Jscrambler

Jscrambler

Real-time client-side security preventing Magecart

Overview

Jscrambler provides security for web and mobile apps by preventing Magecart and other client-side threats. It monitors and controls client-side code and network activity in real time, offering an inventory, live detection feed, and an alert explorer, with Code Integrity and behavior-based protections that block malicious scripts. It differs from many security vendors by focusing specifically on client-side protection and combining active enforcement with visibility, plus partnerships with Verimatrix and Intertrust that bolster credibility. Its goal is to help organizations protect digital assets and user data by stopping harmful client-side behavior and ensuring compliance with data protection rules.

About Jscrambler

Simplify's Rating
Not yet rated

We're working on gathering enough insights on this company, check back soon!

Industries

Company Size

51-200

Company Stage

Growth Equity (Venture Capital)

Total Funding

$22.5M

Headquarters

San Francisco, California

Founded

2014

Get referred to Jscrambler

See people who can refer or advise you

Funding

Total Funding

$22.5M

Above

Industry Average

Funded Over

3 Rounds

Growth Equity VC funding comparison data is currently unavailable. We're working to provide this information soon!
Growth Equity VC Funding Comparison
Coming Soon

Benefits

Flexible Work Hours

Training Programs

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

3%

1 year growth

0%

2 year growth

-1%
Australian Associated Press
Jul 30th, 2026
Jscrambler launches Unified Client-Side Security Platform for the AI era.

Jscrambler launches Unified Client-Side Security Platform for the AI era. new product July 30, 2026 First platform to unify software integrity and data governance at browser runtime, helping enterprises continuously enforce security against AI-powered threats and data harvesting risks PORTO, Portugal, July 30, 2026 /PRNewswire/ - Jscrambler, the Client-Side Security Platform for the modern enterprise, today announced the launch of its Unified Client-Side Security Platform, introducing a new approach to securing applications and customer data where AI-powered risks increasingly operate: inside the browser. Key Highlights * Jscrambler launched a Unified Client-Side Security Platform that merges software integrity and data governance to close the enforcement gap at browser runtime. * The platform is built on a proprietary Behavioral Enforcement Core that gives AppSec and data governance teams a single deployment and enforcement architecture. * The platform is backed by new browser security research, showing how AI is accelerating client-side software and data risks while exposing the need for continuous browser runtime enforcement. AI is fundamentally changing how software is attacked and how customer data is collected inside the browser. As organizations rapidly adopt AI-powered applications, agents, and third-party services, existing security architectures built around isolated application security, privacy, and governance tools are no longer sufficient. Jscrambler is the first Client-Side Security Platform to unify software integrity and data governance through a common browser runtime architecture, enabling enterprises to continuously enforce security where applications execute and customer data is created. "AI didn't create browser risk - it dramatically accelerated it," said Rui Ribeiro, CEO and Co-Founder of Jscrambler. "Today, software compromise and AI-driven data harvesting occur simultaneously inside the browser, yet most security architectures still treat them as separate problems. Our Unified Client-Side Security Platform changes that by bringing software integrity and data governance together through a single runtime enforcement architecture. Organizations can now continuously secure multiple initiatives through one platform instead of managing disconnected tools." For years, application security teams have focused on protecting software while privacy, governance, and compliance teams concentrated on securing customer data. While this approach was sufficient at one point in time, AI has exposed a critical blind spot inside the browser where applications execute, third-party code runs, AI agents operate, and sensitive customer information is assembled. This convergence is forcing security leaders to rethink how browser security is managed. Rather than deploying isolated point solutions, enterprises need a unified platform capable of protecting software integrity, governing customer data, detecting evolving threats, and enforcing policy continuously throughout the browser runtime. A Unified Platform for Enterprise Security Initiatives The Jscrambler Unified Client-Side Security Platform addresses this new reality by enabling organizations to extend critical security initiatives into the browser through a single runtime architecture. This architecture provides: * LLM-Resilient Code Protection: Defends application code against AI-powered attacks at execution time * Software Supply Chain Security: Provides runtime enforcement against third-party script risks that static pipeline scanners cannot see * AI Data Governance: Detects and controls AI-powered data harvesting at the point of data creation * Data Privacy and Compliance: Extends beyond consent management with runtime enforcement against unauthorized data collection * Fraud and Abuse Prevention: Detects and blocks fraud, automation, and identity abuse at runtime * Threat Detection & Response: Extends active threat hunting, real-time telemetry, and incident response into the browser runtime to neutralize client-side threats * Compliance Enforcement: Features automated technical proof for PCI DSS v4, GDPR, EU AI Act, HIPAA, and CCPA Organizations can deploy individual solutions based on their priorities or expand across initiatives over time, giving CISOs, security architects, AppSec, Security Engineering, Privacy, GRC, and SOC teams shared visibility, continuous runtime enforcement, and a common operational foundation through a single platform. Powered by the Behavioral Enforcement Core Every solution is powered by Jscrambler's proprietary Behavioral Enforcement Core, the platform's centralized runtime engine that continuously monitors, analyzes, and enforces browser behavior through a single deployment, turning enterprise policy into active protection at the point of data creation. Purpose-built for the AI era, the Behavioral Enforcement Core introduces new runtime enforcement capabilities spanning the enterprise security lifecycle. These capabilities include: * Identify: AI-powered script discovery and access mapping that continuously inventories AI agents and third-party scripts accessing sensitive customer data * Protect: LLM-resilient code hardening and proactive AI agent controls that prevent code manipulation, unauthorized runtime access, and AI-powered data harvesting * Detect: Behavioral AI script drift detection that identifies execution anomalies and emerging client-side threats * Respond: AI browser telemetry workflows that reconstruct incidents and accelerate investigations for security operations teams * Comply: Real-time vendor risk assessments and browser telemetry that continuously validate third-party behavior while providing technical evidence for regulatory requirements Research Highlights the Growing Need for Runtime Enforcement The platform launch follows Jscrambler's latest browser security research, Beyond the Vault: What Banking Sites Quietly Share Before You Ever Log In, which uncovered widespread unauthorized third-party tracking and AI-enabled data collection occurring before user consent across leading financial institutions. The findings reinforce a growing industry challenge: software integrity and data governance can no longer be managed separately once applications reach the browser. The Jscrambler Unified Client-Side Security Platform is now available to enterprise organizations worldwide. About Jscrambler Jscrambler is the Client-Side Security Platform for the modern enterprise. The first vendor to unify software integrity and data governance at browser runtime, Jscrambler's Behavioral Enforcement Core gives AppSec and data governance teams a single control plane to protect, enforce, and comply - from one deployment. Built on 15 years of browser runtime expertise and proprietary research, Jscrambler serves Fortune 500 companies, financial institutions, airlines, online retailers, and media organizations whose success depends on what happens in the browser. Learn more at jscrambler.com. AAPR aggregates press releases and media statements from around the world to assist its news partners with identifying and creating timely and relevant news. All of the press releases published on this website are third-party content and AAP was not involved in the creation of it. Read the full terms.

