Compare what the browser actually observed.

Keep capture context, network observations and reviewer conclusions separate. An investigation helps explain a discrepancy; it is not a compliance certificate.

Collect comparable captures

  1. 1

    Get authorization and define one question

    Use an approved test account and target page. Avoid real customer sessions. Open an investigation for that property and state the discrepancy you want to explain.
  2. 2

    Record the context

    Keep the URL, browser/version, region, login state, environment, cache conditions and observation window consistent. Record the configuration version when known. Leave unknown facts blank rather than guessing.
  3. 3

    Capture one labeled scenario per file

    Use distinct labels for pre-installation baseline, installed-before-choice, reject optional, accept, granular choices, withdrawal and return visit. A withdrawal capture must follow a grant in the same browser history. A fresh rejected session is not a withdrawal test.
  4. 4

    Export a sanitized HAR

    Use the Network panel of browser developer tools and export the recorded requests as a sanitized HAR. Use the same recording duration and navigation sequence for the comparison. The app accepts an ordinary uncompressed HAR file, not a ZIP or a screen recording.

Chrome’s sanitized export omits sensitive headers such as Authorization, Cookie and Set-Cookie. Other fields can still contain personal information; “sanitized” does not mean anonymous or complete. See the Chrome HAR export reference.

Review locally before uploading

Choose or drop a HAR into the investigation. Parsing and the initial redaction happen in your browser. The preview shows 100 normalized observations per page and lets you exclude individual requests. Use Previous requests and Next requests to inspect the whole capture. Review paths, cookie names, hostnames and your manually entered context; the preview is not an anonymity guarantee.

The retained allowlist contains redacted host/path, request method/type, available status and duration, timestamps, safe MIME type, an optional redacted initiator URL and cookie names. Request/response bodies, captured HTML, header values, cookie values, URL credentials, fragments and query strings are discarded. Likely identifiers in paths are masked. Unknown fields remain unknown.

Review is still required

Automated rules cannot recognize every personal name or identifier. Exclude questionable observations or prepare a smaller sanitized capture before confirming upload. Do not put secrets in titles, context fields or notes. StrongPrivacy validates and redacts again on the server, never replays captured URLs, and does not send evidence to an AI service.

Cancel reading to choose another file. Cancel upload stops your browser’s request, but a save already accepted by the server may still finish; check the capture register before retrying. Duplicate evidence with the same scenario is rejected, including duplicates whose payload has already expired.

Understand the pilot limits

  • 10 MiB uncompressed input and at most 20,000 requests in one capture.
  • Six available captures per investigation, with a 50 MiB retained-evidence allowance per workspace. Use a follow-up investigation for another question.
  • At most 50 active investigations per workspace. Close a completed case before opening another at the limit.
  • Payloads expire after 30 days and become unavailable immediately at expiry. StrongPrivacy then removes the stored payload; hashes, metadata and attributed review history remain.
  • Manual deletion also removes only the evidence payload. It does not erase the investigation’s review history or separately retained consent receipts.

Thirty days is how long StrongPrivacy keeps an investigation's captured evidence, not a legal rule; set your own retention policy with your counsel. Deleted evidence can remain in backups until those backups expire.

Interpret differences carefully

Select two captures and compare. Filter by host, provider or path, request type, observation change and specialist review status. Results are paginated in groups of 100. Repeated requests remain counted; a new count is not automatically a new provider.

Matching uses normalized host/path, method and type. Query removal and path masking can group different original URLs together. “Only in baseline” means not observed in the comparison capture, not proven blocked. “Changed” can mean a different request count, status or available cookie names. Missing cookie/header data must not be read as an empty cookie jar.

Warnings identify unknown or different context. Catalog categories are suggestions, separate from attributed specialist reviews. Unknown providers remain unknown until reviewed. Opening a capture shows the retained observations and their resource keys for precise notes.

A completed scanner state can also be imported from the same property. Scanner requests do not contain all HAR fields; absent methods, status, cookies and timings stay unavailable. Browser cookie/storage snapshots remain in the original scan report as a separate evidence channel.

Review, export and hand off

Customers can add notes. Assigned specialists can classify a known resource and record “needs attention,” “explained” or “inconclusive,” with a reason. Reviews append to history instead of erasing earlier conclusions. A needs-attention review can create an operational notification when the workspace’s high-impact alert preference is enabled; emails do not include captured requests or review notes.

Link the investigation to a configuration candidate before approval. Download a summary in JSON or CSV to share context, limitations, reviewers and linked configurations. Per-capture downloads contain normalized observations, not the original HAR. Exports are authenticated, workspace-scoped and audited. Treat downloaded files as sensitive and share them only with authorized recipients.

The register shows the latest 100 investigations and each case shows the latest 100 reviews. A summary includes up to 1,000 historical capture records and reviews, plus the latest 100 linked configurations. Exports flag when configuration links are truncated; these pilot limits are not an unlimited archive.

Close the investigation once the question is addressed. Closing does not publish a consent configuration, certify the site or stop retention. Reopen it to add further evidence or a new review.

Understand review and publication →