Local-first by design
Everything Replay records is stored on your machine in a single file. No accounts, no cloud, no telemetry you didn't ask for.
AI Detection & Response
Replay watches what your AI agents do: the commands, files, and URLs they touch. Detection rules run locally, sessions rebuild from saved history, and you can opt into blocking per rule.
Free and local-first. Nothing leaves your machine unless you say so.
How it works
Replay sits between the agent and the system: it watches and records, and only blocks when you opt in.
Everything Replay records is stored on your machine in a single file. No accounts, no cloud, no telemetry you didn't ask for.
Monitoring keeps running even when the app is closed, so nothing slips through while you're away.
A built-in rule catalog, plus your own policy, runs locally against every action. Opt into blocking per rule, or stay monitor-only.
Alerts reconstruct into full session timelines: every tool call, command, and file touched, in order.
Observed domains, IPs, URLs, and hashes are matched against the Threat Landscape feed and surfaced as enriched alerts.
Wired doesn't mean working. A per-agent self-test confirms the connector really sends records, and a staleness flag catches silent failures.
Product
One window for everything your agents did, and everything you should know about it.



Coverage
On-demand rebuilds activity from an agent's saved history. Live captures as it acts. Enforcement can block an action when you deploy a rule in enforce mode.
| Agent | On-demand | Live | Enforcement |
|---|---|---|---|
| Claude Code | ✓ | ✓ | ✓ |
| Claude Cowork | ✓ | — | — |
| Codex | ✓ | ✓ | ✓ |
| Gemini CLI | ✓ | ✓ | ✓ |
| Cursor | ✓ | ✓ | ✓ |
| Windsurf / Cascade | ✓ | ✓ | ✓ |
| GitHub Copilot CLI | ✓ | ✓ | ✓ |
| VS Code Copilot Chat | — | ✓ | ✓ |
| OpenCode | ✓ | ✓ | — |
| OpenClaw | ✓ | ✓ | ✓ |
| Pi | ✓ | ✓ | ✓ |
| Kimi Code | ✓ | ✓ | ✓ |
| Antigravity | soon | ✓ | ✓ |
| Amp | soon | ✓ | ✓ |
| Auggie | soon | ✓ | ✓ |
| Cline CLI | soon | ✓ | ✓ |
| Crush | soon | ✓ | ✓ |
| Devin CLI | — | ✓ | ✓ |
| Factory Droid | soon | ✓ | ✓ |
| Goose | soon | ✓ | ✓ |
| Grok Build | soon | ✓ | ✓ |
| Hermes | soon | ✓ | ✓ |
| Junie CLI | soon | ✓ | ✓ |
| Kilo Code | soon | ✓ | ✓ |
| Kiro IDE / CLI | soon | ✓ | ✓ |
| OpenHands | soon | ✓ | ✓ |
| Qwen Code | soon | ✓ | ✓ |
Download
Replay ships as one file that includes the interface and the detection engine. No accounts, no installers that phone home.
needs the WebKitGTK runtime, which most desktops already have
single .exe, self-contained
arm64 (Intel Macs: check back)
Replay checks for updates automatically and shows new versions in Settings.
Free for non-commercial individual use. For commercial use, contact [email protected]. License · Third-party notices
Enterprise
The free app stays fully local. The enterprise tier adds managed services on top: same engine, central control.
Central visibility over agent activity across every installation: detections, observables, blocked actions, and raw events, with sensitive values redacted.
Distribute your rules centrally, assign per team or host, and audit which rule version was effective, and where and when.