Reduce sensitive data exposure with build-time allowlists
Blog post from Datadog
Datadog’s build-time allowlisting feature for Browser SDK v7 aims to preserve readable Real User Monitoring action names while limiting exposure of sensitive runtime-generated data. When applications use the `mask-unless-allowlisted` privacy setting with action-name privacy enabled, a build plugin analyzes compiled artifacts and source maps to extract static application text, such as fixed labels, into an allowlist; the SDK then displays only matching text while masking unknown, dynamic, or customer-specific values in both RUM and Session Replay. This approach reduces reliance on potentially error-prone HTML privacy overrides, allowing teams to retain useful context such as “Click on Checkout” while concealing values like prices, addresses, and other runtime data. The plugin supports ESBuild, Rollup, Rspack, Vite, and Webpack, can be incorporated into CI/CD workflows, and offers include, exclude, and code-level opt-out controls to fit different application structures and privacy requirements.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Observability | 1 | 3,175 | 737 | 186 | -24% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.