Production

Security, media, and retention

Operate document rendering with explicit token, payload, result, and remote-media boundaries.

Reviewed 2026-08-05 · PDFDesignAPI Engineering

Sensitive data

Send only fields required by the template. Keep API tokens and customer payload values out of application logs and analytics.

Generated PDFs can contain sensitive data and should be stored and served with access controls appropriate to their contents.

Result lifecycle

Synchronous idempotency results and asynchronous job results expire after 24 hours.

Download completed results promptly and apply your own retention policy.

Remote media policy

Customer media must use public HTTP or HTTPS URLs.

The renderer blocks private, loopback, link-local, metadata, reserved, credentialed, unsupported, and unresolvable destinations.

Production readiness

Use template environments, payload validation, timeouts, retries with backoff, idempotency where applicable, and request correlation in your integration.

Contact support for current limits, enterprise deployment requirements, and contractual security review.

Was this page helpful?

Need help with an implementation detail?

Contact technical support →