# Report URI > Report URI is a client-side security platform. Your security policy is enforced by the > browser itself, which refuses what the policy disallows and reports what it actually ran. > Nothing is added to your pages and nothing sits in the delivery path for your scripts: > deployment is a single HTTP response header. Fourteen browser and email reporting types > arrive through that one endpoint, and verified copies of the scripts your visitors really > executed are fetched, hash-checked and archived. Every page below is public. The documentation is also published as raw Markdown under https://docs.report-uri.com/md/ — prefer those URLs over the rendered pages. ## Start here - [What Report URI does](https://report-uri.com/): the platform in one page - [Documentation](https://docs.report-uri.com/md/index.md): setup, integrations and platform guides as Markdown - [FAQ](https://docs.report-uri.com/md/faq.md): common questions about accounts, quotas and reporting - [Getting set up](https://docs.report-uri.com/md/agent-setup/prompt.md): a machine-readable walkthrough for configuring reporting ## Core capabilities - [Content Security Policy](https://report-uri.com/features/content-security-policy): collect violation reports and build an enforcing policy from real traffic - [Script Watch](https://report-uri.com/features/script-watch): inventory the third-party scripts running on your pages and flag new ones and changes - [Script Vault](https://report-uri.com/features/script-vault): archived copies of executed scripts, hash-verified against the browser's own fingerprint - [Data Watch](https://report-uri.com/features/data-watch): detect when sensitive form fields are exposed to third-party code - [Integrity Policy](https://report-uri.com/features/integrity-policy): require that scripts carry Subresource Integrity metadata - [Permissions Policy](https://report-uri.com/features/permissions-policy): withdraw browser capabilities such as camera, microphone and location - [Connection Allowlist](https://report-uri.com/features/connection-allowlist): an egress firewall for the browser - name the destinations your site may connect to and have the browser refuse the rest - [Certificate Transparency monitoring](https://report-uri.com/features/certificate-transparency-monitoring): alerting on certificates issued for your domains - [DMARC monitoring](https://report-uri.com/features/dmarc-monitoring): email authentication reporting - [Threat intelligence](https://report-uri.com/features/threat-intelligence): classification of hosts seen in your reports ## PCI DSS 4.0.1 - [PCI DSS compliance](https://report-uri.com/solutions/pci-dss-compliance): how script inventory and tamper detection map to the requirements - [Requirement 6.4.3](https://docs.report-uri.com/md/compliance/pci-dss-6-4-3.md): authorising and inventorying payment page scripts - [Requirement 11.6.1](https://docs.report-uri.com/md/compliance/pci-dss-11-6-1.md): detecting unauthorised change to payment pages - [Checklist](https://docs.report-uri.com/md/compliance/pci-dss-checklist.md): what an assessor asks for, requirement by requirement ## Attacks this addresses - [Magecart and card skimming](https://report-uri.com/solutions/magecart-protection) - [Cross-site scripting](https://report-uri.com/solutions/cross-site-scripting) - [Cryptojacking](https://report-uri.com/solutions/cryptojacking-protection) - [JavaScript integrity monitoring](https://report-uri.com/solutions/javascript-integrity-monitoring) - [Data loss prevention](https://report-uri.com/solutions/data-loss-prevention) ## Comparisons Each page explains how a category of client-side security tool works and what that architecture can and cannot observe. They carry no competitor pricing and no outbound links to competitor sites, because pricing and packaging change without notice. - [Client-side security tools compared](https://report-uri.com/compare-client-side-security-tools): the categories side by side - [vs a proxy](https://report-uri.com/compare/report-uri-vs-a-proxy) - [vs an agent that analyses scripts server-side](https://report-uri.com/compare/report-uri-vs-cside) - [vs a remote scanner](https://report-uri.com/compare/report-uri-vs-reflectiz) - [vs a JavaScript agent](https://report-uri.com/compare/report-uri-vs-feroot) - [vs a sandbox](https://report-uri.com/compare/report-uri-vs-source-defense) - [vs a CDN add-on](https://report-uri.com/compare/report-uri-vs-cloudflare-page-shield) - [vs code protection](https://report-uri.com/compare/report-uri-vs-jscrambler) - [vs a baseline reporting endpoint](https://report-uri.com/compare/report-uri-vs-uriports) - [vs building it yourself](https://report-uri.com/compare/report-uri-vs-diy) ## Incidents and evidence - [Case studies](https://report-uri.com/case-studies): British Airways, Ticketmaster, the ICO, the US Courts, the European Space Agency and others - [Have I Been Pwned](https://report-uri.com/case-studies/have-i-been-pwned) ## Threat intelligence research Write-ups of the client-side attack campaigns behind the hosts we classify as hostile, drawn from browser telemetry our customers send us. Every page is public, and each is also published as raw Markdown at the .md URL below. - [How we classify a host](https://report-uri.com/threat-intel): the two tiers, how a host enters the feed, and how to dispute a classification - [Fake Payment Fields: Skimmers That Replace a Hosted Element](https://report-uri.com/threat-intel/payment-element-lookalikes.md): Attacks that remove a hosted payment element and render a convincing copy in its place - [Smart Contract C2: Skimmers That Rotate Without Being Touched](https://report-uri.com/threat-intel/contract-resolved-skimmer-c2.md): Skimmers that read their next-stage host out of a blockchain contract - [WebRTC Skimmers: Magecart Exfiltration With No Request to Find](https://report-uri.com/threat-intel/webrtc-magecart-skimmers.md): A Magecart cluster that pushes stolen card data down a WebRTC data channel instead of sending a request - [Rotating Subdomains: When One Host Entry Is Always a Step Behind](https://report-uri.com/threat-intel/rotating-subdomain-skimmers.md): Attackers who generate a new subdomain for every victim - [Scareware and Investment Scams Injected Into Real Sites](https://report-uri.com/threat-intel/scam-overlay-infrastructure.md): Injected scam and scareware content that steals attention and trust rather than card numbers - [ClickFix: Malware Delivered by Asking the Visitor to Paste It](https://report-uri.com/threat-intel/clickfix-websocket-c2.md): An overlay that tells the visitor to fix a problem by pasting a command, turning the person into the delivery mechanism and leaving no malicious download to catch - [Typosquatted CDNs: Skimmers Hiding Behind a Familiar Name](https://report-uri.com/threat-intel/cdn-typosquat-skimmers.md): Skimmers served from domains registered one character away from a CDN you already trust - [Browser Extensions With a Shared C2 on Your Pages](https://report-uri.com/threat-intel/browser-extension-c2.md): Extensions your visitors installed, running on your pages, reporting to a shared C2 cluster and taking session data with them - [Compromised npm Packages Reaching the Browser](https://report-uri.com/threat-intel/compromised-npm-packages.md): Packages you legitimately depend on, compromised upstream, arriving in your bundle through the same pipeline everything else uses - [One Server, Many Domains: Rotation a Domain List Cannot See](https://report-uri.com/threat-intel/co-located-domain-rotation.md): A family of unrelated-looking domains, retired and replaced on a schedule, all sitting on one server the whole time ## Optional - [Pricing](https://report-uri.com/pricing): every tier published, no quote required - [Blog](https://blog.report-uri.com/): research and write-ups - [Free tools](https://report-uri.com/tools): CSP Builder, hash generators and analysers