About Offscript
Offscript is agentless browser-malware detection for internal web apps, built on telemetry your apps already produce: Content Security Policy violation reports.
Why we exist
Employees reach internal apps from managed laptops, personal phones, home desktops, and contractor machines that will never run an endpoint agent. Malicious browser extensions and injected third-party scripts execute inside those sessions, reading form fields and shipping data out where server logs, EDR, and WAFs never look. That gap is where client-side breaches happen, and it has been growing as the browser becomes the real workplace.
Offscript closes the gap without installing anything. Your app already serves a Content Security Policy; every browser that loads it enforces that policy and reports the scripts and connections it blocks. We turn that stream of reports into malware and phishing detections by checking each blocked URL against threat intelligence, so the browsers themselves become your sensors — on any device, with a one-header rollout.
How we work
We are deliberately minimal about data: only CSP violation reports from your own apps are received, never browsing history, page contents, or keystrokes, and raw reports with reporter IP addresses are purged after 30 days. Detection results reach you where you already work — a dashboard, a webhook into your security tooling, and an optional relay that keeps your existing CSP report pipeline intact.
Offscript was founded by Dominic Couture, a security engineer with a background in application security and independent research into the browser-extension ecosystem, including the malicious-extension campaigns this product is built to catch.
Where we fit
Offscript complements EDR and WAF rather than replacing them: it covers what actually runs inside the browser, including on devices that have no EDR at all. The same telemetry doubles as monitoring evidence for supply-chain and client-side security programs such as OWASP Top 10 A03, SOC 2, ISO 27001, and PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1.
Questions about anything on this page? Get in touch.