Comparison matrix
How ShieldReplay compares to session replay (LogRocket) and client-side WAF tools for modern web apps.
| Capability | LogRocket (typical) | ShieldReplay |
|---|---|---|
| Session replay | Yes | Yes |
| Developer timeline (network, console) | Yes | Yes |
| User identification | Yes | Opt-in identify() |
| Client-side WAF + probes | Limited | Built-in |
| Security incidents on replay | Add-ons | Yes |
| Workflow automations | Integration marketplace | Automation Studio + Integrations |
| Slack / Jira / Datadog | Marketplace connectors | Per-site connect + automation actions |
| Self-hosted / private cloud | Enterprise contract | Docker Compose |
| SSO / SAML | SAML + OIDC | OIDC (Okta, Azure AD, Google) — Org admin |
| Org-wide team admin | Teams & roles | Organization + invites |
| Origin-locked ingest | Domain allowlist | Allowed domains list |
| Usage metering | Sessions | Sessions & events |
| Scrollmaps & scroll depth | Yes | Product analytics |
| User path / flow analysis | Yes | Sankey-style flows |
| Advanced session filters & cohorts | 50+ filters | Saved cohorts |
| No-code metric definitions | Inspect tool | Replay + CSS selectors |
| Error grouping dashboard | Yes | Errors tab |
| Performance & network analytics | Waterfall + vitals | Replay + Perf tab |
| NPS / VoC → session link | Integrations | ShieldReplay.feedback() |
| Shadow DOM / iframe / canvas capture | Mature recorder | Same-origin iframe inline, shadow flatten, canvas snapshots |
Where ShieldReplay is stronger
- You need security signals and UX friction in one investigator workflow.
- You want automated response (webhooks, ticketing) tied to replay context.
- AppSec wants probe visibility without losing product analytics.
- You need explicit allowed-origin enforcement so a stolen site token cannot ingest from arbitrary domains.