Zero Audit Findings. No-Code Installation.
No Access to Payment Data.

Remote, agentless PCI DSS 4.0.1 compliance for requirements 6.4.3 and
11.6.1: deployed in 24 hours.

Get Your Site Audit

What the Reflectiz PCI Module Does

More than half of third- and fourth-party applications running on monitored sites access sensitive data with no documented business justification. PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 exist to close exactly that gap, and the Reflectiz PCI Module automates the work of meeting them.

The Reflectiz PCI Module is a purpose-built compliance solution for PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1. It runs entirely remotely: submit a payment page URL, and it begins monitoring within hours (one day onboarding), and automates the work that consumes the most time before and during a QSA audit: script inventory, behavioral approval, business justification documentation, and compliance evidence generation.
Reflectiz is a Principal Participating Organization in the PCI Security Standards Council and works directly with the Council to shape evolving guidance. The module is available as a standalone solution or as part of the Reflectiz Security Hub.

PCI DSS v4.0.1 Requirements

Payment Page Script Management

Requirement 6.4.3 mandates that every script loaded and executed in the consumer's browser on payment pages is managed, documented with a business justification, and verified for integrity. Reflectiz maintains a continuously updated inventory of every script on sensitive payment pages, including third-party, fourth-party, and iFrame-embedded scripts, with per-script approval and justification workflows aligned to PCI DSS 4.0.1 examination procedures.

Unauthorized Change Detection

Header tampering and skimming injections often go undetected until a customer complaint or forensic review surfaces them. Requirement 11.6.1 closes that gap by mandating the detection of, and response to, unauthorized modifications to HTTP headers and payment page contents. Reflectiz continuously monitors HTTP response headers, raises real-time alerts on deviation, and writes timestamped evidence logs the moment a change is detected.  

How the PCI Module Works

Remote Onboarding
Operational in Hours, Not Weeks

The Reflectiz PCI Module requires no agent installation, no code changes, and no access to your production environment. You only need to provide payment page URLs, then Reflectiz's proprietary remote monitoring engine begins scanning and cataloguing every script within hours. According to Reflectiz customer deployment data, most organizations are fully operational within 24 hours of URL handover.

Smart Approvals
Define Once, Auto-Approve at Scale

Reflectiz Smart Approval lets security teams define acceptable script behaviors once. When the platform later detects a script exhibiting an already-approved behavior pattern, it auto-approves the match, removing the per-script manual-review bottleneck. Built-in AI drafts an audit-aligned business justification for each script automatically, which reviewers can accept, edit, or override before approving.

Bulk Approval
Multi-Site Compliance in a Single Action

Bulk Approval lets users approve identical script behaviors across multiple sites at once. Select the risk indicators, apply a general justification, and propagate the settings across every relevant site and checkout page in one action, reducing multi-day one-by-one approval processes to minutes.

Continuous Monitoring
Because 30% of Scripts Change Within Two Weeks

Reflectiz monitoring research across 4,700 websites found that approximately 30% of third-party scripts change within two weeks of deployment. The PCI Module monitors payment pages continuously and generates real-time alerts whenever a script or payment page header deviates from its approved state, maintaining compliance between audit cycles, not only at the point of audit.

Audit Evidence and QSA Reporting
Export-Ready Evidence on Demand

The Reflectiz PCI Dashboard generates on-demand compliance evidence for Qualified Security Assessor (QSA) audits, covering script inventories, individual business justifications, approval status, domain change logs, user activity logs, and evidence logs, in formats aligned with the examine, observe, and interview procedures specified in PCI DSS 4.0.1 guidance.

Key Capabilities

Remote architecture

Reflectiz runs externally with no code insertion and zero access to user PII, session data, or payment transaction information.

iFrame and 4th-party detection

Reflectiz detects and monitors iFrame-embedded scripts and fourth-party elements; coverage that agent-based tools typically cannot provide and that QSAs increasingly request.

AI-assisted justifications

Built-in AI drafts PCI-aligned business justifications for each script automatically, reducing manual documentation effort by up to 90% according to Reflectiz customer data.

Full-site coverage beyond the payment page

Reflectiz monitors the entire web surface, closing the lateral movement risk created when attackers establish a foothold on non-payment pages and execute on checkout.

Zero performance impact

Remote operation means site speed, checkout flows, and user experience are entirely unaffected.

Aggregated multi-site reporting

The Reflectiz Aggregated Report consolidates PCI compliance data from all monitored sites into a single exportable report, so there is no need to reconcile individual site reports before a QSA review.

