Security

Best practices for secure API usage.

Document processing

Smole processes document text and page images to perform OCR, structured extraction and schema generation. Processing effort is selected automatically. Completion time depends on document complexity and service demand.

API Key Security

Your API key authenticates all requests (see API Reference). Keep it secure:

  • Never expose your API key in client-side code
  • Store API keys in environment variables
  • Rotate keys periodically from your dashboard
  • Use separate keys for development and production

Data Handling

  • All data is encrypted in transit using TLS 1.3
  • Stored document files and generated file artifacts are scheduled for automatic deletion once they are 30 days old
  • Deletion runs in the background. Deleted files have a seven-day recovery window in storage
  • This file cleanup does not delete extraction results saved in your account
  • You can request data deletion at any time

Error Codes

CodeDescription
401Invalid or missing API key
403Account disabled or insufficient permissions
429Rate limit exceeded
500Internal server error

GDPR Compliance

Smole is GDPR compliant. You can:

  • Export all your data from the account settings
  • Delete your account and all associated data
  • Request information about data processing