Tagnovo Manifest

A first-party tag reports what real visitors’ browsers loaded on payment pages, with an authorization queue, a named approver and tamper detection.

Checkout coverage

A checkout hosted on another domain cannot be observed by any external scanner. A first-party tag reporting from real visitors' browsers is the only thing that sees it, which is why Manifest exists alongside the scanner rather than inside it.

On the manifestinventory
Waiting for approvalpending
Contents changedhash

Authorized script inventory

A script is discovered, then pending, then authorized. Pending means a named person still has to write why it is allowed on a payment page. A hash change on an authorized script opens a new pending item; the old authorization is not edited.

Scripts appear here once the tag is installed and real visitors have loaded a page in payment scope.

Evidence pack

A PDF of every check in the period, every change, and who reviewed it. SHA-256 stamped so the merchant can prove the file was not edited after it was generated. It is the document an assessor is handed, so it is designed as a document — not as a screenshot of this page.

Installing the tag

One script, one line, or a store-software app install. Never through a tag manager. This is how PCI DSS 6.4.3 and11.6.1 evidence is produced. Tagnovo is not a QSA and does not certify compliance.

Add Manifest