Recognized at the top tier by the PCI Security Standards Council

Reflectiz is a Principal Participating Organization (PPO) in the PCI Security Standards Council – the highest tier of industry participation in shaping global payment security standards.

As a PPO, Reflectiz contributes directly to PCI SSC Technology Guidance Groups, helps to shape ongoing updates of the Data Security Standard, and gains early visibility into emerging standards, keeping the Reflectiz PCI Dashboard aligned with every evolution of PCI DSS.

In April 2026, Reflectiz joined the PCI SSC’s Coffee with the Council podcast alongside BT Group and Salesforce to discuss the value of PPO participation, the findings of the State of Web Exposure 2026 Report, and how third- and fourth-party script risk is shaping the future direction of payment security standards. Brett Johnson, Reflectiz’s Americas lead, highlighted a striking pattern in the data: more than half of third- and fourth-party applications running on monitored sites access sensitive information with no documented business justification. This is the exact gap requirements 6.4.3 and 11.6.1 were designed to close.

Simon Turner
Simon Turner
Head of Security Governance and Compliance for PCI DSS, BT Group
Brett Johnson
Brett Johnson
VP Sales, Americas, Reflectiz
Gagandeep Singh
Gagandeep Singh
Lead of Technology Governance and Compliance Function, Salesforce
Listen to the Coffee with the Council Episode:

What Customers Achieve

Apexx Global
Zero observations. Level 1. Under 24 hours.
Apexx Global is a UK-based payment orchestration platform subject to Level 1 PCI DSS compliance, the strictest tier,. Head of Information Security Deepak Kumar Ramanujam chose Reflectiz because no agent-based alternative could offer monitoring without access to transaction data. Deployment was complete in under 24 hours. The Level 1 audit produced zero observations.
"One of the most important reasons we went with Reflectiz is that it doesn't need to know transaction details. That eliminated security and privacy concerns and third-party risk immediately."
24 hrs to deployment
Zero audit observations
Zero transaction data accessed
Read the Full Case Study
Village Roadshow
700+ scripts. Four sites. Two days. Zero findings.
Village Roadshow, Australia's largest entertainment group, needed to validate over 700 third-party scripts across four key websites for its PCI DSS 4.0.1 audit, without code changes or developer involvement. Reflectiz was deployed in two days. Smart Approval workflows enabled the Digital Experience team to process the full script inventory in a structured, manageable way. The audit produced zero observations.
"Reflectiz gives us the visibility we lacked. If you're struggling with how to meet the new PCI DSS v4.0.1 requirements, Reflectiz is the answer. It removes the blind spots without disrupting your platforms or teams."
700+ scripts approved
Zero audit observations
2 days to deployment
Zero code changes
Read the Full Case Study
lastminute.com
50+ markets. 1,000+ scripts. Zero issues.
Pan-European travel platform lastminute.com operates in more than 50 markets and generates €361M in annual revenues (FY2025). Director of Platform Security Alessandro Gazzoni ran the Reflectiz approach past his QSA before making the selection decision. The auditor approved it without caveats. Onboarding was smooth. The Reflectiz element of the compliance audit proceeded without issues.
"Simplicity combined with effortless visibility. That's important in a company with hundreds of engineers. Reflectiz delivers that."
1,000+ scripts monitored
Hours to full deployment
Zero audit issues flagged
Read the Full Case Study
Broadway Gaming
Zero audit findings. Zero developer overhead.
Dublin-based Broadway Gaming Group runs multiple bingo and casino brands across the UK and Ireland, all channelling through a shared checkout page. CISO Kfir Tzukrel ruled out an in-house build ("If I'd made them do it, they wouldn't have had time for anything else") and selected Reflectiz for its agentless architecture and AI-assisted justification capability. The first mandatory PCI DSS 4.0.1 audit passed with zero observations. AI-generated justifications reduced what would have been a multi-day documentation task into an afternoon’s work.
"If you have to meet PCI requirements, it's a no-brainer. PCI is hard, so it's a must."
Zero audit observations
Zero developer hours required
Level 1 PCI DSS passed first time
Zero audit observations
Read the Full Case Study
New

Find the gaps before your QSA does

The Reflectiz and Integrity360 PCI Compliance Solution Assessment gives organizations an independent expert evaluation of their readiness for PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 — before their QSA finds the gaps first.

Reflectiz has partnered with Integrity360, one of the world’s leading cybersecurity service providers, to deliver a structured assessment that covers:

Gap analysis against requirements 6.4.3 and 11.6.1
Script inventory completeness review
Approval and justification workflow evaluation
Audit evidence readiness scoring
Recommendations mapped to QSA examination procedures

Whether your audit is six weeks out or six months away, this assessment gives your security and compliance teams the clarity to act with confidence, not react under pressure.

