Skip to content

Feroot Security

Client-side web security platform that monitors browser JavaScript for skimming, script injection, and supply chain threats, aligned to PCI DSS 4.0 client-side requirements.

Visit Website ↗ + Add to Compare
63/100Incremental Innovator

Overview

Feroot Security builds client-side web application security software that monitors and controls the JavaScript running in a user’s browser, the part of the software supply chain that traditional application security tools (SAST, DAST, server-side WAFs) generally cannot see. Modern web pages load dozens of first- and third-party scripts, and a compromise anywhere in that chain, a hijacked analytics tag, a poisoned npm package, a malicious ad script, can let attackers skim payment card data or credentials directly out of the browser (a technique known as Magecart or web skimming) without ever touching the backend.

Founded in 2017 and headquartered in Toronto, Canada, Feroot went through Y Combinator and has raised roughly $25 million total, including an $8.4 million seed round in 2022 and a $14 million Series A led by True Ventures. Its flagship Inspector product continuously scans and monitors client-side JavaScript behavior in real time to flag unauthorized data access, script injection, and supply chain risk, and the company has built a subscription business it says serves thousands of customers across healthcare, retail, and payment services.

Feroot’s relevance got a concrete regulatory boost with PCI DSS 4.0’s requirements 6.4.3 and 11.6.1, which mandate that organizations handling payment card data inventory and monitor client-side scripts and detect unauthorized changes to payment pages, requirements that took effect in 2025 and map directly onto what Feroot’s product already does, giving the company a clear, independently defined compliance driver rather than a purely discretionary purchase.

Innovation Matrix Assessment

Innovation Velocity 6/10

Feroot has iterated steadily since 2017, expanding its Inspector product's real-time detection and compliance features, including a recent AI-powered compliance platform push tied to its Series A, though it is not among the fastest-shipping vendors in the category.

Operational Value 6/10

A Y Combinator alum with a subscription business it says serves thousands of customers and a public presence on Gartner Peer Insights, indicating genuine production usage rather than early pilots.

Market Momentum 6/10

Total funding of roughly $25M across a 2022 seed and a True Ventures-led Series A is respectable but modest next to the largest AppSec funding rounds, indicating steady rather than explosive growth.

Category Disruption 6/10

Client-side/JavaScript supply chain security is a real blind spot for traditional AppSec tooling, but Feroot is one of several established vendors in this specific niche rather than a category creator at this point.

Real-World Efficacy 6/10

Public Gartner Peer Insights reviews provide some independent user feedback, and the product's core function (client-side script inventory and change detection) directly maps onto now-mandatory PCI DSS 4.0 requirements 6.4.3 and 11.6.1; specific customer count and stats remain vendor-reported.

Enduring Relevance 8/10

PCI DSS 4.0's requirements for monitoring client-side scripts on payment pages, in effect since 2025, create a concrete, externally-imposed compliance driver for any organization handling card data online, directly matching Feroot's core product.

Why CISOs Should Care

Gives compliance and security teams visibility and control over browser-side JavaScript risk, an attack surface that server-side WAFs and SAST/DAST tools do not cover, and maps directly onto mandatory PCI DSS 4.0 client-side requirements.

What Makes It Different

Focuses specifically on the client-side/browser attack surface (script injection, Magecart-style skimming, supply chain scripts) rather than general web application security, with compliance mapping built around PCI DSS 4.0's newer client-side rules.

The Matrix Verdict

63/100 — INCREMENTAL INNOVATOR

A steady, established client-side security vendor whose relevance was meaningfully boosted by PCI DSS 4.0 turning its core capability into a compliance requirement for card-handling websites; a solid, if not category-defining, option in a growing niche.

Editorial Note: Claims vs. Verified Findings

Founding year, funding rounds, and investors are independently corroborated by TechCrunch-adjacent coverage, Preqin, and Feroot's own funding announcements. Customer count ('thousands') and specific detection efficacy figures are vendor-sourced and not independently audited in this research; Gartner Peer Insights reviews offer some independent, if self-selected, user feedback.

Sources