---
title: Security & masking | ReplayPilot Docs
description: What ReplayPilot masks automatically, and how to mask more yourself.
canonical: https://replaypilot.com/docs/security-masking
---

# Security & masking | ReplayPilot Docs

Search docs…⌘KBrowse docs

Get started
- [Installation](/docs/getting-started)
- [What's new](/docs/whats-new)

Dashboard
- [Replays & the session player](/docs/replays)
- [Errors](/docs/errors)
- [Frustration signals](/docs/frustration)
- [Funnels](/docs/funnels)
- [Releases](/docs/releases)
- [Logs & network requests](/docs/logs)
- [Visitors](/docs/visitors)
- [Heatmaps](/docs/heatmaps)
- [Click map](/docs/click-map)
- [Cohort retention](/docs/cohorts)
- [Projects & project keys](/docs/projects)
- [Alerts](/docs/alerts)
- [Shared links](/docs/shared-links)

Integrations
- [Integrations](/docs/integrations)
- [MCP server](/docs/mcp-server)

Account & data
- [Billing & plans](/docs/billing)
- [Security & masking](/docs/security-masking)
- [Data retention & limits](/docs/retention-limits)
- [Team accounts](/docs/team-accounts)

# Security & masking

What ReplayPilot masks automatically, and how to mask more yourself.

## Masking runs twice

ReplayPilot masks sensitive data in two layers, so one layer can catch what the other misses.

- **In the browser, before anything leaves it.** The snippet masks every input on the page by default. This is what keeps passwords and other typed values out of a recording in the first place. See [Install the snippet](/docs/getting-started) for the snippet that does this automatically, with no setup on your part.

- **On our servers, as a backstop.** Before we store a session, our servers scan every event, redact emails and card numbers wherever they appear, and always strip typed keystroke values. The second layer exists in case something slips past the first.

Network headers use a safe allowlist, not a sensitive-header denylist. ReplayPilot keeps only content-type, content-length, cache-control, and etag, and discards every other request and response header before storage.

Both layers run on every plan, with no setup needed.

## Mask anything else yourself

The two layers above cover passwords, emails, card numbers, and keystrokes automatically. Does your product show other sensitive data on the page, like a support-ticket body or an internal customer ID? Add your own always-mask selectors from the project's Masking tab.

A few rules for the selectors you add:

- List one selector per line.

- Each line is a single #id, .class, or plain tag name, not a combination. Selectors like .card .number or input[type=text] aren't supported, only these three simple forms.

- Masking a parent element also masks everything inside it.

ReplayPilot hides the text inside these elements on every recording, on top of the built-in masking described above.

## Exclude data by path

The project's **Ignored Paths** tab controls collection for matching URL paths. A rule can exclude sessions, logs, errors, frustration signals, or a combination. Use it for routes such as an internal dashboard or account area that should not produce some classes of telemetry at all. Ignoring a session also excludes its logs, errors, and frustration signals.

## What we never capture

We never capture request or response bodies for network calls, so nothing there needs masking. See [Logs & network requests](/docs/logs) for the full picture of what we do log for network activity.

## Encryption

We encrypt integration credentials, like webhook URLs and API keys, before storing them. The dashboard only ever shows a short masked preview of what you entered, never the full value again. Everything travels over an encrypted connection.

## Bot protection on sign-up

Sign-up uses Cloudflare Turnstile, a CAPTCHA alternative, to cut down on automated and bot sign-ups.

## Rate limiting and abuse protection

The endpoint that receives your recorded sessions is rate-limited by IP address. We also cap the size of every session, so one runaway or malicious session can't grow without bound.

## Your data rights

Delete a single session from its playback page, a whole project from Settings, or your entire account from the Danger zone in Settings. All three take effect immediately, and none of them need an email to us. You can also export your account's data as JSON from the same Danger zone. See our [Privacy Policy](/policies/privacy) and [DPA](/policies/dpa) for the full detail on what that covers.

Need your own site's visitors to consent before ReplayPilot records them? Set data-require-consent="true" on the snippet tag. See [Install the snippet](/docs/getting-started) for the turnkey consent banner and the grantConsent() API.

## GDPR and CCPA

ReplayPilot is GDPR and CCPA compliant: self-serve data rights, consent-gated recording where you need it, and an accurate [DPA](/policies/dpa) covering our subprocessors. Both are obligations you meet, not certifications you're awarded, and we meet them.

## What we don't have

ReplayPilot has no SOC 2, SOC 3, or any third-party certification. We're a small product, and we'd rather tell you plainly than let you assume otherwise. That's separate from GDPR and CCPA above, which we do meet. Sign-in supports email/password plus Google and GitHub, not enterprise SAML/OIDC SSO.

Read more about how long we keep your data in [Data retention & limits](/docs/retention-limits).

[← Billing & plans](/docs/billing)[Data retention & limits →](/docs/retention-limits)