Script Integrity Monitor
Automates PCI DSS v4.0.1 compliance. Protects your payment pages against Magecart.
CAEV-SIM automatically monitors all scripts loaded on your payment pages. It uses Playwright (Chromium) to scan your URLs like a real visitor, captures each script, calculates its SHA-384 fingerprint, and alerts you in real-time if anything changes or an unauthorized script appears.
This is exactly what PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 demand. Without CAEV-SIM, you would have to do it manually: review every script, document every change, and generate evidence for the auditor. With CAEV-SIM, everything is automatic.
Unique cryptographic fingerprint per script. Filtering, searching, individual authorization with PCI justification.
CSP, HSTS, X-Frame-Options with score 0-100 per site. PCI 11.6.1 compliance.
Docker without network, limited memory, read-only. 20 anti-malware patterns.
VirusTotal, Shodan, CISA KEV, APT Groups. All free, correlated with your data.
Formal document for auditor in 1 click. PDF Executive 360 for management.
Email, Slack, Discord, Teams. Workflow: detect, investigate, resolve.
Every script change recorded with old hash, new hash, timestamp. Full traceability.
Documented justification per script. Complies with 6.4.3: inventory with owner and purpose.
Automatic 02:00 UTC. 7-day rotation. No manual intervention.
Nothing to install on your sites. Scanning is external, like a visitor.
Everything in your infrastructure. No payment data sent to third parties.
Installation. Docker or VM, your choice. SaaS available.
QSA report ready for your auditor. Evidence per script.
Isolated sandbox detects skimming before fraud occurs.
One dashboard for all your companies. Selector and whitelist per tenant.
Workers horizontally. From 5 to 5000 sites without changes.
72 documented REST endpoints. Integrates with your ecosystem.
CAEV-SIM is also for you. Your scripts security shouldn't depend on a regulation.
Digital skimming doesn't care if you have PCI or not. If you process payments, you are a target.
Do you know how many scripts your pages load? Most don't. CAEV-SIM shows you every single one.
A CDN updates, a script changes without notice. You find out instantly.
Log of all scripts on your sites. For development, security, and compliance.
Magecart costs millions. CAEV-SIM costs less than a single incident.
If you ever need PCI, you already have months of evidence. Get ahead.
300 KB download. ./install.sh. 4 questions. 3 minutes.
Import into VirtualBox. Power on. License and credentials. 5 minutes.
Register, pay with card, access instantly. Nothing to install.