Documentation menu

Getting started

API reference

Guides

Trust and support

Security and data handling

How requests are processed, what is recorded, and what is never kept. This page describes the running system; the legal commitments are in the privacy notice and the terms.

Where processing happens

What is never stored

Each request runs in its own browser context, in memory, which is discarded when the response has been sent. There is no cache and no temporary file.

What is counted

For each API key, the number of successful renders in the current month, to apply your plan's allowance. Nothing about their content.

What is logged

For each request: the HTTP method, the path without parameters, the status code and the duration; for an unexpected error, only its type. Not logged: URLs, query strings, API keys, IP addresses, headers or content. The log has a fixed maximum size and overwrites itself.

Isolation of the renderer

For your compliance team

On the Compliance plan we sign a data processing agreement with you and provide a data residency letter describing this setup for your auditors. The service is suited to requirements such as the SAMA rules on outsourcing and the Personal Data Protection Law; whether it meets your obligations is for your compliance function to decide, and we will answer their questions. Write to support@sahifa.dev.

Reporting a security issue

Please write to support@sahifa.dev with the subject "Security". You will get a reply within one business day.