Skip to main content
Blog
Blog

PerimeterX Pricing in 2026: What HUMAN Security Costs (and a Transparent Alternative)

PerimeterX (now HUMAN Security) has no public pricing. Here is the known model in 2026, its modules, and a transparent, listed-price alternative.

Aug 21, 2026 Updated Aug 22, 2026 7 min read
PerimeterX Pricing in 2026: What HUMAN Security Costs (and a Transparent Alternative)
Table of Contents

If you are researching PerimeterX pricing, the first thing to know is that there is no public price to look up, and the second is that the product is now called something else. This guide explains the publicly known pricing model for PerimeterX (now HUMAN Security) as of 2026, what its modules do, why an enterprise vendor prices this way, and how it compares to a client-side security tool that lists its prices openly. No invented dollar figures appear anywhere below, because none are published.

PerimeterX is now HUMAN Security

Before pricing, the naming. PerimeterX and HUMAN Security combined in 2022, and the former PerimeterX products are now sold under the HUMAN brand as part of its application-protection platform. As of 2026, "PerimeterX pricing" and "HUMAN Security pricing" refer to the same commercial terms. The product names that carried over from PerimeterX are:

  • Bot Defender, bot mitigation across web, mobile, and API traffic.
  • Code Defender, client-side and script security aimed at Magecart-style skimming and the client-side requirements of PCI DSS.
  • Account Defender, account takeover and account-abuse protection.

Each is licensed separately. That structure matters for pricing, because your cost is a function of which modules you buy, not a single product price.

Is there public PerimeterX pricing? No, and here is why

As of 2026, HUMAN Security does not publish pricing for the former PerimeterX modules. There is no pricing page with tiers, no per-request rate card, and no self-serve free plan on the website. To get a number you contact sales, scope your traffic and needs, and receive a custom quote.

This is not unusual. Enterprise bot-mitigation and application-security vendors almost universally sell this way, and there are real reasons for it:

  • Traffic volume varies by orders of magnitude between customers. A regional retailer and a global marketplace are not the same deal, so a single list price would be wrong for almost everyone.
  • Modules are bought in different combinations. A team that only needs Code Defender for PCI DSS client-side scope is buying something different from a team that needs all three modules.
  • Enterprise contracts bundle onboarding, support tiers, and SLAs that are negotiated per account.

The trade-off for the buyer is straightforward: you cannot validate cost, or accuracy, on your own traffic before you engage sales. You commit to a scoping cycle first.

The publicly known PerimeterX / HUMAN pricing model

While there is no rate card, the shape of the model is publicly understood from how enterprise bot-mitigation vendors, including HUMAN, describe their commercial terms. As of 2026, treat the following as the model, not as quotes:

  • Custom, sales-led quotes. Pricing is negotiated per account after scoping. Expect discovery calls and a proof-of-concept before a number.
  • Volume-based. Cost scales with traffic, typically measured in requests or page views (and, for some vendors, monthly active users). Higher traffic means a higher contract.
  • Module-based. You pay for the modules you license (Bot Defender, Code Defender, Account Defender), so the same traffic can cost very different amounts depending on scope.
  • Annual enterprise contracts. Engagement is typically a yearly commitment rather than month-to-month, usually with a minimum.

If you need an actual figure, the only source is HUMAN's sales team. Anyone quoting you a specific public PerimeterX price is guessing; treat exact dollar amounts online with suspicion, because HUMAN does not publish them.

Where the overlap with cside is: Code Defender vs client-side security

The module most likely to bring you to a pricing comparison is Code Defender, because client-side and script security is the area where PerimeterX/HUMAN and cside directly overlap. Both address the same core problem: third-party and first-party scripts running on your pages can be tampered with to skim payment data (Magecart), and PCI DSS 4.0.1 now requires you to inventory and monitor those scripts (requirements 6.4.3 and 11.6.1).