How Reflectiz Compares

Capability comparison across the five most commonly evaluated PCI DSS 6.4.3 and 11.6.1 solutions, based on publicly documented product architectures and published customer outcomes as of 2025–2026.

Capability Reflectiz c/side Jscrambler Feroot Source Defense
Deployment model Agentless / fully remote Agent-based Agent-based Agent-based Agent-based
Code changes required No Yes Yes Yes Yes
Access to payment or session data None Yes Yes Yes Yes
iFrame and 4th-party script detection Full Limited Limited Limited Limited
Dedicated PCI DSS 6.4.3 / 11.6.1 dashboard Yes No No Partial Partial
AI-assisted script justifications Yes No No No No
Smart Approval (define once, auto-approve) Yes No No No No
Bulk Approval across multiple sites Yes No No No No
Aggregated multi-site compliance report Yes No No No No
One-click QSA evidence export Yes No Partial Partial No
SAQ A eligibility support, including iFrames Yes No No No Partial
Deployment time Hours to 24 hours Days to weeks Days to weeks Days to weeks Days to weeks
Site performance impact None Present Present Present Present
PCI SSC status Principal Participating Organization Not listed Principal Participating Organization Not listed Not listed
Published audit outcomes Zero observations across all published customer cases Not published Not published Not published Not published

A note on agent-based architectures

Solutions that require agent or tag deployment introduce a third-party component into the payment environment, requiring teams to evaluate the agent itself as a compliance and privacy risk. This was the specific concern Apexx Global’s Head of Information Security cited as the reason for selecting Reflectiz over every agent-based alternative they evaluated.

The SAQ A Consideration

Updated SAQ A guidance gives eligible merchants a path to potentially simplify their compliance obligations, but only if they can affirmatively demonstrate that their entire website is protected from script-based attacks, including Magecart and web skimming. In effect, the new SAQ A now demands the very monitoring that it was meant to spare you.

Reflectiz provides the full-site script visibility, including the iFrame coverage that most tools cannot deliver, required to establish SAQ A eligibility and sustain it continuously between audit periods.

Security Beyond the Payment Page

PCI compliance PCI Compliance secures the payment page. It does not secure the rest of your web environment, and most client-side attacks don’t start at checkout. Reflectiz Security Hub provides continuous visibility and control across your full web surface, detecting malicious script activity, web supply chain risks, misconfigurations, and unauthorized data access. Reflectiz Privacy Hub gives compliance and legal teams visibility into how user data is accessed, collected, and shared across web properties, supporting alignment with GDPR, CCPA, HIPAA, and other privacy obligations alongside your PCI posture.

PCI DSS Additional Resources

Master Your PCI DSS v4 Compliance
The Hacker News
PCI DSS Requirement 6.4.3 Explained
Reflectiz Blog
PCI DSS Section 11.6.1 Explained
Reflectiz Blog
The SAQ A Changes and What They Mean
Reflectiz Blog
Smart Approvals: Managing Script Inventories at Scale
Reflectiz Blog
Reflectiz Joins PCI SSC as a Principal Participating Organization
PCI SSC Blog
Coffee with the Council: Stronger Together
PCI SSC Podcast

FAQ

What is the Reflectiz PCI Module?

The Reflectiz PCI Module is a dedicated PCI DSS v4.0.1 compliance solution that automates script inventory management, unauthorized change detection, Smart Approval workflows, and QSA-ready evidence generation for requirements 6.4.3 and 11.6.1, with no agent installation,, no code changes, and no access to payment or user data.

Does the Reflectiz PCI Module require code changes or agent installation?

 No. The Reflectiz PCI Module operates entirely via remote execution. No agent is installed, no JavaScript tag is deployed, and no access to the production environment is required. Organizations provide payment page URLs, and Reflectiz monitors them remotely.

How does Reflectiz fulfill PCI DSS requirement 6.4.3?

Reflectiz fulfills requirement 6.4.3 by maintaining a continuously updated inventory of every script on payment pages (including third-party, fourth-party, and iFrame scripts) and providing an individual approval and documented justification workflow for each, aligned with the examine, observe, and interview procedures in PCI DSS 4.0.1 guidance.

How does Reflectiz fulfill PCI DSS requirement 11.6.1?

