50k
1M
Custom
Free plan included. No credit card required to start. Scale as you grow.
Automates PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1, monitoring scripts on your payment and checkout pages only. Priced by payment page views, not total site traffic. Detects Magecart, web skimming, e-skimming, and malicious third-party scripts in 100% of visitor sessions with no sampling. Identifies AI agents, headless browsers, and autonomous bots by their browser fingerprint, scripted cadence, and session behaviour. Detects OpenAI Operator, Claude for Chrome, Puppeteer, Playwright, and Selenium. Prevents account takeover and credential stuffing at the browser layer, before a login attempt reaches the server. Device fingerprinting with 99.7% accuracy across VPNs, incognito mode, and cookie clearing. Captures device fingerprints tied to order IDs at transaction time. Pre-built evidence packages ready to export in seconds. Direct integration with Chargebacks911 for end-to-end dispute management.
For PCI DSS compliance, count only your payment and checkout page views, not total site traffic.
In GA4, filter Reports > Engagement > Pages and Screens by your /checkout, /payment, or /cart URLs.
In HubSpot, go to Reports > Analytics Tools > Traffic Analytics > Pages.
Note: Only payment page views count toward your cside limit, not total site traffic.
Free
Everything you need to start
PCI DSS compliantUp to 2,500 payment page views. PCI DSS 6.4.3 and 11.6.1 included. No credit card required.
Start for freeBusiness
Enhanced protection for growing teams
PCI DSS compliantFor up to 100,000 payment page views and beyond. Full PCI DSS 4.0.1 compliance automation. 14-day free trial.
Start trialEnterprise
Built for large-scale traffic
PCI DSS compliantFor high-volume payment pages and organisations that need custom SLA, SSO, and dedicated support.
Talk to an expertFree
Get started with fingerprinting
Up to 1,000 API calls/month. Device fingerprint ID, cross-session recognition, and basic intelligence signals.
Start for freeBusiness
Full-featured fingerprinting with advanced intelligence signals.
Browser fingerprinting with 99.7% accuracy across sessions, VPNs, and incognito mode. All intelligence signals including AI agent detection and VPN detection.
Get startedEnterprise
Built for large-scale traffic
For high-volume traffic and organisations that need chargeback fingerprinting, custom data retention, SSO, and dedicated support.
Talk to an expert“Works out of the box. Documentation is great. Free plan is generous. ”
“Straightforward to implement. Cleanly covers PCI DSS 6.4.3 and 11.6.1. ”
“ We started seeing real value within the first week. ”
Every feature, every plan. Hover the help icon for details.
Chargeback evidence is session-level proof captured at transaction time, including device fingerprints, browser timelines, and behavioural signals, used to win card dispute arbitration with Visa, Mastercard, and Chargebacks911.
50k
1M
Custom
7 days
30 days
90 days
CSP only
CSP + hybrid
CSP + hybrid
99.9%
No exclusions, we did it properly
No exclusions, we did it properly
7 days
30 days
Custom
99.9%
No ticket queues. Every customer from Free to Enterprise gets a shared Slack or Teams channel with cside engineers. Response SLA: under 15 minutes.
For PCI DSS compliance (requirements 6.4.3 and 11.6.1), only your payment and checkout pages count toward your cside limit, not your entire website. To find your payment page views, filter by your /checkout, /payment, or /cart URLs in GA4 under Reports > Engagement > Pages and Screens.
A payment page is any page where a cardholder enters, reviews, or confirms card data, including checkout forms, payment confirmation screens, and stored card management pages. Monitoring these pages for unauthorized script changes is required by PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1. Only payment page views count toward your cside limit, not total site traffic.
Yes. The cside Fingerprint product detects account takeover (ATO) and credential stuffing at the browser layer, before a login attempt reaches the server. cside identifies automated login bots by their scripted typing cadence, absent mouse movement, device fingerprint mismatches, and autofill injection patterns inconsistent with human behaviour. AI agent detection is included in the Fingerprint Business plan and identifies sessions driven by autonomous agents such as OpenAI Operator or Amazon Buy For Me.
cside has a permanent free plan at $0/month covering up to 2,500 payment page views. For PCI DSS compliance, pricing is based only on views of your payment and checkout pages, not your total site traffic. Script Security Business starts at $99/month for up to 100,000 payment page views, scaling to $399/month for 500,000. Fingerprint Business is $99/month. Enterprise pricing is custom. No credit card is required to start on any free plan.
