Data Retention
DevSecOps Bot by Sttor supports a tenant model where scan artifacts can be stored in a customer-managed S3-compatible bucket.
Retention Typically Covers
- Scan result JSON artifacts
- SBOM exports
- Compliance report outputs
Recommended Approach
- Enforce retention using bucket lifecycle rules (e.g., 30/90/180 days)
- Keep long-term compliance exports separately if required by policy