Complete the audit trail with the browser session
Add a continuous browser-side record to the case. Your compliance system still defines the policy, access, retention, and legal meaning around that evidence.
case #AC-2048 · evidence trail
Consent-flow complaint
subject_4f2a · Jul 12
Continuous browser-side record · masking policy attached
Add the browser record to the case
Your compliance system defines the rules, controls, and legal interpretation. rrweb contributes an ordered event stream of the observable browser experience.
- Capture navigation, clicks, inputs, and DOM changes in order.
- Place consent, approvals, and disclosures on the same timeline.
- Keep the open event stream beside policy decisions and backend logs.
session capture · complete record
Open the exact session behind a case
Store a safe subject identifier as recording metadata and mask sensitive fields before events leave the page. Investigators can search by subject, time, or route and open replay at the relevant moment.
- Move from the complaint reference to its session and timestamp.
- Mark consent, approvals, and disclosures as custom events and open that moment directly.
- Show reviewers the browser state around the disputed action.
case #DR-3320 · session search
/checkout
Jul 12, 14:32
/billing
Jul 09, 09:18
/account
Jul 02, 17:04
Apply your retention and access policy
Set a retention window, honour erasure requests by subject, and authorize playback through the same system that owns the case.
- Delete recordings tied to a subject ID when an erasure request arrives.
- Expire sessions against the retention window you set.
- Issue role-scoped playback and log who opened each recording.
governance · acct_8123
replay access log
The session record follows the controls you set
Masking happens in the browser before transport. Your infrastructure or rrweb Cloud stores the events. Your compliance system controls the case, access, retention, and erasure.
Capture
One recorder turns every interaction into an open event stream.
Mask
Sensitive fields leave as placeholders, so secrets never travel.
Your boundary
Store, index, and retain recordings inside your own region.
Self-host or run rrweb Platform in your cloud with a retention window you set.
Replay
Short-lived, role-scoped playback, with every view recorded.
Choose the backend that fits your product
Use managed infrastructure or operate the recording pipeline inside your own boundary.
Start with rrweb Cloud
Use managed ingest, storage, and replay delivery. Masking happens in the browser, while your system keeps the case, retention policy, and access decisions.
rrweb Cloud uses 80% less bandwidth and storage.
Build on open source
Run the MIT-licensed recorder and replayer with your own storage, regional boundary, retention, and access model.
Frequently asked questions
What makes session replay a compliance concern?
A recording is a record of what a real person saw and did, so it is personal data. That is also what makes it useful evidence. The compliance work is deciding what you ever capture, where it is stored, how long you keep it, and who can open it.
Is session replay compatible with GDPR?
It can be, and the implementation decides. Define a lawful purpose, capture only what that purpose needs, mask sensitive fields in the browser before events are transmitted, restrict access and retention, and honour deletion requests. Your legal team should review the final workflow and any consent requirements.
How do I handle a right-to-erasure request?
Store a stable internal subject identifier as recording metadata and resolve real personal details to it on your server. An erasure request then deletes every recording tied to that subject id, and a retention window removes older sessions automatically.
Where is the recording data stored?
Wherever you choose. Self-host the recorder, storage, and replay inside your own region, or run rrweb Cloud for managed ingest and replay. In both cases masking happens in the browser, so the raw sensitive values never reach the store.
Can a recording serve as an audit trail?
rrweb can supply the browser-side record in an audit trail: every captured interaction and interface state in order. Your system adds identity, policy decisions, backend events, access logs, and legal controls. Keep recording limits and masking policy visible in the case.
Can I run the whole system in my own cloud?
Yes. rrweb Platform packages the backend as containers you deploy in your own infrastructure, under a commercial license with full source access, maintenance, and support. The recorder and replayer remain MIT-licensed for teams that build and operate their own backend.
Why rrweb over a packaged compliance or session-replay SaaS?
rrweb supplies the open recorder, event format, and replayer for the compliance workflow you operate. Your system can keep the record in its region and control retention, access, and erasure. A packaged suite supplies a separate console, storage boundary, and policy model.