Reflectiz fulfills requirement 11.6.1 by continuously monitoring HTTP response headers on payment pages and generating real-time alerts whenever an unauthorized change is detected. Each alert is accompanied by a timestamped evidence log capturing the precise nature of the change (including modified, added, or removed headers) in a format aligned with the PCI DSS 4.0.1 examination procedures. These logs are available on demand for QSA review and can be exported directly from the Reflectiz PCI Dashboard.

Can Reflectiz generate the evidence my QSA needs?

Yes. The Reflectiz PCI Dashboard generates one-click compliance evidence exports covering script inventories, individual business justifications, approval status, domain change logs, user activity logs, and evidence logs, in formats aligned with PCI DSS 4.0.1 QSA examination procedures.

Has the Reflectiz approach been reviewed and approved by QSAs?

Yes. Multiple Reflectiz customers have confirmed that their QSAs reviewed and approved the Reflectiz approach without caveats. lastminute.com’s Director of Platform Security confirmed auditor approval before selecting the tool. Reflectiz is also a Principal Participating Organization in the PCI Security Standards Council.

What changed in PCI DSS v4.0.1, and why do requirements 6.4.3 and 11.6.1 matter now?

PCI DSS v4.0.1 made requirements 6.4.3 (script inventory and authorization) and 11.6.1 (HTTP header change detection) mandatory best practices as of March 2025. Organizations that previously relied on self-attestation now need documented, continuous, and auditable controls – not point-in-time assessments. Non-compliance can result in failed QSA audits, elevated assessment scope, and increased liability exposure in the event of a breach.

How is Reflectiz different from agent-based or tag-based script monitoring tools?

Agent-based and tag-based tools require JavaScript to be deployed on the payment page – introducing additional attack surface, requiring developer involvement, and often failing to detect fourth-party scripts loaded by third parties. Reflectiz operates entirely remotely with no code on the page, monitoring the rendered output including iFrames, fourth-party scripts, and dynamically injected content that tag-based tools cannot reach.

What are fourth-party scripts, and why does Reflectiz cover them?

Fourth-party scripts are JavaScript files loaded by your third-party vendors – a chat widget that itself loads an analytics tracker, for example. PCI DSS requirement 6.4.3 requires authorization and justification for all scripts on a payment page, including fourth-party ones. Most tools inventory only scripts you directly load. Reflectiz inventories the full chain, including scripts that are two or three vendor relationships removed from you.

How long does deployment take?

Most organizations are fully operational within 24 hours of providing payment page URLs. Apexx Global’s deployment was live in under 24 hours. Village Roadshow’s four-site deployment was complete in two days with no code changes and no developer involvement.

Does Reflectiz access payment data or user PII?

No. Reflectiz takes a remote, agentless approach. It operates externally with no code insertion and zero access to payment data, session information, or user PII. This architecture was specifically cited by Apexx Global’s Head of Security as the reason Reflectiz was selected over agent-based alternatives.

Can Reflectiz handle multiple brands or payment pages?

Yes. Bulk Approval allows identical script behaviors to be approved across all sites in a single action. The Aggregated Report consolidates compliance data from all properties into one report. Reflectiz is designed for enterprise organizations that operate multiple brands with numerous checkout pages across various territories.

What happens when a previously approved script changes?

Reflectiz detects behavioral deviations in real time and alerts the security team. The script’s approval status updates to reflect the change, and the team can review, generate a new AI-assisted justification, and re-approve – maintaining a continuous compliance posture rather than point-in-time snapshots.

How does Reflectiz support SAQ A eligibility?

Updated SAQ A guidance requires owners to demonstrate that the entire website is protected from script-based attacks. Reflectiz provides full-site script visibility – including iFrame coverage that most tools cannot deliver, plus continuous monitoring,, enabling organizations to establish and sustain SAQ A eligibility. In practical terms, SAQ A-eligible merchants benefit from a significantly reduced compliance scope: fewer controls to implement, a shorter self-assessment questionnaire, and a lighter on-site assessment burden, making compliance materially faster and less expensive to maintain year over year.

What is the Integrity360 PCI Compliance Solution Assessment?

The Integrity360 and Reflectiz PCI Compliance Solution Assessment is an independent expert evaluation covering gap analysis against requirements 6.4.3 and 11.6.1, script inventory completeness review, approval workflow evaluation, audit evidence readiness scoring, and recommendations mapped to QSA examination procedures. It is available as a free gated download.

Can I try Reflectiz before committing?

Yes. Reflectiz offers a 30-day free trial. Organizations can provide their payment page URLs and receive a full script inventory, unauthorized change alerts, and compliance gap assessment – with no installation required and no code changes.

Does Reflectiz replace my QSA?

