Enter Something Here

Dynamic Website Archiving: Why Having a Replayable Viewer Is Critical for Compliance

By Hanzo Team 8 min read
computer screens with calculators

In an SEC or FINRA examination, an examiner can ask a firm to reproduce a specific webpage as it appeared on a specific date. A screenshot saved from that page shows what was on screen at the moment someone captured it. It does not show whether a script rendered different content for a different visitor or different location, or if there’s a filter applied, a disclaimer icon or whether the file itself has been altered since it was saved. Dynamic website archiving addresses that gap by capturing a page’s underlying source, replaying it as it behaved on the day it was captured, and attaching a verifiable timestamp to the record.

In addition, if a calculator was used to show ROI results or projected 401k examples based on specific input, a screenshot does not allow you to revisit the same experience. However, a replayable viewer allows an auditor to revisit the same experience as that visitor did at that point in time and recalculate the same results based on the calculator’s key inputs.

What is Dynamic Website Archiving?

Dynamic website archiving is the automated, scheduled capture of a website’s pages, including interactive and personalized elements, stored in a format (commonly WARC) that allows the page to be reconstructed and navigated later, instead of being viewed as a static image. The capture holds the page’s scripts and files as they were at that moment, so the live site can change afterward while the archived version stays intact, and an auditor can revisit it as if the site were still live.

The Importance of Dynamic Website Archiving

Dynamic website archiving is built to answer the question a screenshot or PDF cannot: what did this page show, and can you prove the record hasn’t changed since. Modern dynamic preservation tools capture each page in WARC format, record a SHA-256 hash value and a timestamp at the moment of capture, and store the result on WORM (write once, read many) storage, so the file itself cannot be altered or deleted before its retention period expires.

The replay step matters as much as the capture. Instead of a flat image, a reviewer opens the archived page as if it was  in its original state: scrollable, with working menus, filters, carousels, calculators, disclaimer icons, and forms, as it existed on the date of capture. That reconstruction is what lets a compliance team or a regulator navigate a historical page the way a visitor actually experienced it, instead of reconstructing it from a static file.

Do Screenshots Remain the Default? And Where Do They Fall Short?

Teams tend to reach for screenshots by default because they are familiar and require no new tooling. For a static page with no interactive elements, that may be adequate.

For anything more complex, Hanzo’s audit-readiness solutions address the pattern directly. A screenshot removes critical context and captures the page as a flat image, so the relationships between the pieces of a page are lost. A screenshot also carries no embedded proof of when it was captured or whether it has been edited since. If a regulator asks a firm to demonstrate that a record has not been altered, a screenshot’s metadata alone does not answer that question.

Compliance Rules for Dynamic Website Archiving

For broker-dealers, SEC Rule 17a-4 requires that certain business records, including electronic communications, be preserved in a non-rewriteable, non-erasable format for a defined retention period. FINRA Rule 2210 governs communications with the public, including firm websites, and requires those records to be retained in the manner Rule 17a-4 sets out. A website that changes weekly, or daily, falls under the same retention logic as an email or a trade confirmation. Namely, a record has to exist of what was published, and it has to hold up as unaltered.

Hanzo’s guide to WORM compliance walks through how these obligations apply across email, collaboration tools, websites, and social platforms, and where traditional archiving tools fall short once the underlying data is dynamic.

Screenshots vs. Dynamic Archiving, Side by Side

  Screenshots Dynamic Archiving
Captures One rendered view Underlying source (WARC), reconstructable
Interactive elements Flattened or missing Preserved and functional on replay
Timestamp integrity File metadata only Timestamp bound to capture, e.g., SHA-256 hash
Tamper evidence None built in WORM storage, hash verification
Scale Manual, one page at a time Scheduled, automated crawls across a domain

Signals a Screenshot No Longer Meets Regulatory Requirements

A few conditions tend to show up together when screenshots stop being sufficient. The organization sits under SEC, FINRA, PCAOB, FTC, or FDA recordkeeping expectations. The website updates on a regular cadence rather than staying static for months at a time. Pages include scripts, personalization, or interactive tools that a screenshot cannot represent. Or a team has already had to explain, during an audit or investigation, why a saved image cannot prove what a page displayed on a given date.

A major airline ran into this exact pattern. Its website changes regularly and is owned by multiple departments, and the legal and compliance team needed the ability to revisit any page as it appeared on a specific date instead of relying on manual captures.

How Chronicle Automates Dynamic Website Archiving

Hanzo Chronicle automates the capture described above: scheduled crawls across a domain, WARC-format storage, SHA-256 hashing, and WORM retention, paired with a replay viewer for review. It’s built for the dynamic website preservation and review use case specifically, including sites with authenticated journeys, calculators, and content that varies by visitor.

Frequently Asked Questions

Is a screenshot a substitute for dynamic website archiving?

A screenshot captures what was visible in one browser at one moment, but it does not preserve interactive elements, embedded metadata, or proof that the file hasn’t been altered since capture, which is what dynamic website archiving is built to provide under rules like SEC 17a-4.

Why do I need a replayable viewer?

A replayable viewer reconstructs the archived page from its stored requests and responses, so dropdowns, sliders, forms, and linked pages work as they did at capture. Without one, a WARC file holds the data but no one can see what the page displayed on a given date.

Why are dynamic captures important for compliance?

Recordkeeping rules ask a firm to show what a record contained on a specific date, and a site that changes regularly makes that hard to prove afterward. A dynamic capture records the page as it appeared that day, including the scripts and interactive elements a static image drops, tied to a timestamp and a SHA-256 hash. When an examiner asks what a page said on a given day, the firm produces the record rather than reconstructing it.

Does this include internal websites or intranet sites that may be subject to compliance?

Yes, when the intranet hosts content a rule reaches, such as supervisory procedures or communications retained under SEC Rule 17a-4. Dynamic website archiving captures internal pages the same way it captures public ones, so a page behind authentication is preserved with the same timestamp, hash, and replayable format.

How does dynamic website archiving prove a page wasn’t altered? By recording a cryptographic hash, such as SHA-256, at the moment of capture and storing the file on WORM (non-rewriteable, non-erasable) storage. Comparing the hash later confirms whether the archived record matches what was originally captured.

What file format does dynamic website archiving rely on? Most dynamic website archiving platforms store captures in WARC (Web ARChive), the ISO 28500 format that preserves a page’s underlying requests and responses rather than a flattened image, so the page can be reopened and navigated later, unlike a screenshot.

Which regulations require dynamic website archiving? Broker-dealers fall under SEC Rule 17a-4, which requires certain records to be preserved in a non-rewriteable format. FINRA Rule 2210 extends that requirement to firm websites as public communications, so a site that changes regularly needs the same retention treatment as an email or a trade confirmation.

The Bottom Line

A PDF export can still answer what a page looked like at one moment. It can’t answer whether that’s still what the page showed a week later, or whether the file itself has changed since. Teams that need an answer to both can request a Chronicle demo and run the comparison against their own site.

Sources

Hanzo Team
Your Trusted Legal Data Management Partners

Our game-changing solutions enable rapid data discovery at unprecedented scale, with impressive speed and relevancy. Contact us to learn more.