Browse documentation
Production

Security and Data Handling

Understand Manifest AI tenant isolation, temporary document storage, retention, webhook controls, and integration responsibilities.

Manifest AI scopes resources to a workspace, encrypts source PDFs in private temporary storage during processing, deletes them at terminal completion, and retains structured results for the configured period unless deleted earlier.

Platform controls

Security is applied across identity, transport, storage, processing, and export.

  • Workspace-scoped authorization on every protected resource.
  • Digest-only API key storage and scoped credentials.
  • TLS for public traffic and private service networking.
  • AES-256-GCM temporary source-file encryption.
  • File type, size, page, and formula-injection validation.
  • Signed webhook events and restricted webhook destinations.
  • Security and mutation audit events.

Retention model

Source files and results have different lifecycles.

Source PDF
Temporary processing input, deleted when the job completes, fails, or is cancelled.
Structured result and evidence
Retained for 90 days by default, unless deleted earlier or contractually configured otherwise.
Operational records
Minimal billing, usage, fraud-prevention, and security records may remain where required.

Integration responsibilities

Customers remain responsible for secure downstream handling and business review.

  • Upload only documents you are authorized to process.
  • Keep API keys and signing secrets server-side.
  • Review critical values before customs, finance, ERP, or operational use.
  • Delete data when it is no longer required.
  • Agree residency, DPA, SLA, and custom-retention requirements before production use.