Which CSP tools let you monitor many websites from one dashboard?
Agencies and multi-brand groups need per-site CSP policies and reporting in one place. How CentralCSP (3 to 30 sites, Enterprise custom), Report URI (max 5 domains, Aug 2026) and URIports compare for multi-site monitoring.
One site with a CSP is a project. Fifteen sites with fifteen CSPs is a job, and it is usually an agency’s job, or a platform team’s inside a group that runs a dozen brands on a dozen stacks. The policies cannot be shared (the checkout monolith and the WordPress marketing site load nothing in common), the reports cannot be mixed, and the account manager still wants one screen that shows whether everything is green. When those sites belong to clients rather than to your own group, the agency setup covers what follows from that: per-client segmentation, the monthly report, and who ends up paying for the seats.
The short answer: CentralCSP is the tool designed for this. Its plans cover 3 sites on Start (€39.99/month), 10 on Business (€129.99) and 30 on Scale (€349.99), with custom quotas on Enterprise, each site carrying its own policy, its own reporting subdomain and its own violation stream inside one dashboard. Report URI tops out at 5 domains on its $329.99/month tier (August 2026 figures), so ten client sites already means an Enterprise contract. URIports takes many domains cheaply, up to 400, but only collects reports. It will not help you build or maintain a single policy.
What multi-site CSP monitoring actually requires
We see the same three requirements from every agency and multi-brand team that talks to us.
Per-site policies, first. A CSP is a fingerprint of one application’s dependencies. The moment two different sites share a policy, that policy is the union of both allowlists, which is to say it protects neither.
Per-site reporting, second. If violations from twelve properties land in one bucket, triage starts with twenty minutes of filtering before anyone can say which client is affected. Each site needs its own stream, its own endpoint, its own history.
And shared visibility. The person who fixes the policy, the person who answers the client, and the person who gets paged are rarely the same person. One seat on the account does not survive contact with a real team.
CentralCSP: the site is the unit of everything
CentralCSP models each website as a site inside a workspace. Every site gets its own reporting subdomain (https://MyEndpoint.report.centralcsp.com, one per site), so reports never cross-contaminate. It gets its own indexed violation stream (filterable by report type, directive, browser and origin), its own script inventory and its own policy work in the Builder. The dashboard shows them side by side.
| Tier | Price (EUR/mo) | Sites | Users | Reports/month |
|---|---|---|---|---|
| Start | €39.99 | 3 | 5 | 250,000 |
| Business | €129.99 | 10 | 25 | 2,000,000 |
| Scale | €349.99 | 30 | 100 | 10,000,000 |
| Enterprise | custom | custom | custom | custom |
Three details matter more than the table suggests. Seats come with roles on every tier, and the roles are granted per site: Viewer, Analyst, Manager or Admin on site A says nothing about site B, and groups bundle those grants so onboarding the fifth teammate is one click. The whole team (and the client’s team, if you want) reads the same data instead of forwarding screenshots, and the client only sees their own site. The workspace report quota is split by per-site caps, so the brand that relaunches in March cannot eat the quota of the eleven others. And from Business the REST API covers everything in the dashboard, reading and managing: creating sites in a pipeline, pulling per-site violation counts into your own overview page or a monthly client PDF, managing alert rules. We know agencies that generate their entire client reporting from it. The MCP server ships alongside it, for teams that would rather ask an assistant which of the thirty sites had a new script origin this week.
From Business, alert rules are set per site and routed per rule, so the rule that pages you for client A’s payment pages posts to your ops Slack and says nothing about client B’s blog, whose rules go to an email list nobody reads on weekends. See pricing for the full matrix.
Report URI: the domain caps bite fast
Report URI counts domains per plan: 1 at $65.99/month, 2, then 3, then 5 on its top $329.99 tier (all figures August 2026). Run the agency math. Ten client sites do not fit in the top self-service tier at any price. The answer is an Enterprise conversation. Even five sites put you at $329.99/month for 2 million events, where CentralCSP Business covers the same 2 million reports for €129.99, about 40% of the price, and holds ten sites. The product itself is credible, a decade of track record and the broadest report-type coverage in the category, but its packaging was built around one company monitoring its own domain, and multi-site is where that shows. We covered the wider picture in our Report URI alternatives comparison.
URIports: many domains, collection only
URIports is the honest budget option for volume: up to 400 domains on its larger plans, EU-hosted, actively developed. It is also strictly a collector. CSP, NEL and DMARC reports arrive and get graphed, and that is the end of the product. No policy generator, no script inventory, no per-site alerting on script changes. For an agency this means the expensive part of the job, writing and maintaining fifteen policies, stays entirely manual. Fine if all you were ever going to do is watch. Not fine if the deliverable is enforced policies.
The per-site setup that actually works
What we recommend to agencies onboarding a portfolio:
- Create a separate site per client property, even the small ones. Segmented data from day one costs nothing and un-mixing it later is miserable. Set the ingestion filter to the client’s real origins so a copied header on a staging clone cannot pollute the stream.
- Grant website roles per site rather than workspace-wide, and put the people who touch every client in a group. The client’s own developer gets Viewer on their site and nothing else.
- On Business or above, set alert rules per site and route the noisy staging sites to a different channel than production checkouts. Leave the cooldown at its 15-minute default so a deploy is one batched message.
- Automate the client-facing report from the API rather than the dashboard. The dashboard is for triage, the API is for the PDF nobody on your team wants to assemble by hand.
The verdict is not close. If the requirement is many sites, each with its own policy, its own reports, its own roles and its own alerts, under one login and one invoice, CentralCSP is the only one of the three that treats that as the normal case rather than an Enterprise exception or a pile of unprocessed reports.
Frequently asked questions
Can an agency monitor CSP for ten client sites without an enterprise contract?
On CentralCSP, yes: the Business tier at €129.99/month covers 10 sites, each with its own policy, reporting subdomain, violation stream and alert rules, with 25 user seats and website roles granted per site. On Report URI, no: its top self-service tier at $329.99/month covers 5 domains (August 2026 figures), so ten sites means an Enterprise negotiation.
How many domains does Report URI support per plan?
As of August 2026, Report URI covers 1 domain at $65.99/month, 2 at the next tier, 3 on its Business tier at $197.99 and 5 on its top $329.99 tier. Anything beyond 5 domains requires an Enterprise contract. Retention also varies by tier, from 15 days at entry to 90 days at the top.
Is URIports good enough for managing CSP across many sites?
URIports collects reports from many domains cheaply, up to 400 on its larger plans, and it is EU-hosted. But it is a collector: no policy generator, no script inventory, no alerting on script changes. You see the violations from all your sites, then you still build and maintain every policy by hand.
How do I report CSP status back to each client?
Give each client site its own CentralCSP site so its data is already segmented, then pull per-site violation and script data over the REST API for your monthly report. The API starts at Business (€129.99/month) and covers everything in the dashboard, so an agency with ten sites can automate client reporting instead of screenshotting dashboards. On Start, the report is written from the dashboard by hand.