Evidence vault
Evidence items are files (validated by type, size and magic bytes) or links, with checksums, versions, review dates, tags and links to products, requirements, vulnerabilities, incidents and CRA cases. Files are private and served through 2-minute signed URLs after authorisation.
- Legal hold prevents deletion until released by an authorised user (audited both ways).
- Retention policies per category (audit events, evidence, incident data, reports, SBOMs, notifications) are configured by owners; destructive changes warn first.
- Evidence proving a CRA submission cannot be removed.
Last updated . This page describes the current release.