News4Hackers
Jul 14th, 2026
Security alert: multiple Jscrambler packages compromised in supply chain attack.

Security alert: multiple Jscrambler packages compromised in supply chain attack. Post Views: 15 A series of malicious iterations of Jscrambler's NPM package were released over the weekend as part of a supply chain attack leveraging stolen credentials. Attack details. The NPM package is integral to Jscrambler Code Integrity, a JavaScript protection tool designed to make web and mobile applications resistant to tampering. The breach began on July 11 when an adversary exploited NPM publishing credentials to deploy a modified version of the package. This version included a preinstall hook intended to deploy malicious binaries during installation. Compromise timeline. Jscrambler addressed the initial compromise, but the threat actor continued to release additional malicious variants, including versions 8.16, 8.17, 8.18, and 8.20. The first unaffected version, 8.22, was later published. Malicious components. The compromised packages contained a preinstall hook, two new files in the dist/ directory (setup.js and intro.js), and platform-specific binaries targeting Linux, macOS, and Windows. During installation, the hook triggers the execution of setup.js, which loads and runs a binary from intro.js. Impact on related projects. Due to the NPM library's role as a dependency, related projects such as Jscrambler-webpack-plugin 8.6.2, gulp-Jscrambler 8.6.2, grunt-Jscrambler 8.5.2, and Jscrambler-metro-plugin 9.0.2 were also impacted. Technical analysis. According to supply chain security firm Socket, the binaries, written in Rust, function as information stealers, extracting credentials, secrets, cryptocurrency wallets, seed phrases, AI coding assistant data, cloud configurations, messaging app data, browser information, Steam sessions, and OS keyring entries. The malware also attempts to escalate privileges, establish persistence, and conduct host reconnaissance. Data exfiltration occurs via TLS using the rustls library, likely directed to a command-and-control server. Additionally, the malware uses stolen credentials to query cloud and orchestration APIs. Response and mitigation. Jscrambler confirmed that the attacker accessed the NPM publishing credentials and stated that all relevant credentials, passwords, and secrets have been revoked and replaced. The company added enhanced security measures to its publishing process as the investigation continues. Recommendations. Users are urged to uninstall affected Jscrambler NPM package versions, perform system malware scans, and rotate all credentials, tokens, and API keys. Conclusion. The incident highlights vulnerabilities in software supply chains, emphasizing the need for rigorous credential management and continuous monitoring of dependencies. Organizations relying on Jscrambler products are advised to review their environments for potential compromises and implement mitigation strategies promptly.

PR Newswire
May 13th, 2026
Jscrambler appoints Sean O'Leary as VP of global sales to drive client-side security expansion

Jscrambler, a client-side security platform based in Porto, Portugal, has appointed Sean O'Leary as Vice President of Global Sales. O'Leary will oversee sales, alliances, partnerships and technical pre-sales as the company addresses growing demand for browser-based security solutions. The appointment comes as organisations face increased client-side vulnerabilities. Modern digital experiences rely on numerous third-party components assembled in real time, creating significant security gaps. Jscrambler's platform enforces security policies directly within browser runtime, protecting application logic and preventing unauthorised data transmission. O'Leary brings extensive cybersecurity sales leadership experience from previous roles at Vendict, CYE and BitSight. The company serves major global retailers, airlines, financial services and healthcare organisations, helping them comply with PCI DSS, GDPR, HIPAA and CCPA regulations.

JScrambler
Mar 26th, 2026
Jscrambler recognized for PCI Compliance and Client-Side Security excellence in 2026 Globee(R) Awards for Cybersecurity.

Jscrambler recognized for PCI Compliance and Client-Side Security excellence in 2026 Globee(R) Awards for Cybersecurity. PORTO, Portugal - March 26, 2026 - Jscrambler, the pioneering Client-Side Security Platform for modern web applications, has been named a winner in the 22nd Annual 2026 Globee(R) Awards for Cybersecurity, a globally recognized program celebrating excellence in all areas of cybersecurity. Jscrambler received gold in the PCI (Payment Card Industry) Compliance category for the second consecutive year, and silver in the Client-Side Security category. These honors highlight the company's groundbreaking contributions to digital security. The browser is the new operational edge and one of the most powerful environments in the enterprise. Despite this, it is also one of the least governed. While existing security, identity, privacy, and compliance solutions and policies operate effectively across networks, cloud systems, and backend infrastructure, once code and data reach the browser, many protections fade. Jscrambler provides the missing control layer, protecting and controlling what happens inside the browser-safeguarding application logic, restricting data access, and preventing unauthorized data transmission in real time. Additionally, Jscrambler's PCI DSS Quick Start Program and QSA Alliance Program provide a zero-friction path to achieve PCI DSS v4 compliance within one business day. Jscrambler's PCI DSS Compliance solution also offers the industry's first AI assistant to streamline PCI DSS script authorization workflows, supporting teams' understanding, analysis, and informed authorization decisions about every script running on their payment pages. This is a fundamental shift in how merchants and service providers can achieve and maintain compliance while dramatically improving security assurance and analyst confidence. "We're grateful to the Globee Awards for once again honoring Jscrambler's innovation and leadership in PCI Compliance and Client-Side Security," said Rui Ribeiro, CEO and co-founder of Jscrambler. "Jscrambler is bringing enforceable control into browser execution. By enforcing policy where applications execute-inside the browser-Jscrambler helps organizations reduce client-side risk, prevent data leakage, protect digital trust, and easily achieve compliance." San Madan, President of the Globee Awards, commended this year's winners: "Congratulations to the 2026 winners for their exceptional contributions to strengthening our digital world. Your innovation, dedication, and leadership continue to advance cybersecurity and inspire progress across industries. We are proud to recognize and celebrate your success." Winners were determined through a merit-based, data-driven evaluation process involving participation from experienced professionals across multiple industries worldwide. The evaluation approach is designed to provide a fair, transparent, and highly competitive assessment of entries. View the full list of 2026 judges. Learn more about Jscrambler's award-winning client-side security and compliance solutions.

