Need: Data Governance & Privacy

Marriott Vacations Worldwide Secures the Browser with Jscrambler

Marriott Vacations Worldwide Secures the Browser with Jscrambler
Marriott Vacations Worldwide (MVW) enhances visibility and control over its client-side environment after meeting the PCI DSS requirements 6.4.3 and 11.6.1 with Jscrambler’s Webpage Integrity (WPI).

Overview

Marriott Vacations Worldwide is a global vacation company that offers vacation ownership, exchange, rental, and resort and property management, along with related businesses, products, and services. The company has a diverse portfolio that includes seven vacation ownership brands. It also includes exchange networks and membership programs, as well as management of other resorts and lodging properties.

Challenge

As a large, digitally driven organization operating in a highly regulated environment, Marriott Vacations Worldwide faces increasing pressure to protect customer data, especially credit card data, across complex web environments, particularly in the browser. Like many enterprise organizations, MVW relies on numerous third-party scripts and marketing tags to deliver personalized experiences and optimize performance. However, this growing client-side ecosystem introduces visibility and control challenges, such as shadow IT and unvetted third-party vendor scripts introduced by marketing and sales teams.

The scale of the scope challenge to discover all the payment pages became especially clear during their internal discovery work: “We did a complete inventory of our web-based payment pages that accept credit cards. That was not an easy task to accomplish. Full disclosure, it took 9 months here for us to discover every single web-based page where we accept credit cards. That kind of just talks to the complexity of the organization.” The core challenge wasn’t simply tracking scripts; it was maintaining continuous visibility and control across a large, evolving digital footprint with a small team managing compliance for multiple entities simultaneously.

Solution

The MVW team was aware of PCI DSS requirements 6.4.3 and 11.6.1 early on and used the on-ramp period to identify a solution. MVW’s websites are highly dynamic, with marketing sites frequently updated, and marketing and sales teams often perform site refreshes outside of IT. The team needed a solution that directly met 6.4.3 and 11.6.1, which ruled out options like a CDN or a combination of CSP and SRI due to the required learning curve and manual effort. After evaluating various approaches, MVW selected Jscrambler’s Webpage Integrity (WPI) product to meet the requirements 6.4.3 and 11.6.1 and improve third-party script control in its browser environment.

By automating client-side monitoring, the solution eliminated the need for manual oversight and significantly reduced operational burden. Its seamless integration with the SIEM provided effective visibility without generating excessive alerts. The intuitive UI also made it easy to manage approvals and push business justifications directly to stakeholders, streamlining governance across teams. TJ mentioned that the solution included what he called a “panic button” feature that allows certain third-party scripts to be instantly cut off from data access without impacting performance. Essentially, the Jscrambler platform provides granular control over third-party scripts, enabling MVW to restrict access to sensitive data while still allowing third-party services to function as intended.

TJ noted that, given the organization’s complexity, the journey was not easy. However, the Jscrambler team made the whole process smooth and pain-free: “Early on, it was a pleasure to work with Jscrambler. Jscrambler really stepped up for us. We have more than 15 unique codebases. It was difficult, but it worked out well for us.”

“We haven’t found anything else out there in the market today that provides all of the benefits from the length of time Jscrambler’s been at this to the ease of use of this solution, and directly meeting the PCI requirements.”
TJ Goldsmith

PCI Compliance Program Director at Marriott Vacations Worldwide

Top Jscrambler Features and Capabilities

  • Granular control over third-party scripts
  • Intuitive UI and minimal learning curve
  • Low-noise alerting

Results

Marriott Vacations Worldwide achieved full compliance with PCI DSS v4 requirements 6.4.3 and 11.6.1 ahead of the enforcement deadline. As TJ shared, “We were 100% compliant before we needed to be.”

By implementing Jscrambler, Marriott Vacations Worldwide achieved:

  • Evidence of Compliance
    Compliance with PCI DSS 6.4.3 & 11.6.1, ease of demonstrating/providing evidence of compliance
  • Visibility & Control
    Enhanced visibility & control over all payment pages across all brands
  • Full Client-Side Protection
    Platform leveraged by other internal teams outside of PCI Compliance
  • Improved Risk Posture
    Improved risk posture through real-time script monitoring and header integrity validation

For Marriott Vacations Worldwide, client-side protection was not simply about checking a compliance box. It was about protecting 160 card data flows across six distinct entities, managing dynamic marketing environments, reducing operational burden, and preserving brand trust. With Jscrambler, MVW implemented a solution that did all that while keeping a lean compliance team efficient.

