HUMAN Client-side Defense simplifies payment page script management in compliance with PCI DSS 4 requirements 6.4.3 and 11.6.1. Deploy a single line of JavaScript to automatically receive a comprehensive risk-scored script inventory, provide a simple method to authorize, justify, and assure the integrity of scripts, and generate on-demand audit reports. The solution monitors script behavior, alerts on unauthorized script changes and security-impacting HTTP headers, and enables investigations of risky script actions. Customers can simplify PCI DSS compliance tasks and safely benefit from browser scripts with complete visibility and control across their entire website.
With HUMAN, users can streamline payment page script and header management, secure their site beyond PCI DSS compliance, unleash their business, and reduce risk.
As of March 31, 2025, any website that accepts card payments online must digest, implement, and operationalize two new PCI DSS 4 requirements to manage scripts and headers on their payment pages.
What are organizations expected to do that is new?
To protect cardholder data from the risks introduced by scripts, requirement 6.4.3 mandates that our customers/prospects manage all payment page scripts as follows
A method is implemented to confirm that each script is authorized
A method is implemented to assure the integrity of each script
An inventory of all scripts is maintained with written justification
To further prevent skimming, requirement 11.6.1 states that a change and tamper-detection mechanism is deployed to alert personnel to unauthorized modifications to the security-impacting HTTP headers and the script contents of payment pages.
Note that requirements 6.4.3 and 11.6.1 also apply to merchants using third-party payment service providers to avoid collecting cardholder data themselves, including merchants who self-attest with SAQ D, SAQ A, and SAQ A-EP.
HUMAN PCI DSS Compliance provides:
Easy deployment by embedding a single line of JavaScript code into your website.
Auto-generated script inventory enables justification and authorization and ensures the integrity of all payment page scripts and alerts on HTTP header modifications.
Detailed management console shows current PCI DSS compliance status and generates audit reports on demand.
Policy rules automate script authorization workflows and enable proactive precision mitigation of risky script behaviors, such as cardholder data access.
Script analyzer provides deep insight into each script provenance and DOM, storage, and network actions to inform authorization decisions.
Inventory management of payment page scripts and security-impacting headers with justification, authorization, and integrity logs, complying with 6.4.3 and 11.6.1 of PCI DSS 4.
API and out-of-the-box integrations with common tools and apps (messaging, ticket management, SIEM) to adapt to your workflows.
Highlights
Streamline Payment Page Script and Header Management
With a single line of code, auto-discover, justify, authorize, and assure script and header integrity.
Secure Your Site Beyond PCI DSS Compliance
Gain complete visibility and control of script behavior, gain deep insight, and block risky script actions.
Unleash Your Business, Reduce Your Risk
Enable the value of scripts with automated policies that surgically block risky actions, protecting payment data in browsers.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This contract covers Client-side Defense: Core and prices around your monthly payment page views. The base dimension includes up to 200,000 payment page views per month. If your traffic goes above that level, a usage add-on charges for each additional 1,000 payment page views per month. So your cost scales with how many payment pages visitors load. You buy the Core capability first, then pay incrementally as views exceed the included volume. Both dimensions apply to the same Client-side Defense: Core product.
Top-of-mind questions for buyers
What counts as one payment page view for billing?
A payment page view is a single load of a page where visitors enter payment or cardholder data. A JavaScript sensor in the visitor's browser records each session. Each time a payment page loads counts as one view. Views are totaled monthly to determine your billing.
What happens to my cost if monthly payment page views exceed 200,000?
The Core dimension includes up to 200,000 payment page views per month. Once you pass that level, the usage add-on charges for each additional 1,000 views. Only the views above 200,000 trigger the add-on charge, and it applies per 1,000-view block each month.
Which dimension drives most of my monthly cost?
The Core dimension covers your base entitlement up to 200,000 payment page views. Beyond that, the per-1,000-view add-on drives added cost and grows with traffic. For sites staying under 200,000 views, only the Core charge applies. High-traffic payment pages push more cost into the add-on.
www.humansecurity.com
Helpful?
Vendor refund policy
No Refunds
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Self Service and White Glove Managed Service Available. Onboarding support provided for all new clients. Leverage the efficiency and adaptive design of HUMAN's collective protection. Collective Protection helps to reduce the intensity and rigor of manual tuning to ensure that identified threat markers and signals are worked back into R&D to protect your business before it happens to you. The solution scales well to support the fast-paced lean security teams of today.
BotOrNot_Support@humansecurity.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
HUMAN is committed to protecting the integrity of the digital world. We ensure that every digital interaction, transaction, and connection is authentic, secure, and human. Every week, HUMAN verifies 20 trillion digital interactions, providing unparalleled telemetry data to enable rapid, effective responses to the most sophisticated threats.
The HUMAN Defense Platform detects, disrupts, and eliminates fraud to ensure a secure, trustworthy, and human environment. HUMAN is the only solution that combines fraud telemetry throughout every moment of a user's digital journey, from online advertising to site scraping, account creation, account takeover, and account fraud. Our intelligent machine learning algorithms, state-of-the-art threat intelligence, and behavioral and anomaly analytics systems and teams work tirelessly to detect and defeat sophisticated bots, malicious scripts, and bad human actors, providing you and your customers with a seamless and secure experience.
HUMAN is a cybersecurity company that safeguards 465+ customers from digital attacks, including bots, fraud, and account abuse. We leverage modern defense to disrupt the economics of cybercrime by increasing the cost to cybercriminals while simultaneously reducing the cost of collective defense. Today we verify the humanity of more than 20 trillion digital interactions per week across advertising, marketing, e-commerce, government, education and enterprise security, putting us in a position to win against cybercriminals.
Humans, bots, and AI agents increasingly act on behalf of legitimate consumers and fraudsters alike. The challenge is not just blocking certain traffic types; it is distinguishing between malicious and legitimate activity regardless of the source, and responding appropriately in each case. HUMAN Sightline combines advanced detection, customizable mitigation, and investigative intelligence to provide that clarity. The solution protects users and accounts from fraud, abuse, and misuse by humans, bots, and AI agents and seamlessly enables trusted interactions across the customer journey. By providing direct visibility into key business metrics, HUMAN Sightline allows you to understand and showcase the impact of anti-fraud measures on your bottom line, so you can optimize accordingly.
PCI Pal enables organizations to deliver secure, frictionless, and PCI DSS compliant payment experiences across voice, digital, agent-assisted, and self-service channels. Built on AWS, PCI Pal's cloud-native platform combines industry-leading payment security with the scalability, resilience, and global reach needed to support modern customer engagement.
Through Speak to Pay, Click to Pay, and Key to Pay solutions, customers can securely complete payments using their preferred method while sensitive payment data is removed from the contact center environment. PCI Pal supports card payments, digital wallets including Apple Pay, Google Pay, and PayPal, and secure payments across phone, IVR, SMS, web chat, and messaging channels.
By reducing PCI DSS scope, protecting customer data, increasing payment completion rates, and improving operational efficiency, PCI Pal helps organizations strengthen compliance, enhance customer trust, and deliver seamless payment experiences at scale.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.