Account-scoped tokens and roles
API tokens belong to accounts, tokens are stored hashed, and workspace roles separate owner, admin, developer, billing, and support needs.
Security and controls
exdata is built for cautious adoption: account-scoped access, hashed API tokens, signed webhooks, retention controls, audit context, support tooling, and clear status reporting.
Security posture
API tokens belong to accounts, tokens are stored hashed, and workspace roles separate owner, admin, developer, billing, and support needs.
Webhook payloads include event, delivery, timestamp, and signature headers so receivers can verify the source before automation runs.
Source files, previews, extracted metadata, and operational logs can follow different retention defaults for cleaner lifecycle control.
Operational confidence
Document automation becomes fragile when failures disappear into a queue. exdata surfaces request IDs, document state, extraction run versions, blocked reasons, webhook delivery context, and account usage.
Document data path
The current defaults keep source files for 30 days, previews for 30 days, and extracted metadata for 365 days. Account owners and admins can choose supported retention windows.
When AI extraction is used, required document content is sent to OpenAI. exdata disables Responses API storage, requests deletion of temporary Files API uploads after each attempt, and sweeps leftovers older than one hour. Provider-side safety retention may still apply under OpenAI’s API data controls.
Customers can delete documents through available API and workspace controls. Scheduled retention handles stored artifacts, while the public subprocessor and residency pages explain third-party and regional boundaries.