About HeaderHawk
Making CSP monitoring simple so you can focus on building.
What I’m building
Content Security Policy is one of the most effective defenses against XSS attacks and data injection vulnerabilities. When configured correctly, it stops entire categories of exploits before they happen.
The problem: monitoring CSP violations has always been painful. Reports flood in with no context. Existing tools feel clunky and unintuitive. You want to drill into your data, filter by directive, see what resources are being blocked and why. Instead you get dashboards that show you everything except what you need.
HeaderHawk exists to change that. It takes a few minutes to set up, and it lets you explore your violation data the way you actually want to — grouped, filterable, and specific enough to act on.
Why I built it
I’m Michael Cameron, and I’m the only person who works on HeaderHawk. Before this I spent a long time running platform engineering and security inside a company that had to take both seriously.
Every time we rolled out a CSP there, the same thing happened. CSP is table stakes, but monitoring it was a mess. The options were to build your own collection pipeline or tip the reports into a generic events platform that was never designed for CSP data. Either way you did a lot of work just to answer basic questions about what was breaking.
So I built the tool I wanted at the time. It’s bootstrapped and independent, there is no investor timeline behind it, and I answer the support email myself.
How I build it
The things I try to hold to.
Simple to set up
A security tool shouldn’t need a team to stand it up. Register your site, add the reporting directive it gives you, and violations start arriving.
Built with care
The same care I put into my own projects. Clean UI, clear docs, and pages that load fast.
Transparent pricing
Every price and limit is on the pricing page. No hidden fees, and no sales gauntlet to find out what it costs.
Careful with your data
A report carries whatever the browser sent — the page URL, the referrer, the user agent — and HeaderHawk records the sending IP with it. None of it is used to track individual people, and none of it is sold. It is deleted on a retention schedule, and the privacy policy spells out exactly what is kept and for how long.
Want to learn more?
Questions about HeaderHawk, or want to talk through a CSP rollout? There is no sales team to get past — it is just me on the other end.