Jscrambler
Jscrambler is a Porto-based cybersecurity company that provides a unified client-side security platform protecting web applications from third-party script threats, digital skimming, and JavaScript tampering. It serves enterprise customers across e-commerce, financial services, healthcare, and media with PCI DSS, GDPR, and HIPAA compliance capabilities.
- Company typePrivate
- Founded2014
- HeadquartersPorto, Portugal
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Jscrambler does
Jscrambler is a Porto, Portugal-based cybersecurity company founded in 2014 that sells a unified client-side security platform protecting web applications from threats that execute in the browser, outside the network perimeter. The platform comprises three core modules — Code Integrity (JavaScript obfuscation, anti-tampering, and anti-debugging), Webpage Integrity (discovery, inventory, and real-time blocking of third-party scripts), and Iframe Integrity (payment-page and embedded-content protection against skimming) — plus a specialized PCI DSS Module supporting v4 requirements 6.4.3 and 11.6.1. In October 2025 the company launched an AI Assistant that generates risk summaries, recommendations, and justifications for PCI DSS script authorization workflows, complementing the BEHAVIOR classification engine and ORACLE Script Fencing project, which use AI to detect anomalous script behavior and auto-generate blocking rules.
The company serves enterprise customers across e-commerce and retail, financial services, healthcare, KYC and identity verification, media and streaming, IT and software, gaming and gambling, and payment service providers. Named enterprise users include Netflix, Booking.com, Airbnb, Inditex, Zara, Avon, Gap, Sky, KLM, and AutoZone, alongside a Fortune 500 European airline, an e-learning customer, and the fragrance retailer Scentbird. Jscrambler combines a product-led growth entry point (free trial self-service signup) with enterprise field sales and a channel program that includes a QSA Alliance embedding the platform into PCI DSS compliance assessments and reseller/VAR partnerships with deal registration. Cumulative disclosed funding totals roughly $22.5 million across four rounds (2013, 2018, 2021, 2025), with Ace Capital Partners leading the 2021 Series A and Iberis Capital leading the February 2025 round; the company is private and headquartered in Porto with operating reach across EMEA and North America.
Jscrambler firmographics
Firmographics- Name
- Jscrambler
- Legal name
- Jscrambler
- Website
- https://jscrambler.com
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Jscrambler is a Porto-based cybersecurity company that provides a unified client-side security platform protecting web applications from third-party script threats, digital skimming, and JavaScript tampering. It serves enterprise customers across e-commerce, financial services, healthcare, and media with PCI DSS, GDPR, and HIPAA compliance capabilities.
- Ownership category
- akta.pro rank
Jscrambler industry classification
Industry- Product category
- Client-Side Application Security
- NAICS
- Security Systems Services (except Locksmiths) (561621), Computer Systems Design Services (541512), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Browser & Web Isolation Security (HDADAEAK)
- akta.pro secondary industry
- Marketplace & Platform Trust & Safety (Buyer/Seller Abuse) (HDADALAI)
Keywords
Where Jscrambler is headquartered
LocationHeadquarters
- HQ city
- Porto
- HQ country
- Portugal
- HQ region
- Europe
Offices1 record
Markets served
Jscrambler business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Client-Side Protection Platform Subscription: Subscription-based access to Jscrambler's client-side security platform including Code Integrity, Webpage Integrity, and Iframe Integrity modules, with tiered pricing based on usage and feature access.
- Enterprise Licensing: Enterprise agreements with custom pricing for organizations requiring advanced protection features, dedicated support, and expanded protection limits.
- Free Trial/Freemium Entry: Free trial option for new users to evaluate the platform before committing to paid subscriptions, supporting product-led growth motion.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free Trial tier for evaluation purposes |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels10 records
Jscrambler product offering
Product offeringCore offering
Jscrambler sells a unified client-side security platform that protects web applications at runtime in the browser through three integrated modules: Code Integrity (JavaScript obfuscation and anti-tampering), Webpage Integrity (third-party script monitoring and blocking), and Iframe Integrity (embedded payment protection). The platform is delivered as a subscription to enterprise customers and includes a PCI DSS compliance module and an AI Assistant for automated script authorization workflows.
