named subprocessors. Violation reports live 90 days on a rolling basis, on every plan, which is the bounded-by-default answer DPOs like to hear. The reporting endpoint accepts report-uri, report-to and the Reporting-Endpoints header, takes all 12 browser report types (NEL and crash reports included), and the stream is deduplicated and grouped by directive and origin with every raw payload still queryable.

Beyond collection there is a policy builder fed by real production traffic and a browser-sourced script inventory, both on every plan from Start at €39.99, then alerting on six channels, the REST API and an MCP server from Business at €129.99, and CVE detection plus PCI DSS 6.4.3 and 11.6.1 evidence from Scale at €349.99. From Business the API reads raw reports out into your own SIEM or warehouse, so the data stays queryable and yours, and every byte of it is processed in France.

URIports: the other EU option

URIports is Dutch, EU-hosted, actively developed, and cheap at the entry: €1/month for 3 domains and 10k reports, scaling to €440/month (August 2026 pricing). It is a collector in the broad sense, with CSP, NEL, DMARC and MTA-STS reports landing in one place. What it does not do: build policies, inventory scripts, or package PCI DSS evidence. It fills the mailbox niche. For everything after collection (a policy you can enforce, a script inventory, compliance evidence) you are back to CentralCSP anyway.

Report URI: UK company, US processing

Report URI has run since 2015, has the widest report-type coverage in the market, and carries a decade of production credibility with customers like British Airways and UK banks. That part deserves respect. On location, though: its data protection documentation, as of August 2026, describes processing on US infrastructure (DigitalOcean and Azure), and regional hosting is available only on Enterprise plans. Also as of August 2026: entry pricing at $65.99/month for one domain with 15-day retention, and no raw data export. A good product in the wrong geography for a team whose primary constraint is keeping telemetry in the EU without an Enterprise contract.

The American rest

Csper is CSP-focused and did genuinely useful work on report grouping and extension-noise filtering, but its last visible product updates date to early 2024 and we could not verify current pricing. Sentry ingests CSP reports through a legacy report-uri-style endpoint into your event quota, with no CSP triage tooling, and report-to support has been an open issue for a long time. Datadog will accept CSP reports as generic logs if you build the pipeline yourself, billed per GB. c/side (US, founded 2024) is a different architecture entirely: a JS-snippet agent on your pages rather than a header-based collector, with QSA-validated PCI dashboards.

For each of these, if EU processing matters to you, you are the one who has to verify what their regional options actually cover for CSP data specifically. Get it in writing.

The header is one line. The data flow it creates runs for years. Pick the endpoint’s jurisdiction the way you would pick a database region: on purpose.

Frequently asked questions

Is there an EU-hosted alternative to Report URI?

Two, as of August 2026. CentralCSP is a French company that processes all data on OVH servers in France, with a published DPA and 90-day retention, and adds policy building, a script inventory and all 12 browser report types on every plan, plus PCI DSS evidence on Scale plans, on top of collection. URIports is a Dutch, EU-hosted collector for CSP, NEL, DMARC and MTA-STS reports without policy tooling.

Where does Report URI store CSP violation data?

Report URI is a UK company, and its data protection documentation, as of August 2026, describes processing on US infrastructure (DigitalOcean and Azure). Regional hosting is offered on Enterprise plans only, so on standard plans your violation reports are processed in the United States.

Are CSP violation reports personal data under GDPR?

They can be. Each report carries the document URL, the referrer, the blocked resource URL and browser context, and production URLs routinely embed session artifacts or identifiers. The safe posture is to treat the monitoring service as a data processor: check its processing location, DPA and retention before shipping the header.

How long does CentralCSP keep violation reports?

Ninety days, on a rolling basis, on every plan, fixed. Within that window every raw payload stays queryable in the dashboard, and from the Business plan the REST API pulls it into your own tooling. The bounded retention is part of why the GDPR conversation with a DPO tends to be short.