Script Security monitors every third-party script on your site in 100% of visitor sessions, with no sampling. It automates PCI DSS 4.0.1 compliance for requirements 6.4.3 and 11.6.1, and detects Magecart and web skimming attacks. Because cside runs in every session, not a sample, you catch targeted attacks that only fire for specific users, geographies, or times. It is priced by payment page views per month.
Fingerprint provides browser fingerprinting, device fingerprinting, AI agent detection, account takeover prevention, credential stuffing detection, and chargeback evidence capture. It is priced by API calls. Both are included in the Enterprise plan.
Yes. Both Script Security Business and Fingerprint Business include a 14-day free trial. The free plan on both products is permanent: it does not expire and does not require a trial period.
Deployment takes under five minutes. Add one script tag to your site and cside begins monitoring immediately with no performance impact. PCI DSS 4.0.1 script inventory for requirements 6.4.3 and 11.6.1 populates within the first 24 hours of real traffic. AI-written script justifications are generated automatically.
Enterprise includes custom payment page view limits, 90-day script and fingerprint data retention, 99.9% uptime SLA, SSO, multi-team organisation layer, dedicated account manager, SIEM integrations, S3 log push, compliance platform integrations (Vanta, Drata), AWS Marketplace billing, ACH payment, and custom enterprise terms. It covers both Script Security and Fingerprint.
No. cside is a single lightweight script tag. It does not sit in front of your traffic, does not act as a proxy, and does not intercept or modify requests between your users and your servers. Some competitors use a proxy or reverse-proxy architecture, which introduces latency and a single point of failure. cside never does this. Your payment pages load exactly as they do today. cside observes what executes in the browser and alerts you. It does not sit in the critical path of any transaction.
cside fingerprinting detects AI agents, autonomous browsers, and headless automation frameworks through a combination of browser automation signals, environment tampering checks, and behavioural fingerprints. The Fingerprint Events API returns a bot field for every identification call, covering AI browser agents such as OpenAI Operator, Claude for Chrome, and Perplexity Comet, as well as headless browsers like Puppeteer, Playwright, and Selenium, and classic scrapers. Detection runs server-side after the client-side script submits a fingerprint, so it cannot be bypassed by modifying browser headers alone.
Winning a card dispute requires session-level evidence captured at transaction time, not reconstructed after a chargeback is filed. Visa and Mastercard dispute processes increasingly require device fingerprints, browser session timelines, script activity logs, and behavioural signals as proof. cside captures full session context automatically for every transaction with 100% session coverage and no sampling. When a dispute is filed, a pre-built evidence package is ready to export in seconds. Merchants using cside for chargeback evidence see an average 40% increase in dispute win rates (platform data, 2024-2025).
cside integrates directly with Chargebacks911 (CB911) for end-to-end dispute management. The Chargeback Evidence feature, available in the Fingerprint Enterprise plan, captures device fingerprints tied to order IDs at transaction time and formats pre-built evidence packages that meet CB911's dispute submission requirements. When a dispute is raised, your evidence package exports in seconds rather than hours. The integration removes the manual work of assembling evidence after the fact and gives your disputes team the session-level proof that card network arbitration increasingly requires.
A pageview is counted each time a page on your monitored site loads in a browser and the cside script executes. For PCI DSS compliance pricing, only views of your payment and checkout pages count toward your limit, not total site traffic.
API usage is measured in fingerprint requests. Each time your application calls sendClientTelemetry, it counts as one call. Your dashboard gives you a live view of request volume across all monitored properties.
Yes, on the Enterprise plan. cside supports MTU-based pricing as an alternative to pageview or API call volume. You pay based on the number of unique users fingerprinted each month rather than total request count. This model works well for sites with high repeat-visit traffic, where per-request pricing would otherwise inflate costs without adding coverage.
Didn't find what you were looking for?
View all FAQAdd one script tag and get full browser-layer visibility. PCI DSS 6.4.3 and 11.6.1 compliance automated from day one.