Outside-in · Nothing to install
See your store the way a malicious attacker and a privacy compliance scanner do.
Our AI agent reads it from outside on a schedule — every script, every request, every tracker. Then our security experts decide what actually matters. Watch one run.
yourstore.com
this week
A real browser opens your page. Nothing is clicked yet.
Risk grade
Nothing has moved.
Illustrative. Free shows what changed; paid adds whether it matters. A grade describes what we observed, not a prediction about your store.
Both run on a schedule — weekly, or every weekday — so a surprise change gets caught without you remembering to look. Walking your checkout is a real shopper journey, so it shows up in your own analytics. We ask your approval before we schedule it.
Nothing goes on your payment page
Everyone else asks you to add a script. Under PCI DSS 6.4.3, theirs lands in your scope. We stay outside.
Their vault, your doorway
On Shopify the payment form is theirs. The path to it is yours — and that is where e-skimming happens.
A person reads it first
Most changes are nothing. On a paid plan someone decides which ones are not, before you hear about it.
48%
of scripts on a payment page are pulled in by another script — not by the page. Which is why an audit is true the day you buy it, and why we watch instead.
c/side, Client-Side Attack Report, Q3 2026 — their own monitored customers, not a census of the web.
Run it on your own store
Twenty seconds, no account. You get a list of what we found, not a pitch.
We monitor and report. We do not block attacks, and we do not certify compliance. We are not a QSA or an ASV, and nothing we run satisfies PCI DSS Requirement 11.3.2. Your self-assessment, risk decisions and attestation remain your own.