Encrypted temporary source files
Submitted PDFs are encrypted with AES-256-GCM in private job storage. The source file is removed when processing completes, fails, or is cancelled.
This page describes the controls implemented in the current Manifest AI service. Requirements such as a DPA, dedicated region, custom retention, penetration-test evidence, or contractual SLA should be agreed before production onboarding.
Submitted PDFs are encrypted with AES-256-GCM in private job storage. The source file is removed when processing completes, fails, or is cancelled.
Authenticated workspace, result, layout, export-template, SKU-mapping, and billing queries are scoped to the owning account. Administrative actions are separately allowlisted and re-authorized on the server.
Developer keys are available only to eligible plans. Secrets are shown once, stored as keyed hashes, limited by scope, rate limited, revocable, and recorded in the API audit trail.
Webhook deliveries use timestamped HMAC signatures, bounded retries, delivery history, and replay protection guidance so integrations can reject forged or stale requests.
Extracted results and evidence are retained for 90 days by default. Customers can delete a stored result earlier; expiry scrubs extracted content and identifying document metadata while minimal billing and security records may remain.
Uploads are type, size, and page limited. Formula-like spreadsheet values are neutralized, internal engine details are removed from customer responses, and exports are generated only for the authenticated owner.
Do not send customer documents, credentials, or exploit details through a public channel. Email our team first so we can provide a secure coordination path.
Contact security