The difference relevant to a buyer researching price is transparency. Code Defender's cost is inside a custom HUMAN quote. cside's client-side security product lists its price publicly, so you can size the spend yourself before talking to anyone.

cside pricing, published openly

cside deploys as one first-party JavaScript snippet and lists its pricing on the pricing page. It does not sit in front of your traffic or act as a proxy; it is a single lightweight script tag. As of 2026 the published figures are:

Client-side security (the Code Defender overlap):

PlanPriceIncluded
Free$0/monthUp to 2,000 pageviews
Business$99/monthUp to 100,000 payment page views
Business (higher volume)$499/monthUp to 500,000 payment page views
EnterpriseCustomCustom limits, SSO, SIEM, 90-day retention

Because PCI DSS scope follows the pages that can reach card data, client-side security pricing tracks your payment and checkout page views rather than total site traffic.

Device intelligence (fingerprinting, priced separately):

PlanPriceIncluded
Free$0/month1,000 API calls/month, no card
Business$99/month50,000 API calls ($2 per 1,000 overage)
Scaleup to $2,000/monthUp to 1 million API calls
EnterpriseCustomMTU-based option, custom terms

cside device intelligence fingerprints across 250+ browser, device, and network signals per session at 99.7% accuracy, holding that accuracy across incognito sessions, VPN connections, and cookie-clearing. Mobile is available as native iOS and Android SDKs in beta (early access), running the same engine as the web client with app-only signals on top.

The practical difference for a buyer is that you can start on a free plan, confirm the product works on your own traffic, and know your cost, all without a sales cycle.

PerimeterX / HUMAN vs cside: what to weigh on price

  • Transparency. PerimeterX/HUMAN pricing is custom-quote only as of 2026; cside publishes its prices. If you need to budget before a procurement cycle, published pricing is the practical starting point.
  • Ability to evaluate first. HUMAN engagement starts with sales and scoping; cside has a free tier on both client-side security and device intelligence, so you can validate accuracy and coverage before you pay.
  • Scope of the buy. HUMAN's three modules (Bot Defender, Code Defender, Account Defender) are a broad, enterprise bot-defense platform; cside is a single first-party snippet covering client-side/script security plus device intelligence. Match the tool to the problem: if your driver is PCI DSS client-side scope and script monitoring, that is exactly cside's Code Defender overlap.
  • Contract shape. HUMAN is typically annual enterprise; cside offers month-to-month paid plans alongside enterprise terms.

If your requirement is a full enterprise bot-defense platform across web, mobile, and API with dedicated onboarding, PerimeterX/HUMAN is built for that scale and you should get a quote from their team. If your requirement is client-side and script security for PCI DSS, with device intelligence alongside, and you want to see and validate the price yourself, cside covers that overlap with published pricing.

Which should you choose?

  • Need a broad enterprise bot-mitigation platform (bots, client-side, ATO) and can run a procurement cycle: get a custom quote from HUMAN Security (formerly PerimeterX).
  • Need client-side and script security for PCI DSS 6.4.3 / 11.6.1, with transparent pricing you can budget today: cside client-side security.
  • Need device fingerprinting and a fraud verdict alongside, priced per API call with a free tier: cside device intelligence.

All cside figures above are published and current as of 2026-08-22; see the pricing page for the full breakdown. PerimeterX/HUMAN figures are not published, so this guide describes the model rather than quoting a price.

Further reading

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

There is no public, standard price. As of 2026, PerimeterX is part of HUMAN Security (the two combined in 2022), and HUMAN sells through a sales-led, custom-quote model with no pricing published on its website. Cost is negotiated per account and, based on the publicly known enterprise model, scales with traffic volume (requests or page views) and the modules you license. To get a number you have to contact sales and go through scoping, so the honest answer is that the price depends on your traffic and your module selection, and only HUMAN can quote it.

Effectively yes, as of 2026. PerimeterX and HUMAN combined in 2022, and the former PerimeterX products are now sold under the HUMAN Security brand as part of its application-protection and defense platform. If you are searching for 'PerimeterX pricing', you are looking at HUMAN's commercial terms. The product names you may still see, Bot Defender, Code Defender, and Account Defender, originated with PerimeterX and carried over.

