Security and data lifecycle

Generate documents with a clear, bounded data flow

Understand how render requests, generated results, remote assets, authentication, and template access are handled before moving to production.

How it helps

Security controls documented from current product behavior

This page avoids unsupported certification claims. Contact us for a technical architecture review and current contractual details.

Encrypted transport

Production API requests use HTTPS. Keep API tokens in server-side secret storage.

Private results

Generated job results are private and require authorized access.

Limited retention

Synchronous idempotency results and asynchronous job results expire after 24 hours.

Payload minimization

Application logging and render history are designed not to expose customer render payload values.

Restricted remote media

Renderer networking blocks private, loopback, link-local, metadata, reserved, credentialed, and unresolvable destinations.

Team ownership

Templates and API access are scoped through authenticated team ownership.

Frequently asked questions

How long are generated job results available?
Current synchronous idempotency results and asynchronous job results expire after 24 hours.
Can templates load private network resources?
No. Renderer media policy blocks private and otherwise unsafe network destinations.
Is PDFDesignAPI certified for a specific compliance standard?
No certification is claimed on this page. Contact the team with your exact procurement and compliance requirements.

Start with a real document

Create a template and generate your first PDFs without a credit card.

Request an architecture review