Securing One of the Biggest E-Commerce Websites with Jscrambler

Securing One of the Biggest E-Commerce Websites with Jscrambler
In a landscape where cyber threats are constantly evolving, the Fortune 500 Retail Company’s success with Jscrambler serves as a testament to the efficacy of dedicated client-side protection.

Overview

Established in the 1960s, this client is an iconic American brand boasting four flagship labels. The company recently also expanded its portfolio. As a Fortune 500 company, the company’s commitment to innovation extends beyond the retail industry, delving into the digital realm with a strong online presence and a high-traffic e-commerce platform.

Challenge

In the past decade, the client’s e-commerce traffic has soared, paralleling the rise in online shopping. However, this increase also attracted more frequent and more sophisticated cyber threats. The company witnessed a surge in malicious scripts targeting customer data through various methods, including keylogging, card skimming, and credential hijacking. Confronted with this escalating threat, the client sought robust client-side security solutions to shield its web applications.

The retailer’s broad digital exposure, especially during peak shopping periods like Black Friday, left them vulnerable to attack vectors like JavaScript data exfiltration and script hijacking. To counter these threats, the client required a system that provided comprehensive control to mitigate these kinds of attacks. Additionally, their collaborations with third-party vendors necessitated a security tool that could precisely regulate the data accessible to these third-party tags.

Solution

The retailer sought the right solution to secure its client-side applications against the evolving threat landscape. For an e-commerce platform of their scale, they needed more than just the basics.

The retailer required a security solution that would continue to monitor their website just as effectively in real-time and take appropriate automated action against threats, regardless of traffic volume. Flexibility was equally crucial, especially the ability to restrict data access through form fencing and to oversee all data points on their site comprehensively. Moreover, swift response times were imperative, as the retailer’s success hinged on transforming website visits into sales through an exceptional user experience.

The client’s criteria extended to adaptability and enduring protection. After a thorough evaluation, the retailer identified Jscrambler as the sole contender to meet all of their stringent criteria. Jscrambler’s R&D continuously monitors emerging threats, ensuring the platform evolves to effectively react to the ever-changing cyber threat environment.

As the final deal clincher, Jscrambler gave the retailer a security tool fully focused on client protection. The team already had security tools in their arsenal but didn’t want to rely solely on default security features or add-ons to existing solutions. They believed strongly in a clear separation of responsibilities and were specifically looking for a platform that focused solely on client-side protection, independent of their web application firewall, tag manager, and other existing tools.

“With the kind of traffic we see, data protection for JavaScript, the ability to stop data exfiltration, and field-level protection for sensitive information like credit card details and PII are just the beginning. We also need a solution that can scale up and continue to perform optimally as our business grows. This is absolutely critical.”
Director of Product Security at the Fortune 500 Retail Company

“With Jscrambler, we can maintain the level of security that is critical to running a multinational business and preserving our customer’s trust. The unique layer of security it adds is definitely an integral part of our defense strategy. I’d highly recommend Jscrambler to any other business with a full-blown e-commerce platform that hosts millions of customers daily.”
Director of Product Security at the Fortune 500 Retail Company

Top Jscrambler Features and Capabilities

  • Comprehensive client-side protection
  • Real-time threat mitigation
  • Real-time alerts and reporting

Results

Adopting Jscrambler has provided the retailer with several benefits. Protection from Magecart and skimming risks is crucial for e-commerce platforms, and having Jscrambler covering them on this front helps the client breathe a little easier. They know that sensitive data is protected from exfiltration and hijacking when customers shop on the retailer’s website and that banking and PCI information will remain secure.

Jscrambler WPI 101 – Getting Started

Web applications are facing growing threats from client-side attacks that seek to steal sensitive data and disrupt user experiences. Jscrambler’s Webpage Integrity (WPI) defends against these increasingly targeted risks by safeguarding web assets and payment pages against supply chain attacks, data exfiltration, DOM tampering, and more, while maintaining a seamless user experience and supporting compliance with data privacy-related regulations.

Understanding the Need for Webpage Integrity

With more websites relying on third-party scripts, the client-side attack surface has expanded significantly. Attackers exploit vulnerabilities in these scripts and forms to skim payment data, inject malicious code, or manipulate webpage behavior. Such attacks not only lead to financial losses but also cause critical damage to brand trust and compliance risks. Ensuring the integrity of every script running on the website is crucial for preventing data breaches and complying with regulations and standards, such as PCI DSS v4.

Key Features of Jscrambler Webpage Integrity

Jscrambler’s Webpage Integrity solution provides comprehensive capabilities designed to secure client-side environments:
  • Webpage Inventory: Automatically discover and monitor all third-party scripts (and all other scripts) present on the website, analyzing their origin, behavior, and prevalence to identify risk factors.

Inventory dashboard

  • Sensitive Data Overview: Get detailed reporting on events involving access to sensitive data on webpages (forms, cookies, browser storage, text elements), with filters to isolate alerts by vendor, page, or event type.
  • Form Fencing: Actively block unauthorized scripts from accessing form fields to prevent data skimming and leakage.
  • PCI DSS Compliance Module: Gain tools and reports to help meet PCI DSS version 4 requirements, particularly regarding script integrity on payment pages (6.4.3 and 11.6.1).

PCI DSS Vendor Services dashboard

  • Custom Policies: Define precise security rules without disrupting your user experience. Jscrambler’s customizable policies let you block, alert, or ignore specific script behaviors, such as unauthorized data access, directly on the client side. Instead of stopping scripts from running, WPI silently intercepts and neutralizes risky actions, preserving both page functionality and the integrity of sensitive data.
The Webpage Integrity product uses a hybrid architecture that combines Agent-Based Protection and Agentless Monitoring.  This flexibility lets organizations deploy rapid, lightweight monitoring on less critical pages while applying active, real-time blocking to high-risk areas such as login, payment, and other sensitive data entry forms. Data from both deployment types is integrated into a single unified dashboard, providing a seamless view of client-side risks and compliance status.

App Management dashboard

Step-by-Step Implementation Process

Integrating Jscrambler WPI follows a structured approach to ensure effective deployment and tuning:
  1. Kickoff & Team Alignment
To help things run as smoothly as possible, the Jscrambler team asks that you form a small cross-functional group on your side. Start by assigning the champion (e.g., someone with the title AppSec Lead, Architect, Security Manager, or Risk Manager) from your team for the duration of the integration process. That person will have regular meetings with the team and be the main point of contact. It is also essential to allocate some developer resources (DevOps) for the agent injection on the pages to be monitored in the beginning stage of the deployment. For PCI DSS compliance, it is recommended to loop in your Compliance/Fraud manager for alert triage.
  1. Planning and Scoping
After defining the WPI plan for the client, collaboration is key to identifying the websites and respective pages where the agent should be injected. During this phase, the sensitive forms to be monitored are also mapped, the customer’s first-party vendors are configured, and access permissions are set up for the group of users who will operate the dashboard.

Sensitive Data configurations

  1. Deployment
The successful deployment starts with injecting the Jscrambler agent into the web pages to be monitored, or with the Agentless monitoring component for those aiming to bring payment pages into compliance. Embedded Agent Injection The Jscrambler team shares the snippet instructions for injecting the Jscrambler agent. Usually, the DevOps from the customer side completes this action. The agent injection can be carried out in one of two ways: via code injection or via Tag Manager, in which case no development resources are needed. In an Agent-Based approach, the agent should be injected into previously configured websites and pages. It is recommended that the Jscrambler agent be one of the first scripts loaded on each page to ensure maximum visibility and control. This early injection provides stronger security coverage and ensures that monitoring and blocking can occur before any malicious scripts have a chance to execute. How the Jscrambler Agent Works The agent operates invisibly within end-users’ browsers to monitor script behavior, network requests, and DOM interactions. Importantly, all data transmitted to Jscrambler’s backend is anonymized to protect user privacy, with no personally identifiable information collected. This approach ensures near real-time visibility into any unauthorized or suspicious activity without compromising compliance. Best Practices for a Successful Implementation
  • Inject the agent as early as possible in the page load process to block threats before they can cause harm.
  • Appoint a dedicated project champion, such as a Security or Risk Manager, to coordinate communication and facilitate decision-making with Jscrambler’s team.
  • Use the initial configuration phase as an opportunity to continuously identify benign versus malicious actions in the environment, refining rules and alerts accordingly.
Agentless Monitoring allows WPI to run without any code changes or script deployments on the customer’s side. Instead of embedding an agent into live pages, Jscrambler uses a synthetic user that automatically visits the target pages and executes our data collection routines. This approach simulates real user behavior to detect and classify third-party scripts and potential skimming threats. The agentless option allows customers to move forward even when they can’t easily insert the agent into a web property, such as when they don’t have direct control over the application. To enable agentless monitoring on the web property, provide the Jscrambler team with the URLs of the properties and their corresponding payment pages you wish to monitor. Once the URLs are shared, the Jscrambler team will set up your account and provide the necessary login credentials for you and any additional users. Our team will also configure the websites and payment pages to be monitored by the Agentless Monitoring component.
  1. Configuration & Training
During the training period, insights gathered from the dashboard help confirm that the configured websites, pages, and other settings are correct or identify where small adjustments are needed. For use cases such as Form Fencing, control rules over sensitive forms should be validated to ensure they are properly defined and effective. Jscrambler’s team will be available throughout this process to assist with configuration review and verification. To ensure smooth configuration, weekly meetings can be held, and the topics discussed can include, but are not limited to:
  • Volume: Exact pages where the Jscrambler agent should work
  • Rules to alert about specific actions
  • New configuration requests
  • Custom events tracking
  1. Production
In the final stage, live threat monitoring and alerting begin, with ongoing adjustments to maximize security without impacting the user experience.
  1. Ongoing Operations, Support & Response
As a final step, an ongoing operating rhythm should be established to deliver long-term value from the platform. With the WPI dashboard, it is easy to do reviews, stay on top of the threats, automate compliance reporting, and stay audit-ready. Quarterly performance reviews with the Jscrambler Customer Success Manager can help optimize policies: analyzing blocked activity, updating allow-lists for new vendors, and refining rules as threats evolve. For incidents, rely on predefined rules to act quickly on alerts, including restricting access for suspicious scripts and escalating to Jscrambler support when needed.

Deployment Approaches: Agent-Based vs Agentless

  • Agent-Based Deployment: Embeds a hardened JavaScript agent directly within the website, enabling real-time detection and active blocking of malicious scripts. This method is preferred for high-risk pages needing comprehensive protection.
  • Agentless Monitoring: Not only applicable to this use case, but it also offers a faster path to PCI DSS compliance by passively scanning specified payment pages and tracking third-party services without impacting performance. It is ideal for initial rollouts or pages where direct agent insertion is not feasible.

Compliance and Security Confidence

Jscrambler’s infrastructure is PCI DSS-compliant, ISO 27001-certified, and GDPR-aligned. Regular internal and external penetration testing underpins the product’s security posture, providing customers with assessment-ready reports and increased assurance when protecting critical web applications.

Getting Started Tips

  • Get a full overview of all third-party vendors present on your website, and find out which teams, people, or processes can add JavaScript to the site. Is there a change management or approval process for this?
  • If you need to quickly gain visibility into web pages and third-party risks, start with Agentless Monitoring.
  • Share as many insights as possible during the configuration phase so that Jscrambler team can build tailored protections.
  • Leverage Jscrambler’s intuitive dashboards and real-time alerts to quickly respond to evolving threats.

Conclusion

Jscrambler’s WPI delivers essential, real-time protection against client-side threats that traditional security solutions often miss. Deploying WPI is a decisive step toward securing the client-side and future-proofing web applications against evolving attacks.  

Jscrambler WPI 101 – Form Fencing

Welcome to our new blog series! Jscrambler WPI 101 is a series of articles about Jscrambler’s product Webpage Integrity (WPI), its main use cases, innovative features, and tips on how to maximize the benefits of using the product.
 

The focus of this article is the WPI use case for Form Fencing. Forms are integral to many online businesses that sell goods and services online. Forms gather important customer data and allow you to easily collect payment. Before we cover how WPI’s Form Fencing works, let’s see what kind of forms Webpage Integrity protects and the ways in which they are deployed on websites. In the section below, we’ll primarily review the payment forms as they collect the most sensitive data that criminals target – cardholder data. 

Form Fencing: The Dangers of Form Data Leakage 


Safeguarding user data is critical. Websites rely on third-party analytics libraries to track user behavior, but these integrations can sometimes become a security liability. Let’s imagine that there is a website that uses a third-party analytics library to store user session data. While this functionality is essential for business insights, it also opens the door for potential exploitation.

Imagine a scenario where the third-party library is compromised by malware. Let’s suppose the attackers manipulate a function to access all form inputs and exfiltrate sensitive information. Initially, the function only stores basic user details like email, user ID, first name, and last name.

However, with the malware in place, additional sensitive data—such as addresses and credit card details—could be stealthily collected and sent to an unauthorized external server, all without detection. This kind of data breach can be catastrophic, leading to identity theft, financial loss, and reputational damage.

Preventing Unauthorized Data Collection with Fencing Rules


To counteract such threats, businesses can leverage WPI’s Form Fencing, a proactive security measure that ensures that only authorized first-party scripts and third-party vendors collect and transmit data. With Form Fencing, organizations can create specific rules to monitor and prevent third-party scripts from accessing form fields.

Preventing-Unauthorized-Data-Collection-with-Fencing-Rules


Setting up a Fencing rule is straightforward:

  • Navigate to the Rules page and create a new rule.

  • Define a clear name and description for easy identification.

  • Specify which website pages should be monitored.

  • Identify the values to configure the rule with the form ID/name or the input ID/name (for example, bookingCode for input booking code and lastName for the input last name).

  • Configure the targets.

    Setting-up-Fencing-rule-is-straightforward

  • Configure the action to prevent form data from being accessed by unauthorized scripts.

  • Deploy the rule and activate the WPI protection agent.

Once in place, this rule ensures that any attempt to extract unauthorized information is immediately blocked and flagged in the dashboard.
 

Payment Form Deployment Types WPI Addresses


There are different ways in which you can deploy a form to be displayed on a website and collect payment data. The most vulnerable forms are usually forms that collect card payment data; they are the most common target of digital skimming attacks. Below are the most common types of payment forms.

Direct API Integration Forms

Deployment: The merchant collects payment details and sends them securely via an API to the payment processor. In this case, the WPI agent should be injected by the merchant who is responsible for rendering the payment form.

Direct-API-Integration-Forms


JavaScript-Based Payment Forms

Deployment: A secure JavaScript library (e.g., Stripe.js) collects payment data directly and sends it to the processor. In this case, the WPI agent should be injected by the merchant who is responsible for rendering the payment form.

 JavaScript-Based-Payment-Forms



Stripe.js-Braintree-Hosted-Fields


Example: Stripe.js, Braintree Hosted Fields


Hosted Payment Forms

Deployment: A third-party payment processor hosts the form, so WPI should be deployed and provided by the Payment Service Provider (PSP).

Hosted-Payment-Forms



Form Fencing for PCI DSS v4 compliance 


PCI DSS requirements 6.4.3 and 11.6.1 will become effective on March 31st, 2025. Both requirements were developed to ensure that online merchants’ payment pages are sufficiently protected to detect and prevent skimming attacks. 

If you are a Merchant who hosts a payment form yourself, then you can use a Form Fencing feature as a Compensating Control or follow a Customized Approach to become PCI DSS v4 compliant. Therefore, you don’t need to worry about authorizing scripts.

Form-Fencing-PCI-DSS-v4-compliance 

Additionally, Form Fencing works as an extra layer of defense that can shield your forms from skimmers even before you authorize scripts.

As cyber threats continue to evolve, proactive security solutions like Form Fencing are essential in protecting sensitive information. By implementing Form Fencing, businesses can safeguard user data, maintain compliance with data protection regulations, and enhance trust with their customers. Don’t wait for a breach to occur—instead, take control of your data security today.