ScreenshotNeo

BlogHow-to

How to keep a history of recurring website screenshots for compliance

Build a repeatable screenshot record with clear context, protected originals, an approved retention schedule, and a process you can retrieve and review.

By the ScreenshotNeo team4 October 202610 min read

To keep a useful history of recurring website screenshots, capture the same defined pages on a documented schedule and preserve each original with a manifest that identifies the page, capture time and time zone, capture method, and responsible person or system. Store records in a controlled, backed-up repository with an approved retention schedule, access controls, integrity checks, and a tested retrieval and export process.

A screenshot alone does not prove who captured it, whether its timestamp is trustworthy, or whether it accurately represents the live page at that time. Retention and compliance obligations depend on the applicable jurisdiction, industry, record type, and approved schedule. The workflow below helps establish reliable records; it does not determine which rules apply to your organization.

1. Decide what the screenshot record needs to show

Start with the business question. A capture intended to show a disclosure or pricing page may need only a readable visual record. A record intended to show navigation, linked documents, or interactive behavior may require a richer web archive alongside the screenshot.

  • List the pages and page states to capture, including relevant locales, logged-in states, and device layouts.
  • Identify the business activity each page documents and the record owner.
  • Decide whether the record must preserve visual appearance, links, interactions, or website-management context.
  • Determine which law, contract, internal policy, or approved schedule controls retention and disposition.

NARA guidance for federal agencies emphasizes authenticity, reliability, documented controls, and capture fidelity. Its federal retention guidance is not a universal schedule for private organizations. NARA also notes that permanent federal web content should retain hypertext functionality, such as through harvesting; treat that as a fidelity consideration when deciding whether a screenshot is enough. NARA guidance on managing web records

2. Define a repeatable capture event

Write down the cadence, capture configuration, and exception procedure. Use the same settings each time when comparing visual changes. Record changes to the process, such as a different viewport, consent-banner handling, authentication method, or capture tool, because those differences can affect what the image shows.

A practical manifest can be JSON, CSV, or repository metadata. These fields are an operational recommendation; the cited sources do not prescribe this exact schema.

{
  "record_id": "pricing-page-2026-10-04T09:00:00Z",
  "page_url": "https://example.com/pricing",
  "captured_at": "2026-10-04T09:00:00Z",
  "time_zone": "UTC",
  "capture_method": "scheduled browser capture",
  "capture_configuration": {
    "viewport": "1440x900",
    "full_page": true,
    "locale": "en-US"
  },
  "operator_or_system": "scheduled-capture-job",
  "business_owner": "web-compliance",
  "file": "pricing-page-2026-10-04T09-00-00Z.png",
  "sha256": "...",
  "notes": "No capture exception"
}

Use an unambiguous timestamp such as ISO 8601 with a time-zone offset. Record the requested URL and, where available, the final URL after redirects. If the page depends on login, locale, geolocation, consent, or a user interaction, record the relevant state without placing passwords, session tokens, or other secrets in the manifest.

3. Capture on a schedule and preserve the original

  1. Choose a cadence based on the business purpose and applicable requirements. There is no universal interval for all pages.
  2. Run the capture through an authorized account or system with a documented owner.
  3. Save the returned original file and its manifest together under a stable record ID.
  4. Record failures, skipped captures, and material configuration changes. Do not silently substitute a later successful capture for a missed scheduled event.
  5. Restrict changes and deletion to authorized roles, and retain a log of important actions.

Where a process needs repeatable local browser automation, Playwright can capture a page to an image. Install it with npm init -y and npm install playwright, then install a browser with npx playwright install chromium. Save this as capture.mjs and run node capture.mjs https://example.com/pricing.

import { chromium } from 'playwright';
import { createHash } from 'node:crypto';
import { mkdir, writeFile } from 'node:fs/promises';

const requestedUrl = process.argv[2];
if (!requestedUrl) throw new Error('Usage: node capture.mjs <url>');

const capturedAt = new Date();
const stamp = capturedAt.toISOString().replaceAll(':', '-');
const outputDir = 'records';
await mkdir(outputDir, { recursive: true });

