# c/side

**Canonical:** https://apis.io/providers/c-side/  
**Website:** https://cside.com  
**APIs profiled:** 0

c/side (cside) is a client-side security platform that detects script attacks, AI agents, account takeover, and fraud at the browser layer. It provides active runtime detection that watches what third-party scripts, users, and agents actually do as they execute in the live browser session, in real time, rather than relying on static scans or block-lists, and it automates PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 (validated by a VikingCloud QSA). cside deploys as a single JavaScript snippet with no proxy and no DNS changes, and was the first client-side security product with integrated AI analysis. The platform protects websites from malicious third-party scripts, e-skimming, Magecart, and supply chain attacks, and adds device fingerprinting (102+ signals), VPN/bot/AI-agent detection, chargeback evidence, and privacy monitoring for GDPR, CCPA, and HIPAA. Founded in 2024 and backed by Uncork Capital, cside integrates via a CLI, Next.js and Vite plugins, a manual script tag, and Salesforce Lightning, and sends security alerts through webhook, S3, and Jira/Linear notification endpoints. cside publishes an llms.txt, a public read-only MCP server, and a Trust Center covering SOC 2 Type II, PCI SAQ-D, and ISO 27001.

## Kin Score — 46.2 / 100 (developing)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 46.2).

| Facet | Score |
|---|---|
| Discoverability | 68.5 |
| Contract Quality | 45.1 |
| Governance | 18.2 |
| Contract Governance | 18.2 |
| Operational Transparency | 52.6 |
| Developer Ergonomics | 52.4 |
| Commercial Clarity | 36.8 |
| Access Clarity | 36.8 |

Regulatory layer — **Payments**: 40.6 (matched via tags).

## Agent readiness — 33.3 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | verified |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## MCP servers (1)

- **c/side MCP Server** — cside operates a public, read-only remote MCP (Model Context Protocol) server at https://mcp.cside.com that exposes cside.com marketing-site and docs.cside.com documentation con...

## Security (3)

- **C Side Domain Security** — TLSv1.3 · HSTS · DMARC
- **C Side Vulnerability Disclosure** — security.txt · contact published
- **C Side Trust Center** — SOC 2 Type II, PCI DSS (SAQ-D AOC), ISO 27001 (in progress), GDPR

## Tags

Company, Security, Client-Side Security, Application Security, Fraud Prevention, PCI DSS Compliance, Device Fingerprinting, Bot Detection, Web Security, Script Monitoring

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/c-side/). Scores are computed from the provider's own public artifacts under a published rubric.
