PaymentGuard · PCI-DSS v4.0.1 Requirements 6.4.3 and 11.6.1

Monitor Every Script
Across Your Payment Pages
And Mobile Apps.
Prove It On Demand.

Payment pages change constantly, making PCI DSS 4.0.1 compliance difficult to maintain manually. PaymentGuard continuously inventories and monitors the behavior of every script running across your payment pages and mobile apps, detects unauthorized changes in real time, and automatically generates the evidence required for PCI DSS Requirements 6.4.3 and 11.6.1.

  • •••• •••• •••• 4242
    Scanning payment page — LIVE
    checkout.example.com
    Enterprise Plan
    Secure
    Card number •••• •••• •••• 4242
    Expiry 09 / 28
    CVV •••
    Pay securely
    Run-Time ScriptsStatus
    stripe.jsAuthorized
    gtm.jsAuthorized
    pixel-new.jsChanged
  • Continuous audit
    94/100 PCI Score
    Evidence package ready
    Req 6.4.3 Req 11.6.1 SAQ A-EP SAQ D
    QSA Evidence Report
    PCI DSS 4.0.1 package
    Ready
    Script Inventory Generating Complete
    Integrity Hashes Generating Complete
    Change Audit Log Generating Complete
    Vendor Justification Generating Complete
    SAQ A-EP Package Generating Complete
    Export for QSA

Trusted by the world's most recognized digital brands

Reddit Instacart Xerox Forbes Gusto Aristocrat Newegg Bolt

The 6.4.3 And 11.6.1 Controls, Done For You

Both requirements are ongoing obligations. Neither is satisfied by a scan you ran last quarter.

What the requirement asksManage all payment page scripts that are loaded and executed in the consumer's browser. Authorize each script, assure its integrity, and maintain a written inventory with business justification.
  • Automatic discovery of every executing script, including scripts loaded dynamically at runtime and scripts pulled in by other scripts
  • An authorization decision recorded per script, with the business justification kept alongside it
  • Integrity verification, so a change on a third-party CDN you do not control does not pass unnoticed
  • A written inventory that stays current on its own rather than being rebuilt before each assessment
What the requirement asksDeploy a change and tamper-detection mechanism to alert personnel to unauthorized modification of the HTTP headers and page content received by the consumer browser, and evaluate at least weekly, or at a frequency defined by your risk analysis.
  • Continuous monitoring of page content and HTTP security headers
  • Alerting when an unauthorized modification appears, so response time is measured in minutes
  • Configurable evaluation frequency, from hourly through weekly, aligned to your risk analysis
  • A dated record of every evaluation, whether or not it found anything
What your assessor actually asksNot "did you have a problem?" Every payment page has had a problem. The question is what did you do about it, and can you show me?
  • Continuous, timestamped scan history with no gaps to explain
  • Reporting laid out for the assessment rather than exported raw and interpreted verbally
  • The decision trail: what was authorized, by whom, and on what basis
  • Evidence produced as a by-product of running the control, not reconstructed before an audit
Scan Your Checkout Page Free

Six PaymentGuard Capabilities

Automatic Script Inventory

Every script executing on your payment pages, discovered and catalogued, including the ones no one on your team put there.

Real-Time Change Detection

Content and HTTP header modification surfaced as it happens, with alerting, rather than at the next scan interval.

Integrity Assurance

Authorized scripts verified as still being the scripts you authorized, including changes made upstream at the vendor.

Assessor-Ready Documentation

Inventory, justification and evaluation history, laid out for the people who assess you.

Runtime Policy Enforcement

Optional. Control which scripts may touch card, email and password fields. Block everything outside policy by default.

Estate-Wide Coverage

Built for organizations with many payment pages across many brands, platforms and acquisitions, not one tidy domain.

Four Steps to Continuous PCI DSS Compliance

Discover

AI agents automatically inventory all scripts, tags, and data flows on payment pages across your web and mobile properties, establishing your authorized baseline for PCI DSS 6.4.3 compliance.

Authorize & Monitor

PaymentGuard continuously validates that only authorized scripts are present on payment pages and monitors for any unauthorized additions, modifications, or behavioral changes per PCI DSS 11.6.1.

Detect & Block

Real-time behavioral analysis detects data skimming, formjacking, and cardholder data exfiltration attempts, and blocks threats at the digital experience layer before sensitive data is exposed.

Prove

Continuous audit evidence, like script inventories, change logs, and compliance enforcement records, is automatically generated and delivered to your GRC and QSA workflows, every day.

PaymentGuard For Merchants, PSPs, ISAs, And QSAs

One deployment aligns processors and merchants around the same two controls, 6.4.3 and 11.6.1, so everyone in the chain works from the same evidence.

Closing the SAQ A-EP and SAQ D gap

The scripts on your checkout are rarely all yours. Tag managers, analytics, chat widgets, personalization and whatever marketing added last sprint all execute in the same browser as your payment form. PaymentGuard gives you the inventory, the authorization record and the weekly evaluation evidence the questionnaire expects, without a manual review cycle before each submission.

Scale across every merchant page you touch

Processors carry the obligation across a large, changing surface. PaymentGuard is built to run against many properties at once, with per-property reporting and a consolidated view of what changed where, so scope grows without the review burden growing with it.

iFrame and hosted payment page protection

A hosted payment page reduces your scope. It does not remove the parent page from the picture, and 6.4.3 still reaches the scripts that surround it. PaymentGuard covers both sides of that boundary so the assessment does not turn into an argument about it.

Evidence you can assess without a screen share

Structured, dated, complete reporting built for review: inventory, justification, evaluation frequency and change history in one place, so the assessment conversation starts from the record rather than from a raw export and a verbal explanation.

Don't Take Our Word For It.

