Industry: Travel & Hospitality

Marriott Vacations Worldwide Secures the Browser with Jscrambler

Marriott Vacations Worldwide Secures the Browser with Jscrambler
Marriott Vacations Worldwide (MVW) enhances visibility and control over its client-side environment after meeting the PCI DSS requirements 6.4.3 and 11.6.1 with Jscrambler’s Webpage Integrity (WPI).

Overview

Marriott Vacations Worldwide is a global vacation company that offers vacation ownership, exchange, rental, and resort and property management, along with related businesses, products, and services. The company has a diverse portfolio that includes seven vacation ownership brands. It also includes exchange networks and membership programs, as well as management of other resorts and lodging properties.

Challenge

As a large, digitally driven organization operating in a highly regulated environment, Marriott Vacations Worldwide faces increasing pressure to protect customer data, especially credit card data, across complex web environments, particularly in the browser. Like many enterprise organizations, MVW relies on numerous third-party scripts and marketing tags to deliver personalized experiences and optimize performance. However, this growing client-side ecosystem introduces visibility and control challenges, such as shadow IT and unvetted third-party vendor scripts introduced by marketing and sales teams.

The scale of the scope challenge to discover all the payment pages became especially clear during their internal discovery work: “We did a complete inventory of our web-based payment pages that accept credit cards. That was not an easy task to accomplish. Full disclosure, it took 9 months here for us to discover every single web-based page where we accept credit cards. That kind of just talks to the complexity of the organization.” The core challenge wasn’t simply tracking scripts; it was maintaining continuous visibility and control across a large, evolving digital footprint with a small team managing compliance for multiple entities simultaneously.

Solution

The MVW team was aware of PCI DSS requirements 6.4.3 and 11.6.1 early on and used the on-ramp period to identify a solution. MVW’s websites are highly dynamic, with marketing sites frequently updated, and marketing and sales teams often perform site refreshes outside of IT. The team needed a solution that directly met 6.4.3 and 11.6.1, which ruled out options like a CDN or a combination of CSP and SRI due to the required learning curve and manual effort. After evaluating various approaches, MVW selected Jscrambler’s Webpage Integrity (WPI) product to meet the requirements 6.4.3 and 11.6.1 and improve third-party script control in its browser environment.

By automating client-side monitoring, the solution eliminated the need for manual oversight and significantly reduced operational burden. Its seamless integration with the SIEM provided effective visibility without generating excessive alerts. The intuitive UI also made it easy to manage approvals and push business justifications directly to stakeholders, streamlining governance across teams. TJ mentioned that the solution included what he called a “panic button” feature that allows certain third-party scripts to be instantly cut off from data access without impacting performance. Essentially, the Jscrambler platform provides granular control over third-party scripts, enabling MVW to restrict access to sensitive data while still allowing third-party services to function as intended.

TJ noted that, given the organization’s complexity, the journey was not easy. However, the Jscrambler team made the whole process smooth and pain-free: “Early on, it was a pleasure to work with Jscrambler. Jscrambler really stepped up for us. We have more than 15 unique codebases. It was difficult, but it worked out well for us.”

“We haven’t found anything else out there in the market today that provides all of the benefits from the length of time Jscrambler’s been at this to the ease of use of this solution, and directly meeting the PCI requirements.”
TJ Goldsmith

PCI Compliance Program Director at Marriott Vacations Worldwide

Top Jscrambler Features and Capabilities

  • Granular control over third-party scripts
  • Intuitive UI and minimal learning curve
  • Low-noise alerting

Results

Marriott Vacations Worldwide achieved full compliance with PCI DSS v4 requirements 6.4.3 and 11.6.1 ahead of the enforcement deadline. As TJ shared, “We were 100% compliant before we needed to be.”

By implementing Jscrambler, Marriott Vacations Worldwide achieved:

  • Evidence of Compliance
    Compliance with PCI DSS 6.4.3 & 11.6.1, ease of demonstrating/providing evidence of compliance
  • Visibility & Control
    Enhanced visibility & control over all payment pages across all brands
  • Full Client-Side Protection
    Platform leveraged by other internal teams outside of PCI Compliance
  • Improved Risk Posture
    Improved risk posture through real-time script monitoring and header integrity validation

For Marriott Vacations Worldwide, client-side protection was not simply about checking a compliance box. It was about protecting 160 card data flows across six distinct entities, managing dynamic marketing environments, reducing operational burden, and preserving brand trust. With Jscrambler, MVW implemented a solution that did all that while keeping a lean compliance team efficient.

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler
Jscrambler’s advanced script and form security protection ensures sensitive form data is protected and malicious scripts cannot load.

Overview

This European airline is a global leader in air transportation that operates an extensive flight network connecting Europe to the world through its hubs in European capitals. With over 70,000 dedicated employees and a commitment to diversity, the airline serves millions of passengers across 300 destinations in 120 countries. A large portion of these passengers uses the company’s websites and mobile apps to book flights, check in online, chat with customer service, and redeem loyalty points.

Challenge

The client’s decision to search for client-side protection technology was initially triggered by a credit card data breach at another airline.

Before implementing Jscrambler, the client relied on more traditional security processes that involved checklists and paperwork. However, this manual approach left room for vulnerabilities: “We had security people who could decompile libraries, but they were usually too busy to do it.”.

When the client’s team needed to go fast and add new scripts, innovation sometimes took priority, which meant they would find workarounds to circumvent the documentation-heavy process, leaving them potentially open to attack.

Solution

In search of a comprehensive JavaScript monitoring and protection solution, the client considered various factors, including features and cost. Jscrambler stood out as the only solution that met their security requirements.

The client was particularly impressed by Jscrambler’s Form Fencing feature, which offers fine-grained behavioral control over third-party tag access to form data based on high-level assumptions and user-defined rules. Unlike other solutions, Jscrambler allowed the airline to authorize or block scripts individually.

The company put Jscrambler’s Webpage Integrity solution to the test in multiple Magecart attack scenarios. They ran dozens of tests to see if the solution could detect if content was added, modified, or removed from pages illicitly (DOM tampering), if form events were poisoned, or if data was exfiltrated to a drop server. Jscrambler’s technology passed every single test with flying colors and outperformed all the other available solutions. Adding Jscrambler to a page had little to no impact on its performance.

“Other solutions allow you to monitor cross-site scripting or visit CSP policies, but that’s all they do. They won’t protect forms. They won’t ask, “Is this sensitive data? Yes or no?” For us, Jscrambler was the best platform because they do it all.”
Information Analyst and Product Owner Mobile at Top European Airline

“With most companies, you buy a product, you get support for one or two months, and then you’re on your own. But with Jscrambler, we meet regularly twice a month. We know when new features are coming, even if they haven’t been released yet because they’ll tell us about them on our call and ask us what we think. It’s a nice dialogue to have. You really feel the personal touch. Jscrambler’s customer support is definitely a big plus.”
Information Analyst and Product Owner Mobile at Top European Airline

Top Jscrambler Features and Capabilities

  • Full Visibility and Control
  • Form Fencing
  • PCI DSS Compliance

Results

With zero security incidents, increased efficiency, and peace of mind, Jscrambler has become an integral part of the airline’s strategy for maintaining the highest security standards in today’s evolving digital landscape. The client attests, “We sleep easier at night because we know that the people at Jscrambler are looking out for us and our clients.”