Buyer's guide

Government social media archiving buyer's guide

The short version: a defensible archive captures official-account activity as it happens, including edits, deletions and comments from the public, preserves the metadata that proves authenticity, and produces a request-ready export in minutes. This guide turns that into evaluation criteria, vendor questions and a 90-day evaluation plan your records officer can sign off on.

Why archive social media at all?

You already know your records law; this is about what it implies for social channels. Content created or received in the course of official business can qualify as a record under federal law and the public records laws of all 50 states — whether it lives in an email, a document or a social media thread. Social makes that hard in a specific way: the content changes after publication. Posts are edited, comments arrive and disappear, threads carry the context. A record that must be producible later has to be captured as it happened, not reconstructed afterwards.

Your own state's statute, response deadline and oversight guidance are summarized, with sources, in the 50-state law guides.

What must a defensible archive preserve?

Whatever vendor you choose, hold the archive to this standard:

  • Everything, not just posts — comments, replies and reactions from the public, shared images and video, and direct messages where the platform API provides them.
  • Edits as versions — every version of an edited post, with the change visible, not just the latest state.
  • Deletions preserved — the deleted content and the fact of its deletion.
  • Context intact — a comment attached to its post and thread, because a record out of context is a weaker record.
  • Metadata and timestamps — author, time, platform identifiers, kept with each item.
  • Integrity you can prove — checksums and audit logs that show the record has not been altered since capture.
  • Retention you control — schedules by account or record class, matching your retention authority.

How do capture methods compare?

MethodWhat it getsWhat it misses
Manual screenshotsA picture of one momentMetadata, timestamps, edits, deletions, comments arriving later; cannot prove authenticity; depends on someone remembering
Native platform downloadsYour own posts, periodicallyPublic comments and reactions, edit history, deletions between exports; formats change at the platform's discretion
Periodic snapshots/crawlsPage state at intervalsAnything posted, edited or deleted between snapshots — precisely the contested material
API-based continuous captureItems as they happen, with metadata, versions and deletionsContent types a platform's API does not expose — ask any vendor exactly which those are

The gaps cluster in the same place: content that changed after publication. That is usually the content a records request or dispute is about.

What should you ask any vendor?

Capture

  • How soon after something is posted, edited or deleted is it captured?
  • Are comments, replies and reactions from the public captured — and kept attached to their post?
  • Which platforms are supported, and through what mechanism (official API, browser capture, crawling)?
  • Exactly which content types can the platform APIs not provide?

The record

  • How are edits stored — as versions with the change visible, or overwritten?
  • What happens when content is deleted at the source?
  • What metadata is kept per item, and how is integrity proven (checksums, audit logs)?
  • Can retention schedules differ by account or record class?

Producing records

  • Can one search run across every connected account at once, and can searches be saved?
  • What export formats are produced (for example PDF, CSV, HTML, JSON), and does the export carry the metadata?
  • How long does a realistic export take — minutes or a support ticket?

Commercials and risk

  • Does pricing change with accounts, users, storage or a busy month? Where exactly is the meter?
  • What security certifications and controls exist (for example ISO/IEC 27001, encryption, MFA, role-based access, penetration testing), and can you see the evidence?
  • If you ever leave, what do you get out, in what format, and what does it cost?
  • Can the system run in parallel with your current approach during evaluation, and can history be backfilled so the archive doesn't start at zero?

How should you run the evaluation?

  1. Start ~90 days before your decision date — renewal, budget cycle or program start.
  2. Connect real accounts (or a live test account) and let capture run in parallel with whatever you do today. Nothing is cancelled during evaluation.
  3. Backfill history and confirm how far back each platform allows.
  4. Run a mock records request end to end: pick a real past incident, search for it, review the thread including any edits or deletions, export, and check the export against the requirements list above.
  5. Have IT review the security evidence — certificates, not assurances.
  6. Records officer signs off before any contract changes hands.

If you are replacing an incumbent, the ArchiveSocial and Pagefreezer comparison pages cover migration specifics — including why you keep your old export and how parallel capture keeps the record continuous.

How does Brolly answer these questions?

Brolly is a social media archiving platform built entirely around this standard: automatic near-real-time capture of posts, comments, edits and deletions from Facebook, Instagram, Threads, X, YouTube, LinkedIn and TikTok via official APIs; versions and deletions preserved with metadata, checksums and audit logs; retention by account or record class; cross-account search with request-ready PDF, CSV, HTML and JSON exports in minutes. It is ISO/IEC 27001:2022 certified and NIST SP 800-53 aligned, priced by records captured with unlimited accounts, users and storage, and every plan starts with a 30-day free trial. The full factual rundown is on the product facts page; US agencies can start from their state's law guide.

Common questions

Buyer questions.

Do we need archiving if the platforms keep our posts anyway?
Platform history is not a record you control: edits overwrite, deletions vanish, accounts get locked or suspended, and platforms change what their APIs and exports return. An archive you hold independently is the difference between owning your record and hoping a third party kept it.
Are screenshots an acceptable archive?
Screenshots capture pixels, not records. They miss metadata, timestamps, edit history and deletions, they cannot prove they were not altered, and someone has to remember to take them. They may supplement an archive; they cannot be one.
Should we archive comments from the public?
Ask your records authority — in many jurisdictions, comments received on an official account can be part of the record, which is why complete capture includes comments, replies and reactions, not just your own posts.
How long should an evaluation take?
Around 90 days works well: enough time to run a candidate in parallel with your current approach, backfill history, run a mock records request end to end, and get records-officer sign-off before a renewal or purchase decision.
What does Brolly cost?
Brolly prices by records captured, in tiers, with unlimited accounts, users and storage on every plan — and a 30-day free trial with no credit card. See the pricing page for current tiers.