Security & Privacy
- Stored data includes screenshots, diff artifacts, run metadata, and integration delivery logs.
- Never commit tokens to repository. Use GitHub Secrets for
SCANU_TOKENand related values. - Slack bot tokens are encrypted at rest before saving.
- Token-based API access is revocable and supports expiry dates.
- For GDPR workflows, keep only required projects and delete old runs based on your data policy.