Product overview
Jscrambler offers a unified client-side security platform with a modular architecture. The core platform provides comprehensive protection for web applications through three integrated product modules: Code Integrity (protecting first-party JavaScript from reverse engineering and tampering), Webpage Integrity (monitoring and controlling third-party scripts), and Iframe Integrity (securing embedded content from skimming). The platform also includes specialized compliance modules including the PCI DSS Module for payment page security and compliance. In October 2025, Jscrambler introduced an AI Assistant that extends the platform's capabilities specifically for PCI DSS script authorization workflows, providing automated risk analysis and recommendations.
Differentiator
Problem solved
Functional benefit
Products and services
- Client-Side Protection Platform Unified client-side security platform that enforces software integrity and data governance at runtime in the browser, integrating Code Integrity, Webpage Integrity, and Iframe Integrity modules for enterprise customers.
- Code Integrity Protects first-party JavaScript code with obfuscation, anti-tampering, anti-debugging, and self-defending techniques to prevent reverse engineering, tampering, and automation abuse; targets software companies and SaaS providers shipping JavaScript-heavy applications.
- Webpage Integrity Discovers and inventories dynamic third-party scripts post-deployment, monitors and blocks malicious script behavior in real-time, and automates vendor risk oversight to mitigate OWASP A03 software supply chain failures for enterprise web properties.
- Iframe Integrity Protects iframes from skimming attacks and delivers PCI DSS compliance capabilities for merchants embedding payment iframes; prevents digital skimming in embedded payment contexts.
- PCI DSS Compliance Module Achieves PCI DSS v4 compliance by authorizing, protecting, and monitoring payment page scripts; provides automated evidence collection and audit-ready documentation for merchants, PSPs, and QSA partners.
- AI Assistant for PCI DSS Script Authorization AI-powered assistant embedded in the Jscrambler platform that streamlines PCI DSS script authorization by generating risk summaries, recommendations, justifications, and providing real-time interaction support for compliance teams.
Quantifiable outcome
- 6 billion+ protected web sessions
- +5 more outcomes
Companies that use Jscrambler
Customer profileNamed customers14 records
Segments8 records
Ideal customer profiles4 records
Jscrambler technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability7 records
Feature9 records
Jscrambler partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- ISEP/GECADcoreAcademic research partnership with ISEP (Instituto Superior de Engenharia do Porto) / GECAD for the Behavior Classification Project. The collaboration develops AI-powered solutions for monitoring and classifying behaviors in web applications to identify potential security threats using machine learning models and neural networks.
- CCG/ZGDV InstitutecoreResearch partnership with CCG/ZGDV Institute for the ORACLE Project, developing a knowledge base of behavioral models for third-party scripts and vendors. The collaboration enables automatic generation of script fencing rules using AI-powered script classification to proactively block unexpected script behavior.
- QSA Alliance Program PartnerscoreNetwork of Qualified Security Assessors (QSAs) who integrate Jscrambler into PCI DSS compliance assessments and implementations for merchants and organizations requiring payment security compliance.
- Partner Program MembersminorReseller and integration partners who distribute and implement Jscrambler solutions to end customers through the partner program with deal registration and go-to-market support.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Jscrambler competitors and assessment
Company assessmentBroad incumbents
- Cloudflare: Cloudflare Bot Management and Page Shield (client-side protection) compete in adjacent layers of the same stack. While broader and infrastructure-led, Page Shield directly overlaps Jscrambler's Webpage Integrity value proposition.
- F5 (Shape Security / Distributed Cloud Bot Defense): F5's Shape Security line addresses credential abuse, fraud, and client-side threats for financial services and retail—directly overlapping with Jscrambler's enterprise buyer base and PCI DSS compliance use cases.