"They solved my 6.4.3 and 11.6.1 nightmares."

We spent months searching for a solution to meet these PCI requirements. We found a number of other vendors who did pieces of it. None had the ease of implementation we were looking for. Then we found Feroot. It scanned our pages with no overhead.

Verified User
★★★★★
High PerformerBest SupportEasiest To Do Business WithHighest User AdoptionTop 50

"Quick and easy implementation, plus dedicated support."

Feroot met PCI DSS v4.0.1 requirements quickly and easily, with very little effort on my part, always a plus on a small team. The team built a genuine relationship with me and clearly cares how the product runs.

Verified User
★★★★★
High PerformerBest SupportEasiest To Do Business WithHighest User AdoptionTop 50

"Feroot support is top notch."

As the person in Feroot every day, I love how easy it is to navigate. I also appreciate the consultative support. After one quality walkthrough, implementation was straightforward.

Verified User
★★★★★
High PerformerBest SupportEasiest To Do Business WithHighest User AdoptionTop 50

"Our payment pages stay compliant, and audits are painless."

Continuous monitoring of payment-page scripts means nothing slips through between audits. What used to be a scramble is now business as usual.

Chief Security Officer
★★★★★
High PerformerBest SupportEasiest To Do Business WithHighest User AdoptionTop 50

Every Payment Channel. Every Session. Always Protected.

Websites

Full PCI DSS 6.4.3 and 11.6.1 enforcement across all web checkout and payment pages

Mobile Apps

Cardholder data protection and compliance enforcement across iOS and Android payment flows

Merchant & Vendor Ecosystems

Extend protection and compliance enforcement to external merchants, vendors, and partners processing payment data

Three Ways Teams Start With PaymentGuard

The fastest paths to closing your runtime PCI gap. Most teams adopt PaymentGuard to clear one specific 6.4.3 / 11.6.1 hurdle, then extend the same deployment outward.

Merchants Closing The SAQ A-EP / SAQ D Gap

Inventory and justify every payment-page script, detect tampering, and produce the evidence your self-assessment or QSA review now requires under 4.0.1.

See your use case in a demo → Or scan your checkout page free →

Payment Processors And Service Providers, At Scale

Roll the same script tag across thousands of customer and third-party payment pages, with horizontal visibility for your central team and a scoped view for each customer or business unit.

See your use case in a demo →

IFrame And Hosted-Payment-Page Protection

Monitor PSP iFrames and hosted checkout for skimming, formjacking, and exfiltration, and show the embedded payment surface stays clean.

See your use case in a demo →

What Sets Feroot Apart For PCI

Built for runtime PCI from the browser up, not a network tool retrofitted to checkout. PaymentGuard runs where card-skimming actually happens: in the browser, in the scripts your network tooling never sees.

Agentic AI That Handles The Repetitive Work At Scale

Feroot's capabilities run as AI agents: they discover scripts, maintain the inventory, watch for tampering, and assemble evidence continuously, across one checkout or many payment pages, so your team reviews exceptions instead of building spreadsheets.

Web And Native Mobile App Coverage, One Platform

Card-skimming isn't limited to the browser. PaymentGuard extends the same script inventory, tamper detection, and audit evidence to native iOS and Android checkout flows, so mobile app payment pages meet 6.4.3 and 11.6.1 right alongside your website.

Browser-Extension Scripts Filtered Out Of PCI Scope

Scripts loaded by a visitor's own browser extensions aren't the merchant's responsibility under PCI. Feroot identifies these visitor-controlled scripts and excludes them from your PCI report automatically, so your inventory, and your assessor, see only the scripts that are actually in scope.

Enterprise-Grade, Multi-Brand Visibility

Operate across many business units and brands with horizontal visibility for the central team and scoped access per unit. Enterprise teams can oversee hundreds of sites across dozens of business units while each unit sees only its own assets.

Compare PaymentGuard for your environment
  • Slack logo
  • PagerDuty logo
  • Splunk logo
  • ServiceNow logo
  • Logz.io logo
  • Webhooks integration services logo
  • Jira Software logo
  • Opsgenie logo
  • Sumo Logic logo
  • JupiterOne cybersecurity asset management logo
  • Datadog logo
  • Microsoft Teams logo
  • Amazon CloudWatch logo
  • AWS CloudWatch Logs logo
  • API configuration settings icon

Connected to Your PCI & Security Stack

PaymentGuard extends PCI DSS compliance telemetry, script inventory data, and tamper detection evidence into your existing SIEM and GRC platforms, delivering real-time alerting and reporting to SecOps and compliance workflows for fast remediation. Proactive risk scoring extends your payment security risk profile to the GRC tools your teams already use.

Complete the Platform

PaymentGuard works seamlessly alongside DXComply and DXSecure as part of the Feroot Digital User Experience Security and Compliance Platform.

DXComply

Automate consent auditing & privacy compliance

Automate continuous consent auditing and compliance enforcement across your websites and mobile apps, aligned to GDPR, CCPA, HIPAA, and 50+ global regulations.

Explore DXComply →
DXSecure

Always-on threat detection & blocking

Always-on detection and blocking of malicious scripts, data skimming, formjacking, and unauthorized script execution at the browser and mobile app layer.

Explore DXSecure →

FREE DOWNLOAD:

Get the Feroot PaymentGuard Compliance Report: a practical walkthrough of the runtime requirements in PCI DSS 4.0.1, what your QSA will ask for, and how Feroot produces the script inventory, tamper detection, and audit evidence automatically.


PaymentGuard Live Demo

PCI DSS 4.0.1 Requirements 6.4.3 And 11.6.1: Handled, On Every Payment Page.

Automate the run-time script inventory, tamper detection, and audit evidence your assessment requires. Deploy once; scale from one checkout to many payment pages.