No. Reflectiz automates the evidence collection, script inventory management, and change detection workflows that QSAs examine – but it does not perform the assessment itself. It is designed to make QSA assessments faster, cheaper, and more predictable by ensuring compliance posture is continuously maintained rather than assembled under deadline pressure.

Does Reflectiz work with hosted payment pages and iFrame-based checkouts?

Yes. Reflectiz monitors the entire rendered payment page context, including iFrame content from hosted payment providers. This is particularly important for SAQ A merchants, whose eligibility depends on demonstrating that the parent page loading the iFrame is itself free from unauthorized scripts.

Ready to Close Your PCI Gap?

The Reflectiz PCI Module gives security and compliance teams continuous payment page monitoring, audit-ready evidence, and Smart Approval workflows, deployed in hours,, with no code changes and no access to payment data.

Start a 30-Day Free Trial

Reflectiz is a Principal Participating Organization in the PCI Security Standards Council. ISO 27001 certified.

FAQs

What is the Reflectiz PCI Module?

The Reflectiz PCI Module is a dedicated PCI DSS v4.0.1 compliance solution that automates script inventory management, unauthorized change detection, Smart Approval workflows, and QSA-ready evidence generation for requirements 6.4.3 and 11.6.1 — with no agent installation, no code changes, and no access to payment or user data.

Does the Reflectiz PCI Module require code changes or agent installation?

No. The Reflectiz PCI Module operates entirely via remote execution. No agent is installed, no JavaScript tag is deployed, and no access to the production environment is required. Organizations provide payment page URLs, and Reflectiz monitors them remotely.

How does Reflectiz fulfill PCI DSS requirement 6.4.3?

Reflectiz fulfills requirement 6.4.3 by maintaining a continuously updated inventory of every script on payment pages — including third-party, fourth-party, and iFrame scripts — and providing an individual approval and documented justification workflow for each, aligned with the examine, observe, and interview procedures in PCI DSS 4.0.1 guidance.

How does Reflectiz fulfill PCI DSS requirement 11.6.1?

Reflectiz fulfills requirement 11.6.1 by continuously monitoring HTTP response headers on payment pages and generating real-time alerts whenever an unauthorized change is detected.

Can Reflectiz generate the evidence my QSA needs?

Yes. The Reflectiz PCI Dashboard generates one-click compliance evidence exports covering script inventories, individual business justifications, approval status, domain change logs, user activity logs, and evidence logs — in formats aligned with PCI DSS 4.0.1 QSA examination procedures.

Has the Reflectiz approach been reviewed and approved by QSAs?

Yes. Multiple Reflectiz customers have confirmed that their QSAs reviewed and approved the Reflectiz approach without caveats.

What changed in PCI DSS v4.0.1, and why do requirements 6.4.3 and 11.6.1 matter now?

PCI DSS v4.0.1 made requirements 6.4.3 and 11.6.1 mandatory as of March 2025. Organizations need documented, continuous, and auditable controls — not point-in-time assessments.

How is Reflectiz different from agent-based or tag-based script monitoring tools?

Reflectiz operates entirely remotely with no code on the page, monitoring the rendered output including iFrames, fourth-party scripts, and dynamically injected content that tag-based tools cannot reach.

What are fourth-party scripts, and why does Reflectiz cover them?

Fourth-party scripts are JavaScript files loaded by your third-party vendors. Reflectiz inventories the full chain, including scripts that are two or three vendor relationships removed from you.

How long does deployment take?

Most organizations are fully operational within 24 hours of providing payment page URLs.

Does Reflectiz access payment data or user PII?

No. Reflectiz takes a remote, agentless approach with zero access to payment data, session information, or user PII.

Can Reflectiz handle multiple brands or payment pages?

Yes. Bulk Approval allows identical script behaviors to be approved across all sites in a single action.

What happens when a previously approved script changes?

Reflectiz detects behavioral deviations in real time and alerts the security team.

How does Reflectiz support SAQ A eligibility?

Reflectiz provides full-site script visibility and continuous monitoring, enabling organizations to establish and sustain SAQ A eligibility.

What is the Integrity360 PCI Compliance Solution Assessment?

An independent expert evaluation covering gap analysis against requirements 6.4.3 and 11.6.1, available as a free gated download.

Can I try Reflectiz before committing?

Yes. Reflectiz offers a 30-day free trial with no installation required.

Does Reflectiz replace my QSA?

No. Reflectiz automates evidence collection workflows but does not perform assessments itself.

Does Reflectiz work with hosted payment pages and iFrame-based checkouts?

Yes. Reflectiz monitors the entire rendered payment page context, including iFrame content from hosted payment providers.