Production
Security, media, and retention
Operate document rendering with explicit token, payload, result, and remote-media boundaries.
Reviewed 2026-08-05 · PDFDesignAPI Engineering
Sensitive data
Send only fields required by the template. Keep API tokens and customer payload values out of application logs and analytics.
Generated PDFs can contain sensitive data and should be stored and served with access controls appropriate to their contents.
Result lifecycle
Synchronous idempotency results and asynchronous job results expire after 24 hours.
Download completed results promptly and apply your own retention policy.
Remote media policy
Customer media must use public HTTP or HTTPS URLs.
The renderer blocks private, loopback, link-local, metadata, reserved, credentialed, unsupported, and unresolvable destinations.
Production readiness
Use template environments, payload validation, timeouts, retries with backoff, idempotency where applicable, and request correlation in your integration.
Contact support for current limits, enterprise deployment requirements, and contractual security review.