HUMAN Client-side Defense simplifies payment page script management in compliance with PCI DSS 4 requirements 6.4.3 and 11.6.1. Deploy a single line of JavaScript to automatically receive a comprehensive risk-scored script inventory, provide a simple method to authorize, justify, and assure the integrity of scripts, and generate on-demand audit reports. The solution monitors script behavior, alerts on unauthorized script changes and security-impacting HTTP headers, and enables investigations of risky script actions. Customers can simplify PCI DSS compliance tasks and safely benefit from browser scripts with complete visibility and control across their entire website.
With HUMAN, users can streamline payment page script and header management, secure their site beyond PCI DSS compliance, unleash their business, and reduce risk.
As of March 31, 2025, any website that accepts card payments online must digest, implement, and operationalize two new PCI DSS 4 requirements to manage scripts and headers on their payment pages.
What are organizations expected to do that is new?
To protect cardholder data from the risks introduced by scripts, requirement 6.4.3 mandates that our customers/prospects manage all payment page scripts as follows
A method is implemented to confirm that each script is authorized
A method is implemented to assure the integrity of each script
An inventory of all scripts is maintained with written justification
To further prevent skimming, requirement 11.6.1 states that a change and tamper-detection mechanism is deployed to alert personnel to unauthorized modifications to the security-impacting HTTP headers and the script contents of payment pages.
Note that requirements 6.4.3 and 11.6.1 also apply to merchants using third-party payment service providers to avoid collecting cardholder data themselves, including merchants who self-attest with SAQ D, SAQ A, and SAQ A-EP.
HUMAN PCI DSS Compliance provides:
Easy deployment by embedding a single line of JavaScript code into your website.
Auto-generated script inventory enables justification and authorization and ensures the integrity of all payment page scripts and alerts on HTTP header modifications.
Detailed management console shows current PCI DSS compliance status and generates audit reports on demand.
Policy rules automate script authorization workflows and enable proactive precision mitigation of risky script behaviors, such as cardholder data access.
Script analyzer provides deep insight into each script provenance and DOM, storage, and network actions to inform authorization decisions.
Inventory management of payment page scripts and security-impacting headers with justification, authorization, and integrity logs, complying with 6.4.3 and 11.6.1 of PCI DSS 4.
API and out-of-the-box integrations with common tools and apps (messaging, ticket management, SIEM) to adapt to your workflows.
Highlights
Streamline Payment Page Script and Header Management
With a single line of code, auto-discover, justify, authorize, and assure script and header integrity.
Secure Your Site Beyond PCI DSS Compliance
Gain complete visibility and control of script behavior, gain deep insight, and block risky script actions.
Unleash Your Business, Reduce Your Risk
Enable the value of scripts with automated policies that surgically block risky actions, protecting payment data in browsers.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This contract covers Client-side Defense: Core and prices around your monthly payment page views. The base dimension includes up to 200,000 payment page views per month. If your traffic goes above that level, a usage add-on charges for each additional 1,000 payment page views per month. So your cost scales with how many payment pages visitors load. You buy the Core capability first, then pay incrementally as views exceed the included volume. Both dimensions apply to the same Client-side Defense: Core product.
Top-of-mind questions for buyers
What counts as one payment page view for billing?
A payment page view is a single load of a page where visitors enter payment or cardholder data. A JavaScript sensor in the visitor's browser records each session. Each time a payment page loads counts as one view. Views are totaled monthly to determine your billing.
What happens to my cost if monthly payment page views exceed 200,000?
The Core dimension includes up to 200,000 payment page views per month. Once you pass that level, the usage add-on charges for each additional 1,000 views. Only the views above 200,000 trigger the add-on charge, and it applies per 1,000-view block each month.
Which dimension drives most of my monthly cost?
The Core dimension covers your base entitlement up to 200,000 payment page views. Beyond that, the per-1,000-view add-on drives added cost and grows with traffic. For sites staying under 200,000 views, only the Core charge applies. High-traffic payment pages push more cost into the add-on.
www.humansecurity.com
Helpful?
Vendor refund policy
No Refunds
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Self Service and White Glove Managed Service Available. Onboarding support provided for all new clients. Leverage the efficiency and adaptive design of HUMAN's collective protection. Collective Protection helps to reduce the intensity and rigor of manual tuning to ensure that identified threat markers and signals are worked back into R&D to protect your business before it happens to you. The solution scales well to support the fast-paced lean security teams of today.
BotOrNot_Support@humansecurity.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with the pre-built security hardening and recurring maintenance. Deploy a Amazon Linux 2023 virtual machine hardened with 300+ security controls to support PCI DSS needs. Save time. Launch secure. Accelerate compliance.
This product has charges associated with it for hardening and maintenance. This Citadel VM is secured using 300+ open source security controls and validated using Citadel Audit.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.