Skip to content

Security and controls

Security controls for production document workflows.

exdata is built for cautious adoption: account-scoped access, hashed API tokens, signed webhooks, retention controls, audit context, support references, and clear status reporting.

Security posture

Built around account boundaries and integration safety.

Access

Account-scoped tokens and roles

API tokens belong to accounts, tokens are stored hashed, and workspace roles separate owner, admin, developer, billing, and support needs.

Delivery

Signed webhook events

Webhook payloads include event, delivery, timestamp, and signature headers so receivers can verify the source before automation runs.

Retention

Separate retention windows

Source files, previews, extracted metadata, and account activity records can follow different retention defaults for clearer lifecycle control.

Processing confidence

Production issues need observable state.

Document automation becomes fragile when failures are hard to investigate. exdata surfaces request IDs, document state, processing metadata, blocked reasons, webhook delivery context, and account usage.

Request and run context
API failures include request IDs, and processing runs carry the metadata needed to understand the returned result.
Blocked document handling
Documents that cannot be processed carry a blocked reason so your team can choose the next action.
Service checks
Service checks cover availability, document processing, webhook delivery, billing, and extraction behavior.
Public security resources
Privacy, terms, DPA, TOMs, subprocessors, data residency, security, status, and API documentation are available from the public site.

Document data path

See what happens from upload to deletion.

Account storage

Separate retention by data type

The current defaults keep source files for 30 days, previews for 30 days, and extracted metadata for 365 days. Account owners and admins can choose supported retention windows.

AI extraction

AI data handling is explicit

When AI extraction is used, required document content is sent to OpenAI. exdata applies the documented data-handling controls for that processing and links to OpenAI’s API data controls for provider-side retention and privacy details.

Deletion and providers

Controls and boundaries stay public

Customers can delete documents through available API and workspace controls. Scheduled retention handles stored artifacts, while the public subprocessor and residency pages explain third-party and regional boundaries.

Legal and service

Review the public security, privacy, and API documentation before rollout.