Account-scoped tokens and roles
API tokens belong to accounts, tokens are stored hashed, and workspace roles separate owner, admin, developer, billing, and support needs.
Security and controls
exdata is built for cautious adoption: account-scoped access, hashed API tokens, signed webhooks, retention controls, audit context, support references, and clear status reporting.
Security posture
API tokens belong to accounts, tokens are stored hashed, and workspace roles separate owner, admin, developer, billing, and support needs.
Webhook payloads include event, delivery, timestamp, and signature headers so receivers can verify the source before automation runs.
Source files, previews, extracted metadata, and account activity records can follow different retention defaults for clearer lifecycle control.
Processing confidence
Document automation becomes fragile when failures are hard to investigate. exdata surfaces request IDs, document state, processing metadata, blocked reasons, webhook delivery context, and account usage.
Document data path
The current defaults keep source files for 30 days, previews for 30 days, and extracted metadata for 365 days. Account owners and admins can choose supported retention windows.
When AI extraction is used, required document content is sent to OpenAI. exdata applies the documented data-handling controls for that processing and links to OpenAI’s API data controls for provider-side retention and privacy details.
Customers can delete documents through available API and workspace controls. Scheduled retention handles stored artifacts, while the public subprocessor and residency pages explain third-party and regional boundaries.