Skip to main content
Juan Combariza
Growth Marketer

Juan Combariza

Researching & writing about client side security.

Articles by Juan Combariza

Consent Management Monitoring: Prove Your Cookie Consent Is Actually Enforced

A CMP records what visitors agreed to. It does not stop trackers from ignoring those choices. Here is how browser-layer monitoring closes the gap.

Jul 20, 2026

NJDPA: Guide to Requirements + Website Compliance

Get a clear breakdown of the New Jersey Data Privacy Act rules, enforcement timelines, and how to manage third-party scripts for compliance.

Jun 23, 2026

How to Stop AI Agents From Creating Fake Accounts with Signup Shield (Guide)

AI agents create fake accounts using real browsers, residential IPs, and generated identities. Here's the detection signal stack to stop them.

May 20, 2026

How to Block AI-Agent Based Content Scraping Bots (Guide)

AI content scraping bots use real browsers, residential IPs, and LLM-powered extraction to harvest your pricing and content. Here's how to stop them.

May 19, 2026

Best account sharing prevention software: comparing tools for businesses

SaaS teams lose revenue to account sharing daily. Compare the best account sharing prevention software by features, pricing, and reviews.

Apr 23, 2026

How to prevent account sharing fraud (full guide for businesses)

Account sharing costs organizations billions in revenue loss. This guide covers prevention methods like device and session limits, as well as strategic tips.

Apr 22, 2026

7 steps to stop account takeover fraud (for Travel businesses)

MFA is bypassed by advanced phishing kits. See the best practices, fingerprint signals, and tools that Travel fraud teams actually use to stop ATO.

Apr 19, 2026

Quick guide to prevent Account Takeover fraud (crypto businesses)

Crypto accounts are the most valuable ATO target of any industry. See the best practices, fingerprint signals, and tools Crypto teams use to stop ATO.

Apr 17, 2026

Best methods to prevent account takeover fraud (FinTech)

FinTech accounts are targeted daily by attackers. See the best practices, fingerprint signals, and prevention tools FinTech teams use to stop ATO.

Apr 10, 2026

Best practices to prevent account takeover fraud (eCommerce)

eCommerce accounts are targeted daily by attackers. See the best practices, fingerprint signals, and prevention tools eCom companies use to stop ATO.

Apr 8, 2026

Meet cside at RSAC 2026

Meet the cside time at RSAC 2026 in San Francisco. Stop by our booth S-0238 on March 24-26 or grab time with us off the floor.

Mar 23, 2026

How to Block and Detect AI Agents on Your Website: 4 Methods Compared

Compare 4 approaches to blocking and detecting AI agents: robots.txt, server controls, traditional bot detection, and specialized AI agent detection. Find out which ones actually stop fraud.

Feb 24, 2026

How to Monitor Cross Border Data Transfer On Your Website | GDPR, CCPA

Your website is likely sending personal data to other countries. Learn how to track cross-border data transfers for GDPR and CCPA requirements.

Feb 12, 2026

How to Prevent Website Data Breaches (to avoid GDPR & CCPA fines)

1/3rd of breaches involve third parties. Learn how to prevent GDPR and CCPA violations by securing third-party scripts, APIs, and data flows.

Feb 6, 2026

VCDPA: Guide to Requirements + Website Compliance

Get a clear breakdown of Virginia Consumer Data Protection Act rules, enforcement timelines, and how to manage third-party scripts correctly.

Jan 22, 2026

Best Client-Side Security Tools for Compliance Reporting & Audits (2026)

Compare the best client-side security tools for compliance reporting and audits in 2026, ranked by audit evidence, session coverage, and pricing.

Jan 20, 2026

Does GDPR apply to my U.S. company? (3 step self assessment)

GDPR might apply to your website even if you're U.S. based. Use this 3 step checklist to see if you're at risk and the potential for financial penalties.

Jan 8, 2026

TDPSA: Guide to Requirements + Website Compliance

Get a clear breakdown of Texas Data Privacy and Security Act rules, enforcement timelines, and how to manage third-party scripts correctly.

Dec 18, 2025

Magecart Protection: How Attacks Work and How to Stop Them

Magecart steals card numbers from checkout pages while WAFs see nothing. Learn how it works, detection signs, and protection controls for 2026.

Dec 2, 2025

CTDPA: Guide to Requirements + Third-Party Script Compliance

Get a clear breakdown of Connecticut Data Privacy Act rules, enforcement timelines, and how to manage third-party scripts correctly.

Nov 25, 2025

Expired Domain Risks: A Real Example from Oracle's Website

An expired domain reference is all an attacker needs to execute phishing under a trusted origin. This blog looks at an example from Oracle's code.

Nov 25, 2025

Shady Plugins in WooCommerce: Security Risks & Protection Tips

Your checkout is only as safe as your plugins. Discover how WooCommerce handles plugin HTML, why that matters, and the steps to stop malicious code.

Nov 19, 2025

Merchant Chargeback Prevention: The 2026 Playbook

Still have a chargeback stack built for the pre-VAMP era? Here's how leading fraud teams use early dispute blocking to stay ahead of tighter rules in 2026.

Nov 8, 2025

Device Fingerprinting in CE 3.0 | How to Block More Chargeback Disputes

This is how merchants use device fingerprinting to win more Compelling Evidence cases (VISA). It blocks first-party fraud and lowers VAMP ratios.

Oct 21, 2025

Chargebacks911 and cside Partner to Fight Chargeback Fraud

We're excited to reveal our partnership with Chargebacks911. Merging CB911's expertise with cside's client-side intelligence helps merchants fight friendly fraud and win more chargeback disputes.

Sep 9, 2025

cside Joins AWS Partner Network and ISV Accelerate

Working alongside AWS helps us bring our solution to the cloud environment our customers already rely on. For us, this is a step towards making client-side security widely accessible.

Sep 9, 2025
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead