All Vendors
session_replay

Contanuity

Contanuity session replay platform deploys comprehensive surveillance infrastructure including behavioral biometrics, session recording, identity resolution, tag management, and consent bypass. The platform demonstrates maximum-risk surveillance patterns.

119 IOCs3 detections33% pre-consent3 sites
70
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Contanuity discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

3 detections across 3 sites33% pre-consent activity
HIGH

Pre-Consent Activity

Contanuity was observed loading and executing before user consent was obtained on 33% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

3 gaps

disclosure

CRITICAL
They Claim

Pending privacy policy review

Observed Behavior

Session recording observed—EXPLICIT disclosure required to avoid wiretapping liability

Customer Impact

What This Means For You

Customers face MAXIMUM regulatory exposure from session recording without consent—creating GDPR Article 5/6 violations, CCPA non-compliance, and severe state wiretapping liability (California Penal Code §632.7, Pennsylvania Wiretap Act, Florida Security of Communications Act). Session recordings capturing form data, authentication credentials, payment information, or search queries create immediate data breach notification obligations. Identity resolution linking anonymous and authenticated sessions creates Article 6(4) compatible purpose violations. Behavioral biometrics may violate Illinois BIPA. Session replay platforms have highest reputational risk if recording becomes public—users perceive session replay as surveillance.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Contanuity

  • IMMEDIATE: Conduct legal review of state wiretapping laws before ANY session recording deployment
  • Verify explicit session recording disclosure exists in privacy policy with prominent user notification
  • Implement strict consent-gating requiring explicit opt-in BEFORE session recording starts
  • Configure aggressive PII masking for ALL form inputs, authentication flows, and payment data
  • Disable identity resolution features—use session-based analytics only without cross-visit linking
  • Deploy IP address anonymization and geolocation masking to prevent visitor identification
  • Enable data minimization controls with maximum 7-day retention and automated deletion
  • Conduct weekly audits of recorded sessions to verify no sensitive data capture occurred
  • Deploy prominent on-page disclosure when session recording is active (e.g., banner notification)
  • Train compliance team on session replay risks and wiretapping liability
  • Consider complete removal if use case does not justify maximum legal exposure

If You're Evaluating Contanuity

  • Request DPA with explicit indemnification for wiretapping liability and GDPR fines arising from session recording
  • Require technical documentation on PII masking capabilities and verification procedures
  • Verify Contanuity honors consent withdrawal with immediate recording cessation and historical data deletion
  • Demand contractual prohibition on using customer session recordings for Contanuity's own UX benchmarking products
  • Assess alternative analytics platforms without session recording (heatmaps, aggregated metrics only)
  • Require technical audit of Contanuity deployment to verify identity resolution and cross-session tracking are disabled
  • Negotiate maximum 7-day retention for session recordings with cryptographic deletion verification and right to audit
  • Request documentation on subprocessor access to session recordings and geographic data storage locations

Negotiation Leverage

  • Contanuity session recording (BTI-C07) creates MAXIMUM wiretapping liability—require contractual indemnification for state law violations and GDPR fines BEFORE deployment
  • Identity resolution (BTI-C14) linking sessions creates unauthorized long-term surveillance—demand technical controls preventing cross-session tracking OR explicit user opt-in for each recorded session
  • Consent bypass (BTI-C09) with session recording active creates automatic legal violations—require technical implementation preventing ANY recording before explicit consent with prominent disclosure
  • Behavioral biometrics (BTI-C06) during recording enables fingerprinting—demand contractual prohibition on using biometric data for visitor identification beyond session context
  • Tag manager (BTI-C15) enables undisclosed script injection—require contractual restrictions preventing any tags beyond core session replay functionality
  • Request documentation on PII masking methodology and verification—demand technical proof that payment data, credentials, and sensitive form inputs are NEVER recorded
  • Negotiate maximum 7-day retention with automated deletion, cryptographic verification, and right to immediate purge upon user request or consent withdrawal
  • Demand prohibition on using customer session recordings for Contanuity's cross-customer UX insights, ML training, or behavioral benchmarking
  • Require real-time user notification when session recording is active (banner, icon, or modal) with opt-out mechanism on every page
  • Request legal opinion from Contanuity counsel on wiretapping compliance in all customer operating jurisdictions
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Captures mouse movements, scroll patterns, keystroke dynamics, and interaction timing during session recording to enable detailed behavioral analysis and user fingerprinting.

BTI-C07Session Recording

Full session replay

Impact: Records complete user sessions including form fills, authentication flows, search queries, and on-page behavior—creating maximum risk of capturing sensitive data without consent.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Initializes session recording infrastructure before consent collection, creating automatic legal violations and wiretapping liability across all recorded sessions.

BTI-C14Identity Resolution

PII deanonymization

Impact: Links session recordings across visits and devices to build unified user profiles, enabling long-term behavioral surveillance without explicit consent for cross-session tracking.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Deploys tag management infrastructure that can dynamically inject additional analytics scripts beyond session replay functionality.

IOC Manifest

IOC Manifest

117 INDICATORS

Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.contanuity.com/assets/js/jquery-2.2.4.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/bootstrap.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/jquery.bootstrap.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/material-bootstrap-wizard.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/jquery.validate.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/mdl/material.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/common-plugins.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/all-plugins.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/owl-carousel/owl.carousel.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/sweetalert/sweet-alert.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/magnific-popup/jquery.magnific-popup.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/jquery.themepunch.tools.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/jwplayer/jwplayer.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/jquery.themepunch.revolution.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.actions.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.carousel.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.kenburn.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.layeranimation.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.migration.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.navigation.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.parallax.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.slideanims.js*
Tracking script
TRACK
*www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.video.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/common.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/all-components.js*
Tracking script
TRACK
*www.contanuity.com/assets/js/main.js*
Tracking script
TRACK
tracking.contanuity.com
Tracking script
TRACK
www.contanuity.com/assets/js/jquery-2.2.4.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/bootstrap.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/jquery.bootstrap.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/material-bootstrap-wizard.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/jquery.validate.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/mdl/material.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/all-plugins.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/common-plugins.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/owl-carousel/owl.carousel.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/sweetalert/sweet-alert.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/magnific-popup/jquery.magnific-popup.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/jwplayer/jwplayer.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/jquery.themepunch.tools.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/jquery.themepunch.revolution.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.actions.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.carousel.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.kenburn.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.layeranimation.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.migration.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.navigation.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.parallax.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.slideanims.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/libs/revolution/js/extensions/revolution.extension.video.min.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/common.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/all-components.js
Auto-extracted from scan
TRACK
www.contanuity.com/assets/js/main.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Contanuity integrates with analytics platforms, user testing tools, customer data platforms (CDPs), and product analytics systems. The platform may share anonymized session data with UX optimization partners. Cross-session identity resolution enables tracking across devices and authenticated/anonymous states. Tag manager functionality allows integration with heatmapping, A/B testing, and conversion tracking tools.
Loads (1)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

119 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details