Local-first by design
Everything Replay records is stored on your machine in a single file. No accounts, no cloud, no telemetry you didn't ask for.
AI Detection & Response
Replay watches what your AI agents do: the commands, files, and URLs they touch. Detection rules run locally, sessions rebuild from saved history, and you can opt into blocking per rule.
Free and local-first. Nothing leaves your machine unless you say so.
How it works
Replay sits between the agent and the system: it watches and records, and only blocks when you opt in.
Everything Replay records is stored on your machine in a single file. No accounts, no cloud, no telemetry you didn't ask for.
Monitoring keeps running even when the app is closed, so nothing slips through while you're away.
A built-in rule catalog, plus your own policy, runs locally against every action. Opt into blocking per rule, or stay monitor-only.
Alerts reconstruct into full session timelines: every tool call, command, and file touched, in order.
Observed domains, IPs, URLs, and hashes are matched against the Threat Landscape feed and surfaced as enriched alerts.
Wired doesn't mean working. A per-agent self-test confirms the connector really sends records, and a staleness flag catches silent failures.
Download
The binary includes the interface and the detection engine, so one tarball is all you need. No accounts, no installers that phone home.
requires libwebkit2gtk-4.1 + libgtk-3 runtime
single .exe, self-contained
arm64 (Intel Macs: check back)
The app checks /replay/latest.json for new versions and surfaces them in Settings → Updates.
Enterprise
The free app stays fully local. The enterprise tier adds managed services on top: same engine, central control.
Central visibility over agent activity across every installation: alerts, observables, enforcement, and events, redaction-first.
Distribute operator policy centrally, assign per team or host, and audit which rule/version was effective, where, and when.