One capture. Everything it can tell you.
A session contains a vast amount of data and insight. The Platform organises and analyses that information. Every request, every file, every server and every cookie, recorded once and reviewed from more than forty angles.
Ten analysis engines help define the content and see it in separate views. Forty-seven reports across eight sections are available to better understand what is happening in that session. We help you see your data capture in a more informative way.
What the platform does
Various Capture Scenarios
Sites serve different code, different trackers, and different third-party libraries depending on the device, the location and the browser. Producing captures under these various scenarios helps you better understand what your users actually get, when you compare them.
- Capture Plans: reusable browser-interaction scripts that replay identically across versions, producing comparable captures.
- Device Profiles: exact or generated User-Agents with matching client hints, so servers respond as that device would see them.
- Locations: residential, commercial, ISP, or datacenter egress from cities worldwide.
- Pin a page and vary version, country, or device to verify everyone gets the same code.
Risk Factor Analysis on Every Request
The analysis engine profiles the code, the traffic, the payloads, the entities and the infrastructure, and every report in the toolkit is built from what it finds.
- One scale: ten analysis engines roll up to High, Warning and Info, each finding deep-linked to its report.
- Code risks: CSP and SRI weaknesses, HTTPS downgrades, runtime code generation, fetch-to-execute patterns.
- Tracking risks: web beacons, tracking parameters, and fingerprinting in media and POST traffic.
- Evidence only: derived from captured code and traffic, never from build manifests.
Who Is Behind Every Resource
Enrichment on a unique hostname can identify a company. Linking a resource to a company name provides a more thorough account of vendors that the application is dependent on.
- Real entities: enrichment resolves observed domains to companies, software products, and individuals.
- Influence Factors: flags on the parties themselves, ownership, control, sanctions, jurisdiction.
- Deep intelligence: backed by nDiligence profiles, with on-demand enhanced reports and analyst research.
Real-Time Validation and SBOM Generation
Proof that what runs in the browser is exactly what was intended, built from what actually loaded rather than from what a build file claims.
- Validate: as resources load, each response body is hashed with SHA-256 and validated against the Single Source of Truth registry. Known, registered code is identified by software, version, vendor and provenance.
- Generate: SCVue builds an SBOM from what is actually observed loading, and reconciles any declared CycloneDX or SPDX SBOM against it. Shadow dependencies surface instantly.
- Trust: unknown, unverified code is flagged the moment it appears.
Continuous Monitoring
A capture describes the moment it was taken. Once a baseline is established, a scheduled capture is then compared to it for change detection and alerting.
- Every scheduled capture is compared to its baseline the moment it lands.
- Recurring captures baseline every run, compute deltas, and raise alerts on any change.
- Every change raises an alert, deep-linked to the originating record.
Portfolio Scale
Whether you have one or many applications to track, the system allows you to use the same filtering and report-generating features. The tools will scale with you.
- Applications group the way you design them: by department, by business unit, by risk owner, by client, and every rollup report re-groups to match.
- One provider dataset: what you learn about one supplier is valuable information to carry through to others you manage.
- A portfolio-wide view and a single-page view are the same report, not two different tools.
Privacy and Collaboration
Switching between cloud hosting and local hosting is available as you need it. Collaboration is made easy with cloud-based storage.
- Private workspace: all data stays on the client machine.
- Cloud workspace: only scrubbed data ever arrives. The PII scrub runs client-side at promotion and the server re-validates; unscrubbed payloads are rejected.
- Team access, cross-device work, and server-run monitoring and alerting.
Evidence and Export
Nothing in SCVue is an assertion you have to take on trust. Findings trace back to elements found in the capture file, and original content is not modified.
- Every finding links back to the network call that produced it, with its address, headers, content and timestamp.
- Every report exports with all the rows your filters selected, not only the ones on screen. Visual reports export as images.
- The filter selection lives in the page address, so any view can be bookmarked or sent to a colleague.
Multiple Languages
The whole interface, not the navigation with the reports left in English.
- Every report, column header, dialog, empty state and error message, around 1,100 messages per language.
- Numbers, dates, file sizes and sorting follow local conventions rather than the American style.
- Protocol names, header names and standard security terms keep their original form, because translating them makes reports harder to use, not easier.
Start with one capture
A free Community account is available immediately, with a variety of reporting and analysis features available on the same capture. Find out what your first capture can reveal.
One capture is enough to start
Capture a session in the browser, import it, and read what comes back. A free community account is available immediately.