Browser-side protection. Use an edge or server WAF to protect requests before they reach your application.
Recent security signals
The latest 200 reported signals for this site, across all dates. Browser reports are evidence for investigation, not proof of a successful attack.
Protection
When off, the agent still records but does not scan or block.
Default action
Sensitivity
How confident a match must be before it counts as a threat.
Network & transport
Client environment
Behavior & forms
Privacy & UX
Allowed script origins
One exact origin per line. A nonempty list enables alerts for other external script origins. These are browser observations, not proof of malicious scripts or verified file hashes.
Allowed connect origins
Trusted API and analytics endpoints for outbound requests.
Edge correlation
Link browser incidents with your edge WAF or SIEM pipeline.
Payload preview
Test a string against the current policy without saving.
Run a preview to see match results here.
Policy changes apply when visitors load a fresh page with the agent.