const browser = await chromium.launch({ headless: true });
try {
  const page = await browser.newPage({ viewport: { width: 1440, height: 900 } });
  const response = await page.goto(requestedUrl, {
    waitUntil: 'networkidle',
    timeout: 60000
  });
  if (!response || !response.ok()) {
    throw new Error(`Navigation failed: HTTP ${response?.status() ?? 'no response'}`);
  }
  await page.screenshot({ path: `${outputDir}/${stamp}.png`, fullPage: true });
  const image = await (await import('node:fs/promises')).readFile(`${outputDir}/${stamp}.png`);
  const manifest = {
    requested_url: requestedUrl,
    final_url: page.url(),
    captured_at: capturedAt.toISOString(),
    time_zone: 'UTC',
    capture_method: 'Playwright with Chromium',
    capture_configuration: { viewport: '1440x900', full_page: true },
    operator_or_system: 'scheduled-capture-job',
    http_status: response.status(),
    file: `${stamp}.png`,
    sha256: createHash('sha256').update(image).digest('hex')
  };
  await writeFile(`${outputDir}/${stamp}.json`, JSON.stringify(manifest, null, 2));
} finally {
  await browser.close();
}

This example is a starting point, not a complete records-management system. Add authorization, approved scheduling, protected storage, exception reporting, and retention controls appropriate to your organization. Playwright screenshot documentation

4. Protect integrity and provenance

Keep the original capture and its identifying metadata together. Limit write and delete permissions, log important changes, and preserve process documentation. A SHA-256 checksum can detect whether file bytes changed after the checksum was calculated. Recompute it during integrity checks and compare it with the stored value.

A matching checksum does not prove that the capture accurately represented the live site, that the clock was trustworthy, or that a record is legally admissible. It only supports a claim about whether those bytes changed since the hash was made. The checksum example in 36 CFR 1236.42 applies in a specified digitization context; it does not require hashes for recurring website screenshots.

5. Choose a retention and storage plan

Do not choose a retention duration by copying a number from another organization or a federal schedule. Confirm the applicable requirements with the people responsible for records, legal, privacy, and compliance decisions. Document the approved period, trigger for starting it, any hold that suspends disposition, and who authorizes destruction.

For each record class, specify:

  • Where the original and manifest are stored.
  • Who can view, export, alter, or delete them.
  • How backups and recovery are handled.
  • How a legal or investigation hold affects deletion.
  • Which readable and exportable formats will remain available.
  • How and when authorized disposition occurs, with evidence of the action.

For records within its scope, 21 CFR Part 11 addresses controls including accurate and complete copies, access limits, audit trails, and retrieval throughout the retention period. It does not make every screenshot subject to Part 11. FDA’s Part 11 document is nonbinding guidance and describes the agency’s stated enforcement-discretion approach for certain requirements; underlying predicate-rule duties remain relevant. 21 CFR Part 11 · FDA Part 11 Scope and Application guidance

E-SIGN provides a retention path for covered transactions when a retained electronic record accurately reflects the information and remains accessible in a form capable of accurate later reproduction for the required period. Scope and exceptions matter. It is not a universal screenshot-retention rule. E-SIGN Act, section 101(d)

6. Make retrieval and review part of the process

A record that cannot be found or read when needed is a weak recordkeeping outcome. Test retrieval using realistic questions, such as “show the pricing page capture for this date range” or “export all captures for this page and their manifests.” Verify that exports retain the original file and enough context to interpret it.

  • Check that scheduled captures ran and that expected metadata exists.
  • Sample files and recompute stored checksums.
  • Test a restore from backup and retrieval from the repository.
  • Confirm access lists and retention rules still match current responsibilities.
  • Review capture failures and changes to page, tool, or configuration.
  • Document findings and corrective actions.

Choose a review frequency based on the organization’s risks and approved process; the cited sources do not prescribe a universal review interval. GSA also notes that web records can document website management, not just displayed content. GSA web records

7. Evaluate a capture method or service

Ask for a demonstration using pages representative of your real capture needs. Compare:

Area Questions to answer
Capture fidelity Does it handle long pages, lazy-loaded content, redirects, consent states, and relevant interactions?
Context Can you retain the requested and final URL, timestamp and zone, configuration, operator or system, and exceptions?
Integrity and access Can the original and metadata be protected, access restricted, and important changes logged?
Retention and retrieval Can your approved schedule be applied, records searched, and past records retrieved reliably?
Export and readability Can you export complete records in formats that preserve their content and meaning?
Functional evidence If links or interaction matter, does the method preserve more than a flat image?
Exceptions How are bot checks, blank pages, timeouts, failed loads, and missed runs reported?

