Code Defender

Benefit safely from browser scripts

Maximize and protect the business value of client-side scripts, while surgically blocking their hidden security and compliance risk.

Code Defender offers real-time visibility and control of your website’s client-side attack surface.

Deployed with a single line of code running in each of your customers’ browsers, Code Defender automatically inventories your webpage scripts, alerts on risky and anomalous script behavior, enables granular protection of your customers’ sensitive data, and simplifies your privacy and PCI DSS 4 compliance.

See and Stop Client-Side Attacks

Gain full visibility into the scripts running on your website and prevent client-side attacks.

  • Gain Total Visibility

    Continuously Monitor Scripts

    With a single line of code, auto-discover your browser attack surface, including all scripts and sensitive data.

  • Protect Customer Data

    Granular Control Over Scripts

    Manage scripts granularly to mitigate risk without interrupting their desired function.

  • Simplify Continuous Compliance

    Quickly Find and Manage PII Leakage

    Inventory your web scripts, manage authorizations, assure integrity, and generate reports.

Enable Security and Compliance of Website Scripts

Scripts enable you to do business on your website, but they come with a certain level of risk. Code Defender prevents script based data leakage.

Explore Client-side Defense

Learn More

PCI DSS 4 Compliance

Learn More

Personally Identifiable Information (PII) Harvesting

Learn More

Client-Side Supply Chain Attacks

Learn More

Digital Skimming and Magecart Attacks

Learn More

Use Web Scripts Without Risk

Code Defender secures your website by answering the questions “what are my third-party scripts doing” and “what data is being exposed by the scripts?”

Websites use scripts for a number of actions, from login to checkout. Many groups inside a company deploy scripts to enable business without understanding their impact to risk.

Code Defender provides real-time visibility into all scripts, all downstream dependencies, and every action taken in real users’ browsers. Deployed as a single line of code on your website, Code Defender will automatically discover and monitor all scripts, simplifying management.

Modern website scripts load dynamically at run-time in users’ browsers and frequently change without notice. As a result, point-in-time vulnerability scans alone are not sufficient to analyze scripts for malicious or vulnerable code.

Code Defender provides rich insights into and analysis of JavaScript activity on your real consumers’ browsers. It flags and risk-scores any new or changed script behavior, and automatically generates alerts. Out-of-the-box integrations enable sending alerts to your favorite security and collaboration tools.

Though providing significant business value, third-party client side scripts and libraries can put you at risk of a user data breach.

Code Defender allows security teams to authorize important scripts, but disable their unnecessary, anomalous, or potentially malicious elements. With client side mitigation (CSM), security teams have real-time granular control over client-side JavaScript, so they can enable the business without sacrificing access control risks.

Client-side scripts can provide a means to silently leak your users’ PII, including credit card data. Suspicious scripts are typically completely out of your control, and simply removing them may break key functionality on your website.

The Code Defender dashboard offers an at-a-glance overview and actionable recommendations to stop compliance violations and generate compliance reports for audits by Internal Security Assessors (ISA) or PCI’s Qualified Security Assessor (QSA).

Safeguarding Website and Enable Regulatory Compliance

“We wanted to find the anomalies and changes in our client-side scripts. The Code Defender behavioral analysis solution greatly simplifies this process.”

Sr. Manager, Security architecture and engineering

Sally Beauty

Seeing Code Defender in action for yourself is believing.

How Code Defender works

Deploy
The first step is to insert a JavaScript snippet on the template for all pages. Ideally this snippet should be loaded directly to the Document Object Model (DOM) via HTML, at the top of the block as a first party. The snippet is very lightweight at approximately 30kb. Once loaded the page will send relevant information to the HUMAN Sensor. If Code Defender is enabled, it is included as part of the sensor.
Analyze
The Sensor collects activity signals from the client-side browser, including interactions with the DOM, network domains, and local storage. This information is sent to the cloud-based Detector for analysis. The Sensor does not collect any personal data from the browser.
Detect
The cloud-based Detector analyzes the client-side activity signals to build a baseline profile for every first-, third- and Nth-party script running on the web page. The Detector flags any changes in script behavior or execution of new scripts and automatically generates alerts.