PCI Case Study

How a UK Travel Technology Provider Strengthened Oversight of Third-Party Scripts

The Customer: A White-Label Booking Platform

The customer is an established UK travel technology provider operating a white-label reservation platform for travel and parking businesses in multiple markets. Customers present their own branding, while the platform supports the booking journeys and integrations behind the scenes.

As with many multi-tenant platforms, different customer configurations included different analytics, marketing and service integrations. The provider wanted a consistent way to understand the client-side components active across those configurations and to identify meaningful changes over time.

The Challenge: Maintaining Visibility Across a Varied Estate

Customer-specific integrations are valuable, but they can make client-side oversight more difficult. Different pages and site configurations may use different versions of vendor services, while legitimate vendor updates can change scripts regularly.

The provider needed to maintain an inventory of the scripts present on in-scope pages, understand the business purpose of each one and detect relevant changes in line with PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1.

The objective was to create practical, repeatable oversight without introducing another page-side dependency or requiring a large code rollout across customer sites.

The Solution: Why Agentless Won

As the provider evaluated options, it was clear that a solution requiring code changes across all customer sites would be difficult to introduce and maintain.

“To make a change to the code base for all our customers is a challenge. A year ago, if we needed to introduce something across all of our sites quickly, the way to do that was agentless. Having this external scan was a big tick in the box.”
Engineering lead UK travel technology provider

The provider also valued the reduced operational dependency of an external scan:

“I liked the reduced risk of not having another set of code running on our pages that could interfere with service.”
Engineering lead UK travel technology provider

Reflectiz’s agentless approach monitors pages from outside the customer environment. It does not require a new script to run within the booking journey, and it avoids the need for a coordinated code deployment across different customer configurations.

A Proof of Concept That Needed No Developers

The proof of concept was deliberately simple:

“We gave them page names and URLs, and we were given a dashboard, and it was all there. Easy to navigate, easy to access, and it required no developer intervention from our side. That was really the sum of it. It was easy.”
Engineering lead UK travel technology provider

Once the relevant page list had been provided, Reflectiz handled the setup and presented the results in a dashboard that the engineering team could use directly.

The Game Changer: Approving Behaviours, Not Hashes

The feature the provider valued most was behavioural approval: the ability to approve what a script is observed to do rather than relying only on an exact code signature.

Legitimate vendor services update frequently. A control based solely on exact script contents can therefore create a significant maintenance burden, with routine changes generating repeated alerts.

Behavioural approvals provide a more practical way to distinguish ordinary vendor change from activity that warrants investigation:

“That smart approval is critical for me. With multiple pages per customer, all running different versions of the same pages, I can’t imagine being able to track the scripts any other way. It wouldn’t be manageable.”
Engineering lead UK travel technology provider

This gave the team a way to manage change across a varied estate without treating every routine vendor update as a new incident.

Onboarding: As Simple as Sharing a Spreadsheet

After preparing a list of the relevant pages and configurations, the Reflectiz setup was straightforward:

“Once I provided that list, it was pain-free. It was as simple as sharing a table of our information. It was all just taken away and done for me. Hassle-free. It was actually quicker than I needed it to be.”
Engineering lead UK travel technology provider

The onboarding process required no developer intervention on the customer platform and provided a clear starting point for the script inventory and approval process.

Inside the PCI DSS Audit

The PCI DSS assessment included a focused review of the client-side script-monitoring requirements. The provider was able to show the relevant dashboard, approvals and behavioural evidence in a clear and usable form.

“Our QSA was very familiar with Reflectiz already. He said it was a good tool, he knew other companies were using it, and he knew it did what was needed. He was happy to see we were capturing evidence of the approvals, he liked the dashboard, and he was comfortable with how we were tracking behaviours.”
Engineering lead UK travel technology provider

The result was a short, focused audit conversation rather than a separate development exercise to assemble evidence manually.

Beyond PCI: Value from Additional Visibility

Although PCI DSS readiness was the original reason for the project, the additional visibility also helped identify two legacy implementation issues outside the immediate compliance objective. Both were remediated promptly.

The provider valued this wider benefit: the monitoring process supported not only compliance evidence, but also ongoing technical housekeeping across a changing multi-site platform.

Payment-Page Security Beyond the Checkbox

The provider sees client-side monitoring as part of a broader security and operational-control programme, rather than as a compliance exercise in isolation.

Because the platform is white-label, customers see their own branding throughout the booking journey. Consistent visibility of the client-side components therefore matters to both the provider and its customers, while Reflectiz provides an additional monitoring and evidence layer without requiring code to be installed in those pages.

Support and Partnership

The provider also valued the responsiveness of the Reflectiz support and product teams, particularly the ability to raise questions and obtain direct explanations from engineering.

One request became a product feature. The provider wanted a single view across all monitored pages rather than separate page-level exports. That aggregate reporting capability was added within weeks.

“I said it would be really useful to have all of the pages in one report, so I could see that aggregate. Within a few weeks, it was added.”
Engineering lead UK travel technology provider

The Bottom Line

Asked whether the provider would recommend Reflectiz to peers, the answer was clear:

“I’d encourage anyone to include Reflectiz in their evaluation. There’s no developer effort required, and the behaviour approvals mean we’re not continually updating things. As we get everything approved, the alerts narrow down to just the relevant ones, and that’s where the real value is.”
Engineering lead UK travel technology provider

For an engineering team responsible for a varied white-label booking estate, the combination of visibility without installation and monitoring without constant maintenance made a new PCI DSS requirement manageable.

Key Takeaways

  • PCI DSS 4.0.1 readiness: Requirements 6.4.3 and 11.6.1 require organisations to maintain visibility and control over scripts on in-scope payment pages.
  • White-label oversight: Multi-tenant platforms can contain many customer-specific integrations, making consistent client-side visibility important.
  • The agentless advantage: External monitoring avoids a broad code rollout and does not add another script to the live booking journey.
  • Scalable behavioural approvals: Behavioural approval helps absorb ordinary vendor updates while drawing attention to changes that may require investigation.
  • Value beyond compliance: Better client-side visibility can also help identify and remediate legacy implementation issues as part of normal technical housekeeping.

Take control

Stay up to date with the latest news and updates

Become the next success story

Discover your website blind spots and vulnerabilities before it’s too late!

Try for free