These evaluation questions follow from recordkeeping and fidelity concerns in NARA, Part 11, and FDA guidance. They are not claims that any vendor has been validated against them.

Or skip the browser setup

For a straightforward recurring image capture, ScreenshotNeo provides a website screenshot API and MCP server. A single GET request returns a screenshot or PDF. See the ScreenshotNeo API documentation for request options. This example is a capture call; your organization still needs to define its schedule, manifest, retention, access, and retrieval process.

curl -G "https://api.screenshotneo.com/v1/shot" \
  -d access_key=YOUR_API_KEY \
  --data-urlencode url=https://example.com/pricing \
  -o pricing.webp
import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://example.com/pricing"},
    timeout=90,
)
r.raise_for_status()
with open("pricing.webp", "wb") as f:
    f.write(r.content)
const q = new URLSearchParams({
  access_key: 'YOUR_API_KEY',
  url: 'https://example.com/pricing'
});
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('pricing.webp', res);

ScreenshotNeo removes cookie and consent banners, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server offers take_screenshot, get_page_info, and capture_pdf for AI agents. The free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. See ScreenshotNeo for the service and the API options. For compliance records, save the returned original with your own manifest and apply your approved controls.

Sign up for 1,000 free screenshots a month, with no card.

Troubleshooting recurring captures

Symptom Likely cause Fix
Capture is blank or incomplete The page had not rendered, required authentication, or delayed content was not ready. Check the final URL and response status, use an appropriate wait condition, and record authentication and page-state assumptions. Review the resulting image before accepting it as a record.
Images or content are missing on long pages Lazy-loaded resources may only load as the page is scrolled. Use a full-page capture method that loads lazy content, or add a documented scroll-and-wait step. Keep settings consistent across the series.
Captures differ unexpectedly Viewport, locale, timezone, consent state, personalization, or page content changed. Compare manifests and configuration; record the relevant page state. Do not treat every pixel difference as a site change until capture conditions are checked.
Scheduled run is missing Job failure, access change, network issue, or scheduler configuration error. Alert on missing expected records, preserve the failure details, and distinguish a missed capture from a successful later run.
Checksum does not match The file changed, was corrupted, or the wrong file was compared. Preserve the current bytes for investigation, check identifiers and storage logs, and do not overwrite the original. Recalculate only after resolving the cause and document the event.
Old records cannot be opened or exported Format support, repository permissions, or export procedures changed. Test readable copies and exports periodically, retain needed software or format guidance, and document migration while keeping provenance and originals according to policy.

Performance, reliability, and cost

Capture frequency, page count, full-page rendering, and readiness waits drive workload. Start with the pages and cadence justified by the business purpose. Avoid launching overlapping jobs for the same page if they compete for resources or create ambiguous records. A useful system reports each expected run as captured, failed, or intentionally skipped.

Keep the capture pipeline separate from the repository’s preservation duties: a successful image response does not itself create an approved retention schedule, immutable record, trusted timestamp, backup, or audit trail. Budget for capture requests, storage growth, backup, retrieval, and any richer web-archive format needed to preserve links or interactions. For ScreenshotNeo pricing, the free tier is 1,000 shots monthly; paid plans are Starter $5 for 3,000, Growth $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000, and Business $249 for 1,000,000. Yearly billing gives two months free, and every feature is on every plan. Confirm the current plan details on the ScreenshotNeo site.

FAQ

How do I keep a record of website changes?

Capture defined pages on a repeatable schedule, retain each original with a context manifest, and preserve the sequence in a repository where records can be searched and retrieved. Add a richer web capture if the change history must show links or interactive behavior.

How long should compliance screenshots be kept?

There is no universal period in the sources discussed here. Follow the requirement and approved schedule that apply to your jurisdiction, industry, record type, contract, and policy.

Is a screenshot enough to prove what a website displayed?

It can document visual appearance, but by itself it does not establish capture provenance, clock accuracy, or that the image faithfully represents the live page at a claimed time. Preserve context and controls, and use richer capture when the evidence requires links or interaction.

Does Part 11 apply to every website screenshot?

No. Applicability depends on whether the electronic record and activity fall within Part 11’s scope and the underlying requirements. FDA guidance is nonbinding and should not be treated as a blanket exemption.