SÉCURITÉ & FIABILITÉ

La chaîne de rendu est une frontière de sécurité.

Les entrées non fiables ne sont pas exécutées comme une requête web normale dans le processus principal.

01

Network controls

Private network targets, local addresses and unsafe redirects should be rejected before render execution.

02

Isolated browser context

Each render runs with explicit timeout and resource controls rather than inheriting shared customer state.

03

Credential discipline

API keys are identifiable, revocable and subject to plan limits, quotas and rate controls.

04

Temporary outputs

Generated files are treated as temporary artifacts and should use non-predictable delivery links.

05

Operational evidence

Important releases and production events remain observable instead of disappearing into generic success messages.

06

Controlled rollout

Canary releases and rollback paths reduce the blast radius of a bad template version.

DATA PRINCIPLES

Customer documents are infrastructure data, not training material.

The product direction is to collect only operational data needed to run the service, keep retention controlled and avoid using customer documents for AI training.

SECURITY MODEL

La chaîne de rendu est une frontière de sécurité.

ISOLATION01Isolated browser context
CONTROL02Network controls
RECOVERY03Controlled rollout
SÉCURITÉ & FIABILITÉ

Customer documents are infrastructure data, not training material.

The product direction is to collect only operational data needed to run the service, keep retention controlled and avoid using customer documents for AI training.

Contact us about a security review