The Manila Times
Oct 14th, 2025
Jscrambler Announces Industry's First AI Assistant to Streamline PCI DSS Script Authorization Workflows

Jscrambler announces industry's First AI Assistant to streamline PCI DSS Script Authorization Workflows. PORTO, Portugal, Oct. 14, 2025 /PRNewswire/ - Jscrambler, the pioneering platform for client-side protection and compliance, today announced the industry's first AI Assistant for PCI DSS script authorization workflows that delivers clear, transparent, and context-rich insights along with expert recommendations to enable prompt and confident script authorization decisions and justification. PCI DSS v4 requirements 6.4.3 and 11.6.1 mandate the inventorying, authorizing, and monitoring of scripts on payment pages, along with tamper-detection mechanisms to combat e-skimming threats. Despite becoming mandatory on March 31, adoption of these requirements has varied widely. To date, many organizations are investing in client-side protection, while others have relied on non-comprehensive solutions, manual approaches, basic Content Security Policies (CSP), or ultimately delayed full implementation until their next annual assessment. "With low overall compliance rates and frequent complaints about the cost and complexity of existing tools, it's clear that businesses need help streamlining PCI DSS compliance, and our new AI Assistant does just that," said Pedro Fortuna, CTO and co-founder of Jscrambler. "To drive adoption, the next wave of client-side protection must be powered by intelligence, not manual oversight. By tapping into the power of AI, we are closing critical gaps in manual and legacy script authorization systems, particularly as regulatory scrutiny intensifies and skimming threats evolve." The AI-assisted script authorization enhancements to the Jscrambler PCI DSS Solution embed intelligence into compliance workflows, providing more informed script authorization, faster decision-making, and accelerated compliance. The new workflow includes key features designed to reduce time and effort, minimize human error, decrease administrative overhead, and strengthen overall PCI DSS compliance assurance. As a result, organizations can onboard vendors and adapt to payment ecosystem changes faster, more securely, and with greater confidence, while enhancing security by proactively detecting and blocking suspicious behaviors. * AI Insights: Obtain a concise, risk-based summary of each script's purpose, behavior, and reputation. The model distills Jscrambler's intelligence about each script vendor. * Actionable Recommendations: Receive clear, actionable Approve, Block, or Restrict recommendations based on Jscrambler's foundational expertise and experience in helping organizations protect customer payment data. * Instant Justifications: Generate quick and accurate justification text for faster, consistent, and high-quality compliance workflows with a greater long-term impact. * Interactive AI Chat: Access real-time interaction and correspondence to support decision-making while answering risk-based approval questions as they arise. Jscrambler's new AI Assistant is now available as part of its PCI DSS solution. To learn more, visit Jscrambler at booth #17 at the PCI SSC Europe Community Meeting for a live demonstration. Further details are available in the launch blog by Jscrambler CTO Pedro Fortuna ," Jscrambler Launches the First AI Assistant for PCI DSS Script Authorization Workflows ." About Jscrambler Jscrambler is the leader in Client-Side Protection and Compliance. Jscrambler is the first to merge advanced polymorphic JavaScript obfuscation with fine-grained third-party tag protection in a unified Client-Side Protection and Compliance Platform. Jscrambler's integrated solution ensures a robust defense against current and emerging client-side cyber threats, data leaks, misconfigurations, and IP theft, empowering software development and digital teams to innovate securely online with JavaScript. Jscrambler's Code Integrity product safeguards first-party JavaScript through state-of-the-art obfuscation and exclusive runtime protection. Jscrambler's Webpage Integrity product mitigates threats and risks posed by third-party tags, all while ensuring compliance with PCI DSS v4.0. Jscrambler's Iframe Integrity empowers PSPs to deliver seamless protection, PCI DSS compliance, and SAQ A eligibility to merchants. With Jscrambler, businesses adopt a unified, future-proof client-side security policy, all while achieving compliance with emerging security standards. Customers include Fortune 500 companies, online retailers, airlines, media outlets, and financial services firms whose success depends on secure online engagement.

Recently Posted Jobs

Sign up to get curated job recommendations

There are no jobs for Jscrambler right now.

Find jobs on Simplify and start your career today

We update Jscrambler's jobs every few hours, so check again soon! Browse all jobs →