Security and data handling

Clear controls for every document, account, and integration.

This page describes the controls implemented in the current Manifest AI service. Requirements such as a DPA, dedicated region, custom retention, penetration-test evidence, or contractual SLA should be agreed before production onboarding.

Encrypted temporary source files

Submitted PDFs are encrypted with AES-256-GCM in private job storage. The source file is removed when processing completes, fails, or is cancelled.

Tenant-scoped application access

Authenticated workspace, result, layout, export-template, SKU-mapping, and billing queries are scoped to the owning account. Administrative actions are separately allowlisted and re-authorized on the server.

Hashed API credentials

Developer keys are available only to eligible plans. Secrets are shown once, stored as keyed hashes, limited by scope, rate limited, revocable, and recorded in the API audit trail.

Signed delivery events

Webhook deliveries use timestamped HMAC signatures, bounded retries, delivery history, and replay protection guidance so integrations can reject forged or stale requests.

Defined retention and deletion

Extracted results and evidence are retained for 90 days by default. Customers can delete a stored result earlier; expiry scrubs extracted content and identifying document metadata while minimal billing and security records may remain.

Safer document and spreadsheet handling

Uploads are type, size, and page limited. Formula-like spreadsheet values are neutralized, internal engine details are removed from customer responses, and exports are generated only for the authenticated owner.

Responsible disclosure and security questions

Do not send customer documents, credentials, or exploit details through a public channel. Email our team first so we can provide a secure coordination path.

Contact security