Skip to main content
This page has two parts. The first lists facts read from the API code. The second repeats the principles Sahl publishes on sahlfinancial.com/security. That page, the terms, the privacy notice and the DPA clauses are the reference for commitments. This page is not a certification statement.

Facts from the code

Keys

Isolation

  • Every write takes the workspace from the authenticated key. Nothing in the KYC code reads across workspaces.
  • An eID request is stored at the provider under a client id made of your workspace id and your reference. Another workspace’s key gets 404 for it.
  • Cases are separate per environment. Sandbox data never appears in production views.

Files and data

Webhooks

  • Payloads carry ids, your reference, the environment and a verdict summary. They never carry a field value, a name, a date of birth or a document’s contents.
  • Deliveries are signed with HMAC-SHA256 and a timestamp. See Webhooks.
  • A webhook URL must be https and public. Loopback, private ranges and cloud metadata addresses are refused when you save it and again before each send. The address is resolved once per delivery and the connection goes to that checked address. Redirects are not followed.

Traffic

  • Requests go to https://app.sahlfinancial.com/api. The API refuses requests that do not come through Sahl’s own front door (403 direct_access_refused).
  • 100 requests a minute per client IP on these routes.
  • Each key call is logged with route, method, status, latency, X-Request-ID, reference, environment and error code. The log is kept 90 days by default. Request and response bodies are not part of that record.
  • Cross-origin browser calls are accepted only from origins on Sahl’s allow-list.

Retention

  • Each workspace has a retention setting (retention_days, 90 by default in the data model). A retention routine removes, for documents older than that, the raw file, page images, OCR text, extracted field values, validation messages and review corrections. It keeps the rows (ids, statuses, timestamps, scores, counts) so billing and history still add up, and the append-only audit log.
  • A tenant admin can erase or export one case for a data-subject request.
  • The record_retention_days value in a KYC policy records your retention commitment (for example 1,825 days for the FINTRAC preset). It does not delete anything by itself.
  • For an eID check the provider deletes the client’s personal details about seven days after the check. Fetch the result and the PDF before that.
Ask Sahl how retention is set and run on your workspace. The routine is part of the code; this documentation does not state a schedule for it.

Principles Sahl publishes

Report a security issue

Write to Sahl and quote the X-Request-ID of any call involved. Do not send keys or client data in the message.