OpenReplay

United States · www.openreplay.com · 7 vendors

OpenReplay is an open-source session replay and product analytics platform that enables developers to record, replay, and analyze user interactions on web applications. This helps in troubleshooting issues faster, understanding user behavior, and improving overall application performance. The platform also includes developer tools, performance monitoring, and co-browsing capabilities.

Resilience scores

Disruption prediction

OpenReplay has an estimated 10% probability of disruption in the next 6 months.

5 of OpenReplay's 7 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 7 sub-vendors.

Insights

Last updated 2026-07-29 · revision 3

7 direct vendors, 110 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

OpenReplay exhibits a very high degree of migration readiness, primarily driven by its advanced technological foundation. The internal tech stack, featuring 'Kubernetes', 'Docker', and 'AWS', signifies a highly cloud-native and containerized environment, offering exceptional portability for applications across different cloud providers or on-premise setups. The extensive use of open-source components like 'PostgreSQL', 'Apache Kafka', 'ClickHouse', and 'Redis' further enhances portability and reduces proprietary vendor lock-in at the software level. The architecture, with 'Apache Kafka' for event streaming and 'ClickHouse' for analytics, aligns with microservices principles, making components easier to migrate and scale independently. Achieving 'SOC 2 Type II Compliance' indicates robust controls and processes, which would streamline the compliance aspects of any migration. The presence of a 'REST API' and an 'Integrations & API' ecosystem also suggests a modular design that facilitates integration with new systems. The primary weaknesses include the absence of financial data, which prevents an assessment of the company's capacity to fund a large-scale migration. Additionally, 'Data Residency Requirements: Not specified' means there could be unknown constraints that might complicate migration to certain geographies. While the 'Vendor Lock-in Risk: Unknown' and contradictory vendor count data introduce some ambiguity, the inherent portability of OpenReplay's modern, open-source, and containerized tech stack significantly mitigates these potential risks.

Compliance

8 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

OpenReplay's legal entity is Asayer SAS, a French company (SAS = Société par Actions Simplifiée), governed by French law with jurisdiction in Paris, France. This places it squarely within the EU, making GDPR universally applicable. The company explicitly acknowledges GDPR in its Privacy Policy and Terms of Service, enumerates data subject rights for EU/EEA residents, references Data Protection Officers (DPOs), and stores cloud data on AWS servers in the EU. However, the company also uses third-party processors (Google Analytics, Clearbit, Koala, RB2B) for website visitor tracking, which introduces data transfer and consent risks. The Privacy Policy references DPOs but does not publicly name them or confirm formal DPO appointment as required for certain processing activities. The status is 'Partially Compliant' because while strong structural compliance measures are in place (EU hosting, GDPR rights enumeration, DPA references), full independent audit evidence of GDPR compliance is not publicly available, and third-party data processor usage creates residual risk. Risk is Medium rather than High because the company has clearly invested in GDPR-aligned infrastructure and documentation, reducing the likelihood of material violations.

Evidence: https://www.openreplay.com/legal/privacy, https://www.openreplay.com/legal/terms, https://www.openreplay.com/solutions/size/enterprise

SOC 2 (source) — Compliant

OpenReplay explicitly and prominently displays SOC 2 Type II compliance across its website (homepage footer, enterprise page, Terms of Service Section 13.2). The Terms of Service confirms the certification and states that the SOC 2 Type II audit report is available upon request via security@openreplay.com. SOC 2 Type II is the most rigorous SOC 2 certification, covering a period of time (typically 6-12 months) rather than a point-in-time assessment, and evaluates the operating effectiveness of security controls across the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy). Risk is Low because: (1) the certification is explicitly confirmed in legally binding Terms of Service; (2) SOC 2 Type II demonstrates sustained security controls over time; (3) the audit report is available to customers upon request, indicating transparency; (4) this is a well-established framework with clear compliance evidence.

Evidence: https://www.openreplay.com, https://www.openreplay.com/solutions/size/enterprise, https://www.openreplay.com/legal/terms

CCPA — Partially Compliant

OpenReplay explicitly references CCPA in its Terms of Service as an 'Applicable Data Protection Law' and on its enterprise page as a compliance feature ('GDPR / CCPA'). The Privacy Policy references opt-out mechanisms for US visitors (specifically for RB2B tracking). However, no dedicated CCPA privacy notice, 'Do Not Sell My Personal Information' link, or formal CCPA compliance documentation is publicly available on the website. Risk is Medium because: (1) OpenReplay serves US-based enterprise customers and collects personal data from California residents; (2) the company explicitly acknowledges CCPA applicability; (3) however, the absence of a dedicated CCPA notice and opt-out mechanism on the website represents a compliance gap; (4) CCPA enforcement by the California Privacy Protection Agency (CPPA) has been increasing, with fines up to $7,500 per intentional violation.

Evidence: https://www.openreplay.com/legal/privacy, https://www.openreplay.com/legal/terms, https://www.openreplay.com/solutions/size/enterprise

Financials

Three-year financials

Financial Resilience Score: 5/10

OpenReplay is a privately held, VC-backed open-core SaaS company with no publicly filed financial statements. As a US-domiciled private company not registered with the SEC, it is not required to publish audited financials, making a fully quantitative resilience assessment impossible. The company does show credible signs of commercial traction, including an enterprise customer roster featuring Amazon, NVIDIA, Uber, Mercedes-Benz, LG, Deel, Zscaler, ASUS, and Tekion, plus SOC 2 Type 2 attestation that removes friction in enterprise sales cycles. Strategically, the open-source distribution model provides a low-cost customer acquisition channel, and the self-hosting capability creates a structural moat in regulated industries versus SaaS-only competitors like FullStory, LogRocket, and Hotjar. Product breadth has expanded from core session replay into product analytics, co-browsing, a mobile SDK, an AI assistant (kAI), and a screen-capture tool (Spot), creating cross-sell opportunities. However, the company operates in a highly competitive category against well-funded incumbents and free alternatives like Microsoft Clarity. Open-core cannibalization risk, dependence on VC funding cycles for runway, and AI-related variable costs from third-party LLM APIs pressure margins. Private-company opacity itself is a mild negative in vendor risk reviews. Overall resilience is moderate, with clear go-to-market strengths offset by unverifiable unit economics.

Key strengths: Open-source distribution channel drives low-CAC developer adoption, Enterprise logos landed including Amazon, NVIDIA, Uber, Mercedes-Benz, Deel, Zscaler, SOC 2 Type 2 compliance enables enterprise sales, Self-hosting differentiator in regulated industries, Product breadth expansion into analytics, co-browsing, AI (kAI), and Spot

Risk factors: Highly competitive category with well-funded incumbents (FullStory, LogRocket, Hotjar, PostHog, Mixpanel, Amplitude, Datadog RUM), Free alternative Microsoft Clarity pressures pricing, Open-core cannibalization risk from generous free self-hosted tier, Private-company opacity limits external financial assessment, Funding-market dependence for cash runway, AI cost pressure from third-party LLM APIs on gross margin

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report