Newsletter - July 2026

July has been about taking the features we've been building in beta wider, sharpening your tooling and giving you back more of your quota. Here's everything we shipped.

Our betas are graduating to open beta 🎓

The access-control and enterprise features we launched in beta over the last couple of months are moving out to everyone who's entitled to them - no more emailing support@ to be switched on. Single Sign-On with SAML 2.0 is now available on Ultimate and Enterprise plans, IP allow-listing for team and API/MCP access is available on Enterprise, and custom integrity hashes are part of the Integrity Suite. Device Bound Session Credentials (DBSC) - which help keep a hijacked session cookie from being usable off your device - are rolling out to every account, gradually, at no cost. If your plan includes one of these, you'll find it in your Account Settings ready to configure.

A lighter touch on your quota 📉

When we sample your reports, the discarded reports were counted against your quota at 25% of their true volume. We've dropped that rate to 10%. In practice, an account on a 1% sample rate sending 100 reports now sees roughly 11 counted against quota instead of 26. There's nothing to change on your side; your effective quota just goes further.

New free tool: Permissions-Policy builder and analyser 🧰

We've added a Permissions-Policy builder and analyser to our free tools. It both builds a Permissions-Policy header from a simple per-feature editor and analyses an existing one - paste a header (native Permissions-Policy or a legacy Feature-Policy, which it translates for you), pull one from a live URL, or start from scratch, then edit every feature the same way. It's free to use, no account needed, alongside our CSP Builder and the rest of the free tools.

Another new free tool: security.txt generator and validator 🔐

Hot on its heels comes a security.txt generator and validator. Point it at a domain and it fetches the site's security.txt and checks it against RFC 9116 - flagging what's wrong, what's missing and what's about to expire - or paste a file you already have to check its contents. When you're ready to publish one, the built-in editor walks you through every field and hands you back a valid file to drop on your server. Free, no account needed, alongside the rest of the free tools.

Onboard Report URI with your AI agent 🤖

There's a new pill at the top of your dashboard: "Onboard your agent to Report URI". Click it to copy a one-line prompt you can paste into an AI coding agent (Claude Code, Cursor, and friends), which then connects to our MCP Server, confirms your account, and sets up CSP reporting for you - handy if you'd rather have your agent wire up reporting than click through it yourself.

Threat intelligence keeps growing 🛰️

This month our lists picked up hosts from a live ClickFix / EtherHiding campaign - the fake-CAPTCHA lure that tricks people into pasting a malicious command - flagged in the amber Suspicious tier we introduced last month. That's on top of the steady expansion of our curated lists through July, and it all flows into your CSP, CSP Integrity and Integrity Policy reports and your Daily Threat Intelligence digest automatically, so you get an earlier heads-up on hosts worth watching.

Meet Script Vault 🗄️

We've put a name to something we've quietly done for months. When a browser on your site executes a script, it reports the cryptographic fingerprint of the file; we fetch that file, hash it ourselves, and keep a copy only if the bytes match - so what lands in Script Vault is provably the code your visitor actually ran, retrievable months later. That matters after an incident: by the time anyone asks what was in a file, the origin is serving something else and the malicious version has been pulled, but the report still carries a download link to the exact file a real browser reported. It sits alongside CSP Integrity and is available to every customer whose plan includes our Integrity Suite.

New guides, and clearer docs 📚

We've been building out our client-side security content to help you make the case internally and evidence compliance. There's a new PCI DSS client-side security hub covering Requirements 6.4.3 and 11.6.1 in plain English - now with a downloadable, QSA-ready evidence pack that maps each requirement to the evidence you can export - audience-specific guides for CISOs, compliance teams and security engineers, and new Platforms, Frameworks and integrations sections in the docs - with clearer descriptions and cross-links throughout. There's also a new comparison hub if you're weighing us up against other client-side security tools, and fresh Security Operations guides showing how to stream your alerts into Microsoft Sentinel, Splunk and Elasticsearch.

We've moved the dashboard's purely cosmetic UI preferences (like your collapsed sidebar) out of cookies and into your browser's local storage, so they're never sent over the network and stick with you across more of the account area. We've also brought our cookie policy back in line with exactly what the site sets - fewer cookies, and an honest table describing them.

Behind the scenes 🛠️

Following June's re-architecture, we've now moved the entire platform onto PHP 8.5, clearing out deprecated code paths as we went, for better performance and a longer, more secure support runway. As always there's nothing for you to do - just a faster, better-maintained Report URI underneath.

That's July - betas going wider, a lighter quota, new free tools and stronger foundations underneath. There's plenty more coming on the enterprise and client-side security front through the rest of the year. As always, if you have any ideas or feedback, please do let me know.

Scott Helme,

Founder.

Read more