Source code reviews
Source code files are not retained after processing. CIRT retains cryptographic file hashes and the underlying file-level results indefinitely by default. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and file-level results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. A file-level result is primarily a generated summary of the file's purpose and its associated security findings. In rare circumstances it may include a small code snippet. It cannot identify or reconstruct the submitted source file.