Trust

Retention planning for logs and metrics.

Nova helps teams plan retention around practical production operations: searchable recent logs, longer-running metrics, tenant-scoped access, and clear limits. Legal and audit requirements should be reviewed with counsel before relying on any monitoring platform.

Metrics target
Nova positioning references long-running metrics history for trend review.
Logs target
90-day log retention can be discussed for Thai operational and audit needs.
Signals
Linux host metrics, journal logs, selected file logs, and optional Docker logs.
Legal caveat
Nova does not claim automatic legal compliance.

What retention means in Nova

Retention is about how long operational telemetry remains available for dashboards, troubleshooting, and audit review. Nova V1 centers on Linux host metrics and logs rather than full application tracing or security event management.

During private beta, retention should be confirmed directly for each customer because telemetry volume, log noise, host count, and deployment model affect both cost and operational design.

Thailand retention context

Thailand's Computer Crime Act Section 26 is commonly translated as requiring service providers to retain computer traffic data for at least 90 days, with possible longer retention by competent-official order. A public UNODC legal database entry for Section 26 is linked in the related resources.

Nova should be treated as an observability and operational retention tool, not legal advice. The exact logs needed, whether a company is a covered service provider, and how retention duties apply should be reviewed by a qualified Thai lawyer.

Customer responsibilities

Retention only helps if the right data is collected. Customers should decide which application logs are operationally useful, which logs should be dropped, and which logs may contain personal data or secrets.

Nova's current file monitor validation blocks obvious sensitive credential paths, but it cannot know whether an application log includes private business data, access tokens, or personal information.

  • Define which systems are in scope for retention.
  • Avoid logging credentials, tokens, payment data, or unnecessary personal data.
  • Review retention requirements before enabling high-volume logs.
  • Use shorter retention where long retention is not useful or required.