- Akamai (Bot Manager / Page Integrity Manager): Post-PerimeterX acquisition, Akamai bundles client-side script monitoring into its broader WAAP and bot management portfolio. Competes with Jscrambler in script behavior monitoring and PCI DSS use cases, but as part of a much larger platform.
- HUMAN Security: Acquired PerimeterX, bringing client-side defense capabilities into its HUMAN Bot Defender and Ad Fraud Defense suite. Overlaps with Jscrambler's Code Integrity and Webpage Integrity offerings, particularly in e-commerce fraud prevention.
- Imperva: Imperva Client-Side Protection (acquired from Distil Networks lineage) competes directly in the digital skimming and PCI DSS space as part of its broader application security portfolio, including WAF and bot management.
Emerging players
- Reblaze: Cloud-native web application security offering bot mitigation and client-side protections as part of a unified platform. Comparable to Jscrambler's mid-market e-commerce focus, though smaller scale.
- Kasada: Bot management platform specializing in credential abuse and account takeover prevention, frequently competing against Jscrambler in e-commerce, travel, and financial services RFPs for fraud and abuse prevention budgets.
- Cequence Security: API and application fraud protection with bot defense capabilities. Competes in fraud/abuse detection for web applications, with overlap in financial services and e-commerce customers but a more API-centric focus.
Direct peers
- DataDome: AI-driven bot and online fraud protection platform serving e-commerce and travel customers (similar industries to Jscrambler's Booking.com, Airbnb, and airline wins). Competes on real-time script behavior analysis and credential abuse prevention.
- Source Defense: Direct competitor offering client-side JavaScript protection against digital skimming (Magecart) and supply chain attacks on checkout pages. Overlaps closely with Jscrambler's Webpage Integrity and Iframe Integrity modules.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
Jscrambler social profiles
Digital presenceJscrambler compliance and trust
Trust signalCompliance4 records
Jscrambler financial estimates
Financial estimateRevenue estimate
Valuation estimate
Jscrambler leadership team
Management profileNumber of profiles
Profiles4 records
Jscrambler funding detail
Funding detailFunding overview
Funding rounds4 records
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Jscrambler M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Jscrambler
What does Jscrambler do?
Jscrambler sells a unified client-side security platform that protects web applications at runtime in the browser through three integrated modules: Code Integrity (JavaScript obfuscation and anti-tampering), Webpage Integrity (third-party script monitoring and blocking), and Iframe Integrity (embedded payment protection). The platform is delivered as a subscription to enterprise customers and includes a PCI DSS compliance module and an AI Assistant for automated script authorization workflows.
Is Jscrambler a public or private company?
Jscrambler is a private company. It is classified as venture growth investor backed and is currently operating.
When was Jscrambler founded?
Jscrambler was founded in 2014. It employs 51 to 100 people.
Where is Jscrambler based?
Jscrambler is headquartered in Porto, Portugal, in the Europe region.
How does Jscrambler make money?
Three revenue lines are on record. Client-Side Protection Platform Subscription is the primary driver. The others are enterprise Licensing and free Trial/Freemium Entry.
Who are Jscrambler's main competitors?
Broad incumbents on record are Cloudflare, F5 (Shape Security / Distributed Cloud Bot Defense), Akamai (Bot Manager / Page Integrity Manager), HUMAN Security and Imperva. Emerging players are Reblaze, Kasada and Cequence Security. Direct peers are DataDome and Source Defense.
Does Jscrambler have an API?
Yes. Jscrambler provides an API client that allows developers to integrate Jscrambler into their development process and submit requests to their web service programmatically. The API supports CI/CD integration workflows including GitHub CI and GitLab CI integration. Available via API Clients documentation. Developer documentation is at docs.jscrambler.com/code-integrity/documentation/api.
What industry is Jscrambler in?
Jscrambler's product category is Client-Side Application Security. Its primary akta.pro industry code is HDADAEAK, Browser & Web Isolation Security, with a secondary code of HDADALAI, Marketplace & Platform Trust & Safety (Buyer/Seller Abuse). Its NAICS code is 561621 and its SIC code is 7372.