Yes. cside is additive: it monitors an entirely different layer, the third-party JavaScript that executes in your shoppers' browsers, so it runs alongside your WAF, CDN, and existing tooling with no conflict or overlap. Your WAF keeps handling inbound requests to your servers; cside analyses the outbound, client-side script behaviour your WAF cannot see. It is a single first-party script tag (or the agentless Scan Method), needs no DNS change, and does not route your traffic, so adding it does not disturb your current stack. Findings surface in the cside dashboard.
What's the difference between cside and other client-side security solutions?
Most solutions use outdated approaches that miss sophisticated attacks, often heavily relying on public threat feed intel.
How quickly can I implement cside and see results?
For the Script Method, you just add one script tag to your website, and you'll see live data within minutes.
What happens when malicious scripts use legitimate APIs and domains to hide their activity?
Bad actors often use legitimate services to mask their malicious activity. Making it harder to detect the malicious payloads.
Why is client-side security better than traditional threat intelligence tools like Snyk, Veracode, or Checkmarx?
Traditional threat intelligence tools like Snyk, Veracode, Checkmarx, Spectral, JIT, GitLab, Rapid7, Tenable, Qualys, Aikido Security, and Semgrep rely on static threat feeds that are essentially obsolete by the time they're flagged.