Session replay is only useful if you can trust what it doesn't record. A tool that captures a password once has captured it for as long as the recording exists, in every system the recording passes through. So coview masks in the one place where a secret has never left the person who typed it: their browser.
Why masking on the server is too late
If a value is masked after it arrives, it has already travelled over the network, been received by a server and possibly logged on the way. “We delete it when it gets here” is a promise about every component on the path. Masking in the browser is a promise about one thing: the value is replaced before the recording is built.
What is always masked
Before a recording leaves the page, coview replaces the values of:
- Password and hidden fields, and fields whose
autocompletemarks a one-time code, a new or current password, or a payment card. - Fields that look secret by name. A field whose name, id, placeholder or label mentions a password, PIN, token, card, CVV, IBAN, social security or tax ID is masked whatever its type.
- Card numbers anywhere. A run of 13 to 19 digits that passes the card checksum is masked, even in a field nobody marked.
- Anything typed into coview's own widget.
Addresses are cleaned too: query parameters named like token, session, password or email are dropped from recorded URLs, and so is a fragment that carries parameters.
What you add
You know your pages better than any rule. Mark an element with data-coview-mask and coview never sees its text — not in recordings, not when someone watches live:
<div data-coview-mask>Salary: $84,000</div>
You can also mask every input on a site, and keep whole paths out of recordings.
What we keep about the browser
To make replays useful for debugging, coview keeps the errors and warnings the page logged, and the requests that failed or were slow — their address, status and duration. Request bodies and headers are never recorded.
The same rules, live
The masking that protects a recording also protects a live view. When an agent watches a visitor's tab or co-browses with them, masked fields stay masked on the agent's screen (how co-browsing asks first). And during Take over, an agent never types into password, card, bank or tax-number fields.
The safest copy of a password is the one that was never made.
If your privacy policy needs it, recording can wait for consent: coview('consent', { analytics: false }) keeps it off until the visitor agrees. Our privacy page lists everything coview collects.
Masking is on for every workspace from the first session. Start free and add one script tag, or talk to us about a security review.