The three modules that came from PerimeterX are Bot Defender (bot mitigation for web, mobile, and API traffic), Code Defender (client-side and script security aimed at Magecart-style attacks and PCI DSS client-side requirements), and Account Defender (account takeover and account-abuse protection). They are licensed separately, which is one reason there is no single list price: your cost depends on which modules you buy and at what traffic volume.

As of 2026, HUMAN does not publish pricing tiers, per-request rates, or a self-serve free tier on its website for the former PerimeterX modules. Engagement is enterprise and sales-led, typically on an annual contract. This is normal for enterprise bot-mitigation vendors, but it does mean you cannot validate cost or accuracy on your own traffic before you talk to sales.

For the client-side and script-security use case that PerimeterX Code Defender covers, cside publishes its pricing openly. Client-side security starts with a free plan at $0/month for up to 2,000 pageviews, Business is $99/month for up to 100,000 payment page views scaling to $499/month for 500,000, and Enterprise is custom. cside's device intelligence is priced separately, with a free tier of 1,000 API calls per month and paid plans from $99/month for 50,000 calls. You can see the full breakdown on the pricing page and start without contacting sales.

As of 2026, the model has three levers rather than a single number. It is volume-based, so cost scales with your traffic, typically measured in requests or page views (and for some vendors monthly active users). It is module-based, so you pay for the modules you license (Bot Defender, Code Defender, Account Defender), and the same traffic can cost very different amounts depending on scope. And it is contract-based, sold as an annual enterprise commitment negotiated per account. HUMAN does not publish the rates behind any of these levers, so the structure is public but the numbers are not.

Based on the publicly known enterprise model as of 2026, expect an annual contract rather than month-to-month billing, usually with a minimum commitment, and a scoping and proof-of-concept phase before you sign. Onboarding, support tier, and SLAs are typically negotiated as part of the deal. None of these terms are published as standard, so the specifics come from HUMAN's sales team during scoping.

Code Defender is PerimeterX/HUMAN's client-side and script-security module, aimed at Magecart-style script tampering and the client-side requirements of PCI DSS 4.0.1 (requirements 6.4.3 and 11.6.1, which ask you to inventory and monitor the scripts running on payment pages). This is the module that overlaps most directly with cside's client-side security. The difference relevant to a buyer researching price is that Code Defender's cost sits inside a custom HUMAN quote, while cside publishes its client-side security pricing openly.

For the client-side and script-security use case, cside is a transparent-pricing alternative you can evaluate for free. Client-side security starts at $0/month for up to 2,000 pageviews, then $99/month for up to 100,000 payment page views and $499/month for up to 500,000, with a custom Enterprise tier. Because PerimeterX/HUMAN does not publish prices, a strict cheaper-than comparison is not possible without a HUMAN quote, but cside lets you see and validate the cost on your own traffic before paying, which a custom-quote vendor cannot.

The core difference is transparency and evaluation. PerimeterX/HUMAN is custom-quote only, sold as an annual enterprise contract after a scoping cycle. cside publishes its prices, offers a free tier on both client-side security and device intelligence, and runs month-to-month paid plans alongside enterprise terms, so you can budget and validate cside before any sales conversation. Scope differs too: HUMAN's three modules are a broad enterprise bot-defense platform, while cside is one first-party JavaScript snippet covering client-side and script security plus device intelligence.

Yes. cside publishes free tiers on both products as of 2026. Client-side security has a free plan at $0/month for up to 2,000 pageviews, and device intelligence has a free tier of 1,000 API calls per month with no card required. That lets you confirm the product works on your own traffic and know your cost before you commit, which is the main practical contrast with a custom-quote vendor like PerimeterX/HUMAN. You can start from the pricing page without contacting sales.

It is standard for enterprise bot-mitigation and application-security vendors. Traffic volume varies by orders of magnitude between customers, so a single list price would be wrong for almost everyone; modules are bought in different combinations, so two customers with the same traffic can need very different scopes; and enterprise contracts bundle onboarding, support tiers, and SLAs negotiated per account. The trade-off for the buyer is that you cannot validate cost, or accuracy, on your own traffic before engaging sales.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead