News Type: Press

Jscrambler Launches Unified Client-Side Security Platform for the AI Era

First platform to unify software integrity and data governance at browser runtime, helping enterprises continuously enforce security against AI-powered threats and data harvesting risks

PORTO, Portugal — July 30, 2026 — Jscrambler, the Client-Side Security Platform for the modern enterprise, today announced the launch of its Unified Client-Side Security Platform, introducing a new approach to securing applications and customer data where AI-powered risks increasingly operate: inside the browser.

Key Highlights

  • Jscrambler launched a Unified Client-Side Security Platform that merges software integrity and data governance to close the enforcement gap at browser runtime.
  • The platform is built on a proprietary Behavioral Enforcement Core that gives AppSec and data governance teams a single deployment and enforcement architecture.
  • The platform is backed by new browser security research, showing how AI is accelerating client-side software and data risks while exposing the need for continuous browser runtime enforcement.

AI is fundamentally changing how software is attacked and how customer data is collected inside the browser. As organizations rapidly adopt AI-powered applications, agents, and third-party services, existing security architectures built around isolated application security, privacy, and governance tools are no longer sufficient. Jscrambler is the first Client-Side Security Platform to unify software integrity and data governance through a common browser runtime architecture, enabling enterprises to continuously enforce security where applications execute and customer data is created.

“AI didn’t create browser risk—it dramatically accelerated it,” said Rui Ribeiro, CEO and Co-Founder of Jscrambler. “Today, software compromise and AI-driven data harvesting occur simultaneously inside the browser, yet most security architectures still treat them as separate problems. Our Unified Client-Side Security Platform changes that by bringing software integrity and data governance together through a single runtime enforcement architecture. Organizations can now continuously secure multiple initiatives through one platform instead of managing disconnected tools.”

For years, application security teams have focused on protecting software while privacy, governance, and compliance teams concentrated on securing customer data. While this approach was sufficient at one point in time, AI has exposed a critical blind spot inside the browser where applications execute, third-party code runs, AI agents operate, and sensitive customer information is assembled.

This convergence is forcing security leaders to rethink how browser security is managed. Rather than deploying isolated point solutions, enterprises need a unified platform capable of protecting software integrity, governing customer data, detecting evolving threats, and enforcing policy continuously throughout the browser runtime.

A Unified Platform for Enterprise Security Initiatives

The Jscrambler Unified Client-Side Security Platform addresses this new reality by enabling organizations to extend critical security initiatives into the browser through a single runtime architecture.

This architecture provides:

  • LLM-Resilient Code Protection: Defends application code against AI-powered attacks at execution time
  • Software Supply Chain Security: Provides runtime enforcement against third-party script risks that static pipeline scanners cannot see
  • AI Data Governance: Detects and controls AI-powered data harvesting at the point of data creation
  • Data Privacy and Compliance: Extends beyond consent management with runtime enforcement against unauthorized data collection
  • Fraud and Abuse Prevention: Detects and blocks fraud, automation, and identity abuse at runtime
  • Threat Detection & Response: Extends active threat hunting, real-time telemetry, and incident response into the browser runtime to neutralize client-side threats
  • Compliance Enforcement: Features automated technical proof for PCI DSS v4, GDPR, EU AI Act, HIPAA, and CCPA

Organizations can deploy individual solutions based on their priorities or expand across initiatives over time, giving CISOs, security architects, AppSec, Security Engineering, Privacy, GRC, and SOC teams shared visibility, continuous runtime enforcement, and a common operational foundation through a single platform.

Powered by the Behavioral Enforcement Core

Every solution is powered by Jscrambler’s proprietary Behavioral Enforcement Core, the platform’s centralized runtime engine that continuously monitors, analyzes, and enforces browser behavior through a single deployment, turning enterprise policy into active protection at the point of data creation.

Purpose-built for the AI era, the Behavioral Enforcement Core introduces new runtime enforcement capabilities spanning the enterprise security lifecycle.

These capabilities include:

  • Identify: AI-powered script discovery and access mapping that continuously inventories AI agents and third-party scripts accessing sensitive customer data
  • Protect: LLM-resilient code hardening and proactive AI agent controls that prevent code manipulation, unauthorized runtime access, and AI-powered data harvesting
  • Detect: Behavioral AI script drift detection that identifies execution anomalies and emerging client-side threats
  • Respond: AI browser telemetry workflows that reconstruct incidents and accelerate investigations for security operations teams
  • Comply: Real-time vendor risk assessments and browser telemetry that continuously validate third-party behavior while providing technical evidence for regulatory requirements

Research Highlights the Growing Need for Runtime Enforcement

The platform launch follows Jscrambler’s latest browser security research, Beyond the Vault: What Banking Sites Quietly Share Before You Ever Log In, which uncovered widespread unauthorized third-party tracking and AI-enabled data collection occurring before user consent across leading financial institutions. The findings reinforce a growing industry challenge: software integrity and data governance can no longer be managed separately once applications reach the browser.

The Jscrambler Unified Client-Side Security Platform is now available to enterprise organizations worldwide.

To learn more, read the in-depth technical overview of the platform, and register for the August 20 webinar, The Crack in the Vault: How Banking Sites Unknowingly Expose Customer Data to Third Parties.

About Jscrambler

Jscrambler is the Client-Side Security Platform for the modern enterprise. The first vendor to unify software integrity and data governance at browser runtime, Jscrambler’s Behavioral Enforcement Core gives AppSec and data governance teams a single control plane to protect, enforce, and comply — from one deployment. Built on 15 years of browser runtime expertise and proprietary research, Jscrambler serves Fortune 500 companies, financial institutions, airlines, online retailers, and media organizations whose success depends on what happens in the browser. Learn more at jscrambler.com.

Media contact

Doug Fraim

Guyer Group for Jscrambler

[email protected]

US and European Banks Sharing Financial Intent, Loan Details, and Customer Data With Third-Party Platforms, According to Jscrambler Research

Analysis Shows Financial Institutions Are Sending Sensitive Customer Data to Google, Meta, TikTok, LinkedIn, and Salesforce Without Valid Consent

PORTO, Portugal, July 22, 2026 —New research from Jscrambler reveals that banking websites are transmitting sensitive customer information, including hashed identifiers, loan details, and financial intent signals, to third-party advertising, analytics, and personalization platforms. The analysis of 14 financial institutions, spanning retail and investment banks, payment providers, and consumer credit platforms, found that this data routinely leaves the site before a cookie consent choice is made and, in some cases, even after users explicitly reject tracking.

Key Highlights:
– Across 14 financial services websites in Europe and the US, tracking technologies fired without valid user consent on 9 sites, sending data to at least a dozen third parties, including Google, Meta, TikTok, LinkedIn, Pinterest, Adobe, and Salesforce.
– Hashed and unhashed emails, phone numbers, and government tax IDs sent from account-opening and mortgage flows, plus precise loan details — including a €27,000 loan simulation with full repayment terms — from credit and loan-simulator flows.
– Tracking often continued after users rejected cookies, and consent choices frequently didn’t carry over into iframes and subdomains handling the same transaction.

As financial institutions accelerate digital banking, personalization, and embedded financial services, more critical customer interactions are moving into the browser, creating new exposure points beyond traditional application security controls.

While banks present themselves as among the most careful custodians of personal and financial data, Jscrambler’s research shows that the public-facing reality often does not match this. The report found that some of the most regulated and sensitive pages on the web—mortgage applications, account openings, credit simulators—have tracking and personalization scripts that collect and transmit data far beyond what ordinary financial customer-journey measurement requires.

Incidents identified by the research include:
– A Spanish bank’s mortgage process sent a customer’s hashed email and phone number to TikTok’s pixel endpoint immediately after cookie acceptance, despite TikTok appearing in neither the bank’s cookie policy nor its privacy policy.
– In a Portuguese bank’s account-opening flow, a customer’s email address was sent to a Salesforce marketing platform alongside the customer’s name, age, and national tax number (NIF), without valid consent.
– A credit and loan simulator at two other Portuguese institutions shared the full details of a customer’s loan request, including exact amounts, terms, interest rates, and total cost of credit, with Google Analytics. This created a continuous stream of borrowing-intent signals that flowed into a third-party advertising ecosystem used across industries.
– The analysis uncovered examples of leading U.S. banking and investment websites sending analytics requests to third parties before visitors had the opportunity to provide consent, highlighting how browser-side technologies can bypass intended privacy controls.

The research also documented three distinct consent failures with tags firing before a cookie banner was actioned, tags that continued firing after a user selected “reject all,” and consent choices that were correctly recorded on a bank’s main site but not carried into iframes or subdomains handling the next step of the same transaction. In one instance, LinkedIn logged a user’s click on the “reject all” button as a tracking event in the same moment the rejection was being ignored.

“Banks have spent years hardening their perimeter, but critical customer journeys like account opening, lending, and personalization increasingly run through third-party scripts they don’t fully control,” said Gareth Bowker, Head of Security Research, Jscrambler. “You can outsource the function, but you can’t outsource the risk. Our research shows this is not a handful of isolated misconfigurations. It’s a pattern that’s consistent across countries and institutions, where sensitive financial data leaves the browser through technologies many organizations do not fully understand or govern.”

The findings raise significant compliance considerations under GDPR and the ePrivacy Directive’s prior-consent requirements, the EU’s DORA framework governing third-party risk in financial services, the incoming Payment Services Regulation, and US directives, including the Gramm-Leach-Bliley Act, CCPA, and CPRA. Jscrambler notes that responsibility is shared between institutions that don’t audit the runtime behavior of the scripts they deploy, and ad-tech platforms whose default configurations, such as automatic advanced matching, capture and transmit contact data with no explicit action required from the site owner.

Jscrambler recommends that financial institutions do the following:
– Move beyond point-in-time vendor review and static tag audits toward continuous runtime monitoring of account-opening, lending, and simulation flows.
– Deploy enforcement controls that block unauthorized data exfiltration, including data placed in request URLs.
– Verify that rejected consent actually stops data collection rather than merely logging a denied signal.
– Use consent enforcement that extends across iframes and subdomains rather than breaking at the site boundary.

Read the full research report, Beyond the Vault: What Banking Sites Quietly Share Before You Ever Log In.

In addition to the report, Jscrambler will host a webinar to examine the research findings, including real-world examples of sensitive financial data exposure, consent failures, competitive intelligence risks, and the runtime controls that financial institutions need to regain visibility and control over browser activity.

Webinar Details:
Date/Time: August 20, 2026, at 10 AM EST
Participants: Gareth Bowker, Head of Security Research; Nathan Coppinger, Product Marketing Manager; David Alves, Security Analyst.
Registration: Available here.

About Jscrambler
Jscrambler is the Client-Side Security Platform for the modern enterprise. The first vendor to unify software integrity and data governance at browser runtime, Jscrambler’s Behavioral Enforcement Core gives AppSec and data governance teams a single control plane to protect, enforce, and ensure compliance — from a single deployment. Built on 15 years of browser runtime expertise and proprietary research, Jscrambler serves Fortune 500 companies, financial institutions, airlines, online retailers, and media organizations whose success depends on what happens in the browser. Learn more at jscrambler.com.

Media contact
Doug Fraim
Guyer Group
[email protected]

Jscrambler Appoints Sean O’Leary Vice President of Global Sales to Accelerate Worldwide Revenue Growth and Partnership Expansion

PORTO, Portugal – May 13, 2026—Jscrambler, the pioneering platform for client-side security, today announced the appointment of Sean O’Leary as Vice President of Global Sales. In this role, O’Leary will oversee all sales, alliances and partnerships, and technical pre-sales, helping Jscrambler bring its industry-leading client-side security solutions to businesses worldwide.

 

The appointment comes as demand for client-side security continues to accelerate. Modern digital experiences are assembled in real time in the browser from dozens of components, including third-party scripts, payment processors, identity providers, and AI systems, creating a vast, largely ungoverned attack surface. Jscrambler addresses this gap by enforcing enterprise security policy directly inside the browser runtime, protecting application logic, restricting data access, and preventing unauthorized transmission at the point where sensitive data is first created.

 

“Demand for client-side security has never been stronger. Enterprises are waking up to the fact that the browser is where their most sensitive data lives, yet it is also where they are most exposed,” said Rui Ribeiro, CEO and co-founder of Jscrambler. “Sean’s deep experience building and scaling revenue organizations at high-growth cybersecurity companies makes him exactly the right leader to help us meet that moment. In this role, he will be instrumental in bringing our Client-Side Security Platform to the security, privacy, and compliance leaders who need it most.”

 

O’Leary brings extensive experience leading high-performance sales organizations and driving revenue growth across both cybersecurity and risk intelligence sectors. Prior to joining Jscrambler, he held senior leadership positions at several high-growth cybersecurity firms, including Vendict, CYE, and BitSight. O’Leary holds a Bachelor’s degree in Business Management from Bryant University.

 

“The client-side attack surface is one of the most underprotected areas in enterprise security today,” said O’Leary, Vice President of Global Sales, Jscrambler. “Jscrambler has built something truly differentiated, providing organizations with the control they need at the exact point where their most sensitive data is created and where their greatest exposure exists. I’m thrilled to join this team and help bring these capabilities to market at a moment when organizations are just beginning to grasp what they’re up against.”

 

Visit the Jscrambler website to learn more about Jscrambler’s Client-Side Security Platform.

 

About Jscrambler

Jscrambler is the leader in Client-Side Security for the modern, composable web, turning enterprise policy into enforceable control at the point where digital interactions are created, inside the browser.

As organizations increasingly build digital experiences through third-party software supply chains and AI-powered agents, sensitive data is now created directly in the browser — the point of creation for digital interactions — making it one of the enterprise’s most privileged yet least governed attack surfaces.

Jscrambler’s Client-Side Security Platform is powered by a Behavioral Enforcement Core that governs how application code, third-party scripts, and sensitive data behave at runtime. By enforcing software integrity and data governance directly in the browser, the platform ensures sensitive data and AI inputs are controlled in accordance with enterprise policy at the point of creation, before they leave the client environment.

Trusted by leading global retailers, airlines, financial services providers, and healthcare organizations, Jscrambler provides the visibility and enforcement organizations need to stop client-side attacks, prevent data leakage, and maintain compliance with regulations and standards, including PCI DSS, GDPR, HIPAA, CCPA, and the EU AI Act.

Jscrambler Named Innovator in Global InfoSec Awards

PORTO, Portugal, April 3, 2026 – Jscrambler, the pioneering Client-Side Security Platform for modern web applications, has won the following awards from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine: Most Innovative Client-Side Protection, Most Innovative AI Data Leakage Prevention, and Most Innovative Software Supply Chain Security. 


“It’s an honor to once again be among the Global Infosec Awards winners,” said Rui Ribeiro, CEO and co-founder of Jscrambler. “There is a structural control gap created by modern digital architecture, where existing policies and protections stop at the edge while execution continues at runtime. Jscrambler was built to close this gap, providing a technical protection layer and enforceable control inside the browser to reduce client-side risk and secure sensitive data.”

The browser is where digital business executes and where sensitive data is born. However, it remains one of the least governed environments. While AI governance platforms manage models, they do not manage inputs. In practice, these inputs often originate in the browser, and enterprises lose visibility and control over what feeds their AI models. Similarly, software supply chain tools assess code and tampering during development, but miss that client-side execution evolves after deployment with third-party script updates, code injection from tag managers, AI-generated components, and more. The post-deployment risk surface remains unmanaged. Jscrambler enforces software integrity and data governance directly in the browser, safeguarding application logic, restricting data access, and preventing unauthorized data transmission in real time. 

“We scoured the globe looking for cybersecurity innovators that could make a huge difference and potentially help turn the tide against the exponential growth in cybercrime. Jscrambler is absolutely worthy of these coveted awards and consideration for deployment in your environment,” said Yan Ross, Global Editor of Cyber Defense Magazine.

See the full list of winners.


About Jscrambler

Jscrambler is the leader in Client-Side Security for the modern, composable web. 

It turns enterprise policy into enforceable control at the point where digital interactions are created — inside the browser.

As organizations increasingly build digital experiences through third-party software supply chains and AI-powered agents, sensitive data is now created directly in the browser — the point of creation for digital interactions — making it one of the enterprise’s most privileged yet least governed attack surfaces.

Jscrambler’s Client-Side Security Platform is powered by a Behavioral Enforcement Core that governs how application code, third-party scripts, and sensitive data behave at runtime. By enforcing software integrity and data governance directly in the browser, the platform ensures sensitive data and AI inputs are controlled according to enterprise policy at the point of creation — before they leave the client environment.

Trusted by leading global retailers, airlines, financial services providers, and healthcare organizations, Jscrambler provides the visibility and enforcement organizations need to stop client-side attacks, prevent data leakage, and maintain compliance with regulations including PCI DSS, GDPR, HIPAA, CCPA, and the EU AI Act.


About the Global InfoSec Awards

This is Cyber Defense Magazine’s fourteenth year of honoring InfoSec innovators from around the Globe. Our submission requirements are for any startup, early stage, later stage, or public companies in the INFORMATION SECURITY (INFOSEC) space that believe they have a unique and compelling value proposition for their product or service.


About the Judging

The judges are CISSP, FMDHS, CEH, certified security professionals who voted based on their independent review of the company’s submitted materials on the website of each submission, including but not limited to data sheets, white papers, product literature, and other market variables. CDM has a flexible philosophy to find more innovative players with new and unique technologies, rather than the one with the most customers or money in the bank. CDM is always asking “What’s Next?” so we are looking for best of breed, next generation InfoSec solutions.


About Cyber Defense Magazine

Cyber Defense Magazine is the premier source of cybersecurity news and information for InfoSec professionals in business and government. We are managed and published by and for ethical, honest, passionate information security professionals.

Our mission is to share cutting-edge knowledge, real-world stories, and awards on the best ideas, products, and services in the information technology industry.  We deliver electronic magazines every month online for free, and special editions exclusively for the RSAC Conferences. CDM is a proud member of the Cyber Defense Media Group.

Learn more about Cyber Defense Magazine and visit Cyber Defense Magazine or the Cyber Defense Radio to see and hear some of the most informative interviews of many of these winning company executives. Join a webinar and realize that infosec knowledge is power. 

Jscrambler Recognized for PCI Compliance and Client-Side Security Excellence in 2026 Globee® Awards for Cybersecurity

PORTO, Portugal – March 26, 2026 – Jscrambler, the pioneering Client-Side Security Platform for modern web applications, has been named a winner in the 22nd Annual 2026 Globee® Awards for Cybersecurity, a globally recognized program celebrating excellence in all areas of cybersecurity. Jscrambler received gold in the PCI (Payment Card Industry) Compliance category for the second consecutive year, and silver in the Client-Side Security category. These honors highlight the company’s groundbreaking contributions to digital security.

The browser is the new operational edge and one of the most powerful environments in the enterprise. Despite this, it is also one of the least governed. While existing security, identity, privacy, and compliance solutions and policies operate effectively across networks, cloud systems, and backend infrastructure, once code and data reach the browser, many protections fade. Jscrambler provides the missing control layer, protecting and controlling what happens inside the browser–safeguarding application logic, restricting data access, and preventing unauthorized data transmission in real time. 

Additionally, Jscrambler’s PCI DSS Quick Start Program and QSA Alliance Program provide a zero-friction path to achieve PCI DSS v4 compliance within one business day. Jscrambler’s PCI DSS Compliance solution also offers the industry’s first AI assistant to streamline PCI DSS script authorization workflows, supporting teams’ understanding, analysis, and informed authorization decisions about every script running on their payment pages. This is a fundamental shift in how merchants and service providers can achieve and maintain compliance while dramatically improving security assurance and analyst confidence.

“We’re grateful to the Globee Awards for once again honoring Jscrambler’s innovation and leadership in PCI Compliance and Client-Side Security,” said Rui Ribeiro, CEO and co-founder of Jscrambler. “Jscrambler is bringing enforceable control into browser execution. By enforcing policy where applications execute–inside the browser–Jscrambler helps organizations reduce client-side risk, prevent data leakage, protect digital trust, and easily achieve compliance.”

San Madan, President of the Globee Awards, commended this year’s winners: “Congratulations to the 2026 winners for their exceptional contributions to strengthening our digital world. Your innovation, dedication, and leadership continue to advance cybersecurity and inspire progress across industries. We are proud to recognize and celebrate your success.”

Winners were determined through a merit-based, data-driven evaluation process involving participation from experienced professionals across multiple industries worldwide. The evaluation approach is designed to provide a fair, transparent, and highly competitive assessment of entries. View the full list of 2026 judges.

Learn more about Jscrambler’s award-winning client-side security and compliance solutions. 

PCI Security Standards Council Appoints Jscrambler to Brazil Advisory Board For 2026-2027

PORTO, Portugal—February 12th, 2026 — Today, the PCI Security Standards Council (PCI SSC) announced that Jscrambler is one of 34 Brazilian payments leaders to serve on its 2026-2027 Brazil Regional Engagement Board. Jscrambler also currently serves on the PCI Security Standards Council (SSC) Board of Advisors.


Brazil Regional Engagement Board members act as advisors to the Council on payment security issues and challenges in the region, and as ambassadors for helping increase education and awareness of standards and best practices for securing payment data.


Companies serving on the 2026-2027 Brazil Regional Engagement Board represent leaders from all sectors in the Brazilian payments industry, including vendors, merchants, processors, service providers, banks, and industry associations. 


In addition to its work with the Council, Jscrambler continues to expand its comprehensive client-side protection and compliance platform, as well as PCI DSS solutions, designed to simplify ongoing script management, protection, and compliance. In October 2025, Jscrambler announced the industry’s first AI Assistant for PCI DSS script authorization workflows. The assistant delivers clear, transparent, and context-rich insights, along with expert recommendations, to enable prompt, confident script authorization decisions and justification.


Visit Jscrambler’s PCI DSS solutions for more information.


About Jscrambler

Jscrambler is the leader in Client-Side Protection and Compliance. Jscrambler is the first to merge advanced polymorphic JavaScript obfuscation with fine-grained third-party tag protection in a unified Client-Side Protection and Compliance Platform.

Jscrambler’s integrated solution ensures a robust defense against current and emerging client-side cyber threats, data leaks, misconfigurations, and IP theft, empowering software development and digital teams to innovate securely online with JavaScript.

Jscrambler’s Code Integrity product safeguards first-party JavaScript through state-of-the-art obfuscation and exclusive runtime protection. Jscrambler’s Webpage Integrity product mitigates threats and risks posed by third-party tags, all while ensuring compliance with PCI DSS v4. Jscrambler’s Iframe Integrity empowers PSPs to deliver seamless protection, PCI DSS compliance, and SAQ A eligibility to merchants.

With Jscrambler, businesses adopt a unified, future-proof client-side security policy, all while achieving compliance with emerging security standards. Customers include Fortune 500 companies, online retailers, airlines, media outlets, and financial services firms whose success depends on secure online engagement.

PCI Security Standards Council nomeia a Jscrambler para o Conselho Consultivo do Brasil para 2026-2027

PORTO, Portugal — 12 de fevereiro de 2026 — Hoje, o PCI Security Standards Council (PCI SSC) anunciou que a Jscrambler é uma das 34 empresas brasileiras líderes no setor de pagamentos a integrar o Conselho Consultivo Regional (Regional Engagement Board) para 2026-2027.

Os membros do Conselho Consultivo do Brasil atuam como consultores do Conselho em questões e desafios de segurança de pagamentos na região e como embaixadores para ajudar a aumentar a educação e a conscientização sobre padrões e melhores práticas para proteger dados de pagamentos.

As empresas que integram o Conselho Consultivo Regional do Brasil 2026-2027 representam todos os setores da indústria de pagamentos brasileira, incluindo fornecedores, comerciantes, processadores, prestadores de serviços, bancos e associações do setor.

Além de seu trabalho com o Conselho, a Jscrambler continua a expandir sua plataforma abrangente de proteção e conformidade do lado do cliente, bem como soluções PCI DSS, projetadas para simplificar o gerenciamento, a proteção e a conformidade contínuos de scripts. Em outubro de 2025, a Jscrambler anunciou o primeiro assistente de IA do setor para fluxos de trabalho de autorização de scripts PCI DSS. O assistente fornece insights claros, transparentes e ricos em contexto, juntamente com recomendações de especialistas, para permitir decisões e justificativas rápidas e confiáveis sobre a autorização de scripts.

Explore mais informações sobre as soluções PCI DSS do Jscrambler.

Sobre a Jscrambler


A Jscrambler é líder em proteção e conformidade do lado do cliente. A Jscrambler é a primeira a combinar ofuscação JavaScript polimórfica avançada com proteção refinada de tags de terceiros em uma plataforma unificada de proteção e conformidade do lado do cliente.

A solução integrada da Jscrambler garante uma defesa robusta contra ameaças cibernéticas atuais e emergentes do lado do cliente, vazamentos de dados, configurações incorretas e roubo de IP, capacitando as equipes de desenvolvimento de software e digitais a inovar com segurança online com JavaScript.

O produto Code Integrity da Jscrambler protege o JavaScript primário por meio de ofuscação de última geração e proteção exclusiva em tempo de execução. O produto Webpage Integrity da Jscrambler mitiga as ameaças e os riscos representados por tags de terceiros, ao mesmo tempo em que garante a conformidade com o PCI DSS v4. O Iframe Integrity da Jscrambler permite que os PSPs ofereçam proteção contínua, conformidade com o PCI DSS e elegibilidade para o SAQ A aos comerciantes.

Com o Jscrambler, as empresas adotam uma política de segurança unificada e preparada para o futuro do lado do cliente, ao mesmo tempo que alcançam a conformidade com os padrões de segurança emergentes. Os clientes incluem empresas da Fortune 500, varejistas online, companhias aéreas, meios de comunicação e empresas de serviços financeiros cujo sucesso depende do envolvimento online seguro.

Jscrambler Recognized in “The Rise of Web Application Protection Platforms” Research Report by Independent Research Firm

PORTO, Portugal – February 5, 2026Jscrambler, the pioneering platform for client-side protection and compliance, today announced its inclusion in the Forrester report, “The Rise of Web Application Protection Platforms.” Jscrambler is included as a specialized client-side protection solution provider, along with the unique benefits it offers over Web Application Protection Platforms (WAAP).


The Forrester report states that “As web application protection platforms come together, the decision to go with platform versus best of breed is not automatic.”


In fact, according to Forrester’s Security Survey, 2025, which asked security decision-makers who influence or make application security decisions about their application security programs, 43% said that they use best-of-breed tools.


For example, in “The Rise of Web Application Protection Platforms” report, several security pros stated, ‘While a platform was theoretically ideal, the individual components still must meet a quality baseline.”


“When businesses select consolidated platforms, many assume they are fully covered against all potential web risks. But as organizations face increasingly specialized and high-stakes security challenges, this assumption can leave them exposed,” said Rui Ribeiro, CEO and co-founder of Jscrambler. “That’s because while delivering convenience, consolidated application security tools lack the critical depth businesses require. Specialized offerings such as Jscrambler move beyond simple PCI DSS compliance, delivering client-side enforcement that ensures businesses have complete control over the flow of today’s most valuable currency —data.”


The “The Rise of Web Application Protection Platforms” report includes examples in which specialized client-side protection solutions are preferred. Examples include:

  • A security leader at a hospitality organization states, “we have vendors that were happy to talk to us about solutions that could make compliance easier. But my primary driver was something that directly met the PCI requirements.”

  • “An enterprise architect at a global telecommunications provider pointed out that PCI was a very specific need, and that they needed a solution to address it deeply, rather than a more general-purpose capability.”


Access a complimentary copy of the Forrester report, “The Rise of Web Application Protection Platforms”.

For additional insights, attend the upcoming Jscrambler webinar on selecting specialists or platforms for client-side protection. The panel will feature Jscrambler customers along with Sandy Carielli, Vice President, Principal Analyst at Forrester, on March 5th at 11 am ET | 4 pm UK. 

Visit our website to learn more about Jscrambler’s Client-Side Protection and Compliance platform and its Fast-Track PCI DSS Compliance offering.


About Jscrambler

Jscrambler is the leader in Client-Side Protection and Compliance. Jscrambler is the first to merge advanced polymorphic JavaScript obfuscation with fine-grained third-party tag protection in a unified Client-Side Protection and Compliance Platform.


Jscrambler’s integrated solution ensures a robust defense against current and emerging client-side cyber threats, data leaks, misconfigurations, and IP theft, empowering software development and digital teams to innovate securely online with JavaScript.


Jscrambler’s Code Integrity product safeguards first-party JavaScript through state-of-the-art obfuscation and exclusive runtime protection. Jscrambler’s Webpage Integrity product mitigates threats and risks posed by third-party tags, all while ensuring compliance with PCI DSS v4. Jscrambler’s Iframe Integrity empowers PSPs to deliver seamless protection, PCI DSS compliance, and SAQ A eligibility to merchants.


With Jscrambler, businesses adopt a unified, future-proof client-side security policy, all while achieving compliance with emerging security standards. Customers include Fortune 500 companies, online retailers, airlines, media outlets, and financial services firms whose success depends on secure online engagement.


CONTACT:

Doug Fraim

Guyer Group for Jscrambler

Jscrambler Named Winner of the Coveted Top InfoSec Innovator Awards for 2025

Jscrambler Named Most Innovative Client-Side Protection Solution In 13th Cyber Defense Magazine’s Annual InfoSec Awards during CyberDefenseCon 2025  


ORLANDO, Fla.–October 29, 2025 –Jscrambler, the pioneering platform for client-side protection and compliance, is proud to announce it has been named winner in the Most Innovative Client-Side Protection category in the 2025 Top Infosec Innovator Awards from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine.


“We’re thrilled to once again be included among the winners of the coveted Cyber Defense Awards,” said Rui Ribeiro, CEO, Jscrambler. “We couldn’t be more pleased that the panel of judges, including infosec experts from around the globe, has recognized Jscrambler’s continued innovation and category leadership in client-side protection. 


“We scoured the globe looking for cybersecurity innovators that could make a huge difference and potentially help turn the tide against the exponential growth in cybercrime. Jscrambler is worthy of being named a winner in these coveted awards and consideration for deployment in your environment,” said Yan Ross, Editor of Cyber Defense Magazine.


View the full list of the Top InfoSec Innovators for 2025.


About Jscrambler


Jscrambler is the leader in Client-Side Protection and Compliance. Jscrambler is the first to merge advanced polymorphic JavaScript obfuscation with fine-grained third-party tag protection in a unified Client-Side Protection and Compliance Platform.

Jscrambler’s integrated solution ensures a robust defense against current and emerging client-side cyber threats, data leaks, misconfigurations, and IP theft, empowering software development and digital teams to innovate securely online with JavaScript.

Jscrambler’s Code Integrity product safeguards first-party JavaScript through state-of-the-art obfuscation and exclusive runtime protection. Jscrambler’s Webpage Integrity product mitigates threats and risks posed by third-party tags, all while ensuring compliance with PCI DSS v4. Jscrambler’s Iframe Integrity empowers PSPs to deliver seamless protection, PCI DSS compliance, and SAQ A eligibility to merchants.

With Jscrambler, businesses adopt a unified, future-proof client-side security policy, all while achieving compliance with emerging security standards. Customers include Fortune 500 companies, online retailers, airlines, media outlets, and financial services firms whose success depends on secure online engagement.


About Cyber Defense Awards

This is Cyber Defense Magazine’s 13th year of honoring cybersecurity innovators, in this case the Top Global CISOs for 2025, on our Cyber Defense Awards platform. In this competition, judges for these and other prestigious awards includes cybersecurity industry veterans, trailblazers and market makers Ron Gula of Gula Tech Adventures, Gary Miliefsky of CDMG, Dr. Lindsey Polley de Lopez of VentureScope, Katie Gray of In-Q-Tel, Robert R. Ackerman Jr. of DataTribe, Dino Boukouris of AltitudeCyber and with much appreciation to emeritus judges Robert Herjavec of Cyderes, Dr. Peter Stephenson of CDMG and David DeWalt of NightDragon. 

Find the Top InfoSec Innovators for 2025 and download The Black Unicorn Report for 2025.

About Cyber Defense Magazine 

Cyber Defense Magazine was founded in 2012 by Gary S. Miliefsky, globally recognized cyber security thought leader, inventor and entrepreneur and continues to be the premier source of IT Security information. We are managed and published by and for ethical, honest, passionate information security professionals.

Our mission is to share cutting-edge knowledge, real-world stories and awards on the best ideas, products and services in the information technology industry. We deliver electronic magazines every month online for free, and limited special editions exclusively for the RSA, BlackHat and Cyber Defense Conferences. Cyber Defense Magazine is a proud member of the Cyber Defense Media Group.


Jscrambler Announces Industry’s First AI Assistant to Streamline PCI DSS Script Authorization Workflows

New AI Innovation Combines Risk-based Insights, Actionable Recommendations, Instant Justifications, and Interactive Chat to Accelerate Compliance with PCI DSS v4 Anti-Skimming Requirements

PORTO, Portugal – October 14, 2025 — Jscrambler, the pioneering platform for client-side protection and compliance, today announced the industry’s first AI Assistant for PCI DSS script authorization workflows that delivers clear, transparent, and context-rich insights along with expert recommendations to enable prompt and confident script authorization decisions and justification. 

PCI DSS v4 requirements 6.4.3 and 11.6.1 mandate the inventorying, authorizing, and monitoring of scripts on payment pages, along with tamper-detection mechanisms to combat e-skimming threats. Despite becoming mandatory on March 31, adoption of these requirements has varied widely. To date, many organizations are investing in client-side protection, while others have relied on non-comprehensive solutions, manual approaches, basic Content Security Policies (CSP), or ultimately delayed full implementation until their next annual assessment. 

“With low overall compliance rates and frequent complaints about the cost and complexity of existing tools, it’s clear that businesses need help streamlining PCI DSS compliance, and our new AI Assistant does just that,” said Pedro Fortuna, CTO and co-founder of Jscrambler. “To drive adoption, the next wave of client-side protection must be powered by intelligence, not manual oversight. By tapping into the power of AI, we are closing critical gaps in manual and legacy script authorization systems, particularly as regulatory scrutiny intensifies and skimming threats evolve.”

The AI-assisted script authorization enhancements to the Jscrambler PCI DSS Solution embed intelligence into compliance workflows, providing more informed script authorization, faster decision-making, and accelerated compliance.

The new workflow includes key features designed to reduce time and effort, minimize human error, decrease administrative overhead, and strengthen overall PCI DSS compliance assurance. As a result, organizations can onboard vendors and adapt to payment ecosystem changes faster, more securely, and with greater confidence, while enhancing security by proactively detecting and blocking suspicious behaviors. 

New AI Assistant opt-in features include: 

  • AI Insights: Obtain a concise, risk-based summary of each script’s purpose, behavior, and reputation. The model distills Jscrambler’s intelligence about each script vendor. 

  • Actionable Recommendations: Receive clear, actionable Approve, Block, or Restrict recommendations based on Jscrambler’s foundational expertise and experience in helping organizations protect customer payment data. 

  • Instant Justifications: Generate quick and accurate justification text for faster, consistent, and high-quality compliance workflows with a greater long-term impact.

  • Interactive AI Chat: Access real-time interaction and correspondence to support decision-making while answering risk-based approval questions as they arise.


Jscrambler’s new AI Assistant is now available as part of its PCI DSS solution. To learn more, visit Jscrambler at booth #17 at the PCI SSC Europe Community Meeting for a live demonstration. Further details are available in the launch blog by Jscrambler CTO Pedro Fortuna, “Jscrambler Launches the First AI Assistant for PCI DSS Script Authorization Workflows.”