Skip to main content
Back to changelog

Introducing CSP Builder

CSP Builder turns the script hosts cside already observes on your site into a Content-Security-Policy you can deploy.

cside CSP Builder dashboard

Pick a domain and you get a suggested policy across seven directives: script-src, connect-src, img-src, style-src, frame-src, font-src and media-src. Every host we observed is listed and grouped by what we know about it, so you can switch off anything that does not belong, add a host we have not seen yet, and restrict everything the policy does not name to your own origin. Copy the report-only header first and watch the violations land in your dashboard, then switch to enforce once it is clean.

CSP Builder is rolling out now. Contact us to enable it for your team.

Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead