Skip to main content
Pricing

Find the right plan for your team

Free plan included. No credit card required to start. Scale as you grow.

Automates PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1, monitoring scripts on your payment and checkout pages only. Priced by payment page views, not total site traffic. Detects Magecart, web skimming, e-skimming, and malicious third-party scripts in 100% of visitor sessions with no sampling. Identifies AI agents, headless browsers, and autonomous bots by their browser fingerprint, scripted cadence, and session behaviour. Detects OpenAI Operator, Claude for Chrome, Puppeteer, Playwright, and Selenium. Prevents account takeover and credential stuffing at the browser layer, before a login attempt reaches the server. Device fingerprinting with 99.7% accuracy across VPNs, incognito mode, and cookie clearing. Captures device fingerprints tied to order IDs at transaction time. Pre-built evidence packages ready to export in seconds. Direct integration with Chargebacks911 for end-to-end dispute management.

Select your number of

For PCI DSS compliance, count only your payment and checkout page views, not total site traffic.

In GA4, filter Reports > Engagement > Pages and Screens by your /checkout, /payment, or /cart URLs.

In HubSpot, go to Reports > Analytics Tools > Traffic Analytics > Pages.

Note: Only payment page views count toward your cside limit, not total site traffic.

100K150K200K250K300K400K500K
Select your monthly API calls
50K100K150K200K250K300K400K500K

Free

Everything you need to start

PCI DSS compliant
$0 / month

Up to 2,500 payment page views. PCI DSS 6.4.3 and 11.6.1 included. No credit card required.

Start for free
  • Up to 2,500 payment page views/month
  • Unlimited domains
  • 7-day script history retention
  • PCI DSS 6.4.3 and 11.6.1 dashboard
  • AI powered script compliance justification
Most popular

Business

Enhanced protection for growing teams

PCI DSS compliant
$99 / month

For up to 100,000 payment page views and beyond. Full PCI DSS 4.0.1 compliance automation. 14-day free trial.

Start trial
  • Unlimited domains
  • Full PCI DSS 6.4.3 and 11.6.1 compliance dashboard
  • 30-day script history retention
  • Client-side threat intelligence
  • Granular per-vendor permissions control

Enterprise

Built for large-scale traffic

PCI DSS compliant
Custom

For high-volume payment pages and organisations that need custom SLA, SSO, and dedicated support.

Talk to an expert
  • Custom payment page view limits
  • 90-day script history retention
  • 99.9% uptime SLA
  • SSO and multi-team org layer
  • Dedicated account manager

Free

Get started with fingerprinting

$0 / month

Up to 1,000 API calls/month. Device fingerprint ID, cross-session recognition, and basic intelligence signals.

Start for free
  • Up to 1,000 API calls per month
  • Device Fingerprint ID
  • Cross session recognition
  • Basic intelligence signals
  • 7-day data retention
Most popular

Business

Full-featured fingerprinting with advanced intelligence signals.

$99 / month

Browser fingerprinting with 99.7% accuracy across sessions, VPNs, and incognito mode. All intelligence signals including AI agent detection and VPN detection.

Get started
  • All intelligence signals
  • AI agent detection
  • VPN and proxy detection
  • 30-day data retention
  • IP enrichment and threat intelligence

Enterprise

Built for large-scale traffic

Custom

For high-volume traffic and organisations that need chargeback fingerprinting, custom data retention, SSO, and dedicated support.

Talk to an expert
  • Chargeback Evidence (CB911)
  • 99.9% uptime SLA
  • Custom data retention
  • SSO and organisation layer
  • Dedicated account manager
  • Source data fields

“Works out of the box. Documentation is great. Free plan is generous.

— Jasmin S., CTO

“Straightforward to implement. Cleanly covers PCI DSS 6.4.3 and 11.6.1.

— Frédéric B., Director of Software Engineering

We started seeing real value within the first week.

— Information Security Manager, 5,000+ employee company
Reviews
★★★★★ 4.9 / 5 · 37 verified reviews
Awards
Compare all Script Security features Compare all Fingerprint features

Every feature, every plan. Hover the help icon for details.

Chargeback evidence is session-level proof captured at transaction time, including device fingerprints, browser timelines, and behavioural signals, used to win card dispute arbitration with Visa, Mastercard, and Chargebacks911.

Free
Business
Enterprise
Client-side Protection
Real-time malicious domain alerts
Real-time malicious domain alerts
Real-time malicious domain alerts
CSP reporting endpoint

50k

CSP reporting endpoint

1M

CSP reporting endpoint

Custom

Real-time script payload alerts
Real-time script payload alerts
Real-time script payload alerts
Granular per-vendor permissions control
Granular per-vendor permissions control
Granular per-vendor permissions control
E-skimming, clickjacking and cryptojacking defence
E-skimming, clickjacking and cryptojacking defence
E-skimming, clickjacking and cryptojacking defence
Script blocking
Script blocking
Script blocking
Crawler-based analysis
Crawler-based analysis
Crawler-based analysis
PCI Compliance
PCI DSS 6.4.3 and 11.6.1 dashboard
PCI DSS 6.4.3 and 11.6.1 dashboard
PCI DSS 6.4.3 and 11.6.1 dashboard
Script history retention

7 days

Script history retention

30 days

Script history retention

90 days

Unauthorized code blocking

CSP only

Unauthorized code blocking

CSP + hybrid

Unauthorized code blocking

CSP + hybrid

AI powered script compliance justification
AI powered script compliance justification
AI powered script compliance justification
Privacy Monitoring
GDPR violation prevention
GDPR violation prevention
GDPR violation prevention
CCPA violation prevention
CCPA violation prevention
CCPA violation prevention
HIPAA violation prevention
HIPAA violation prevention
HIPAA violation prevention
Support
Email support
Email support
Email support
Slack and Microsoft Teams channel
Slack and Microsoft Teams channel
Slack and Microsoft Teams channel
Dedicated implementation engineer
Dedicated implementation engineer
Dedicated implementation engineer
Uptime SLA
Uptime SLA
Uptime SLA

99.9%

Integrations
Webhook and email notifications
Webhook and email notifications
Webhook and email notifications
SSO
SSO
SSO
S3 log push
S3 log push
S3 log push
SIEM integrations
SIEM integrations
SIEM integrations
Ticketing integrations (Linear, Jira)
Ticketing integrations (Linear, Jira)
Ticketing integrations (Linear, Jira)
Compliance platform integrations (Vanta, Drata)
Compliance platform integrations (Vanta, Drata)
Compliance platform integrations (Vanta, Drata)
Compliance
Attestation of Compliance (AoC)
Attestation of Compliance (AoC)
Attestation of Compliance (AoC)
SOC 2 Type II
SOC 2 Type II

No exclusions, we did it properly

SOC 2 Type II

No exclusions, we did it properly

Audit logs
Audit logs
Audit logs
Payment
Credit card
Credit card
Credit card
AWS Marketplace
AWS Marketplace
AWS Marketplace
ACH / bank transfer
ACH / bank transfer
ACH / bank transfer
Custom enterprise terms
Custom enterprise terms
Custom enterprise terms
Free
Business
Enterprise
Intelligence Signals
Device Fingerprint ID
Device Fingerprint ID
Device Fingerprint ID
Cross session recognition
Cross session recognition
Cross session recognition
Device compromise / hostile environment detection
Device compromise / hostile environment detection
Device compromise / hostile environment detection
VPN detection
VPN detection
VPN detection
AI agent detection
AI agent detection
AI agent detection
IP enrichment and threat intelligence
IP enrichment and threat intelligence
IP enrichment and threat intelligence
Chargeback Evidence
Chargeback Evidence
Chargeback Evidence
Data Retention
Data retention period

7 days

Data retention period

30 days

Data retention period

Custom

Support
Email support
Email support
Email support
Slack and Microsoft Teams channel
Slack and Microsoft Teams channel
Slack and Microsoft Teams channel
Uptime SLA
Uptime SLA
Uptime SLA

99.9%

SSO and organisation layer
SSO and organisation layer
SSO and organisation layer
Dedicated account manager
Dedicated account manager
Dedicated account manager
Support

Every customer gets
direct access to our team.

No ticket queues. Every customer from Free to Enterprise gets a shared Slack or Teams channel with cside engineers. Response SLA: under 15 minutes.

  • Shared Slack or Microsoft Teams channel
  • Direct line to security engineers, not first-line support
  • Feature requests go straight to the roadmap conversation
  • Response time SLA: under 15 minutes during business hours
Talk to a human
Alex Chen · 09:14
Hey, we've got a new gtm-loader.js flagged on our checkout page. Can you check if this looks legitimate or if it is a supply chain issue?
Simon · cside · 09:16 · online
Looking now. I can see the script was first introduced at 09:02 UTC, 12 minutes ago. The payload has changed from yesterday's known-good baseline. I would treat this as a potential supply chain compromise. Can you pause your GTM container while we investigate?
Alex Chen · 09:17
Done. This is exactly why we have you. Thank you.
FAQ

Pricing, answered

01 What counts as a pageview for PCI DSS compliance pricing?

For PCI DSS compliance (requirements 6.4.3 and 11.6.1), only your payment and checkout pages count toward your cside limit, not your entire website. To find your payment page views, filter by your /checkout, /payment, or /cart URLs in GA4 under Reports > Engagement > Pages and Screens.

02 What is a payment page for PCI DSS purposes?

A payment page is any page where a cardholder enters, reviews, or confirms card data, including checkout forms, payment confirmation screens, and stored card management pages. Monitoring these pages for unauthorized script changes is required by PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1. Only payment page views count toward your cside limit, not total site traffic.

03 Does cside help with account takeover and credential stuffing?

Yes. The cside Fingerprint product detects account takeover (ATO) and credential stuffing at the browser layer, before a login attempt reaches the server. cside identifies automated login bots by their scripted typing cadence, absent mouse movement, device fingerprint mismatches, and autofill injection patterns inconsistent with human behaviour. AI agent detection is included in the Fingerprint Business plan and identifies sessions driven by autonomous agents such as OpenAI Operator or Amazon Buy For Me.

04 How much does cside cost?

cside has a permanent free plan at $0/month covering up to 2,500 payment page views. For PCI DSS compliance, pricing is based only on views of your payment and checkout pages, not your total site traffic. Script Security Business starts at $99/month for up to 100,000 payment page views, scaling to $399/month for 500,000. Fingerprint Business is $99/month. Enterprise pricing is custom. No credit card is required to start on any free plan.

05 What is the difference between Script Security and Fingerprint plans?

Script Security monitors every third-party script on your site in 100% of visitor sessions, with no sampling. It automates PCI DSS 4.0.1 compliance for requirements 6.4.3 and 11.6.1, and detects Magecart and web skimming attacks. Because cside runs in every session, not a sample, you catch targeted attacks that only fire for specific users, geographies, or times. It is priced by payment page views per month.

Fingerprint provides browser fingerprinting, device fingerprinting, AI agent detection, account takeover prevention, credential stuffing detection, and chargeback evidence capture. It is priced by API calls. Both are included in the Enterprise plan.

06 Is there a free trial for the Business plan?

Yes. Both Script Security Business and Fingerprint Business include a 14-day free trial. The free plan on both products is permanent: it does not expire and does not require a trial period.

07 How long does deployment take?

Deployment takes under five minutes. Add one script tag to your site and cside begins monitoring immediately with no performance impact. PCI DSS 4.0.1 script inventory for requirements 6.4.3 and 11.6.1 populates within the first 24 hours of real traffic. AI-written script justifications are generated automatically.

08 What does the Enterprise plan include?

Enterprise includes custom payment page view limits, 90-day script and fingerprint data retention, 99.9% uptime SLA, SSO, multi-team organisation layer, dedicated account manager, SIEM integrations, S3 log push, compliance platform integrations (Vanta, Drata), AWS Marketplace billing, ACH payment, and custom enterprise terms. It covers both Script Security and Fingerprint.

09 Will cside break my payment pages or slow down my site?

No. cside is a single lightweight script tag. It does not sit in front of your traffic, does not act as a proxy, and does not intercept or modify requests between your users and your servers. Some competitors use a proxy or reverse-proxy architecture, which introduces latency and a single point of failure. cside never does this. Your payment pages load exactly as they do today. cside observes what executes in the browser and alerts you. It does not sit in the critical path of any transaction.

10 How does cside detect AI agents on my site?

cside fingerprinting detects AI agents, autonomous browsers, and headless automation frameworks through a combination of browser automation signals, environment tampering checks, and behavioural fingerprints. The Fingerprint Events API returns a bot field for every identification call, covering AI browser agents such as OpenAI Operator, Claude for Chrome, and Perplexity Comet, as well as headless browsers like Puppeteer, Playwright, and Selenium, and classic scrapers. Detection runs server-side after the client-side script submits a fingerprint, so it cannot be bypassed by modifying browser headers alone.

11 How does cside help win chargeback disputes?

Winning a card dispute requires session-level evidence captured at transaction time, not reconstructed after a chargeback is filed. Visa and Mastercard dispute processes increasingly require device fingerprints, browser session timelines, script activity logs, and behavioural signals as proof. cside captures full session context automatically for every transaction with 100% session coverage and no sampling. When a dispute is filed, a pre-built evidence package is ready to export in seconds. Merchants using cside for chargeback evidence see an average 40% increase in dispute win rates (platform data, 2024-2025).

12 How does cside integrate with Chargebacks911?

cside integrates directly with Chargebacks911 (CB911) for end-to-end dispute management. The Chargeback Evidence feature, available in the Fingerprint Enterprise plan, captures device fingerprints tied to order IDs at transaction time and formats pre-built evidence packages that meet CB911's dispute submission requirements. When a dispute is raised, your evidence package exports in seconds rather than hours. The integration removes the manual work of assembling evidence after the fact and gives your disputes team the session-level proof that card network arbitration increasingly requires.

13 What is a pageview?

A pageview is counted each time a page on your monitored site loads in a browser and the cside script executes. For PCI DSS compliance pricing, only views of your payment and checkout pages count toward your limit, not total site traffic.

14 What is an API call?

API usage is measured in fingerprint requests. Each time your application calls sendClientTelemetry, it counts as one call. Your dashboard gives you a live view of request volume across all monitored properties.

15 Does cside offer pricing based on Monthly Tracked Users (MTU)?

Yes, on the Enterprise plan. cside supports MTU-based pricing as an alternative to pageview or API call volume. You pay based on the number of unique users fingerprinted each month rather than total request count. This model works well for sites with high repeat-visit traffic, where per-request pricing would otherwise inflate costs without adding coverage.

Didn't find what you were looking for?

View all FAQ

Start monitoring in
five minutes.

Add one script tag and get full browser-layer visibility. PCI DSS 6.4.3 and 11.6.1 compliance automated from day one.

Book a demo