Facts from the code
Keys
Isolation
- Every write takes the workspace from the authenticated key. Nothing in the KYC code reads across workspaces.
- An eID request is stored at the provider under a client id made of your workspace id and your reference. Another workspace’s key gets 404 for it.
- Cases are separate per environment. Sandbox data never appears in production views.
Files and data
Webhooks
- Payloads carry ids, your reference, the environment and a verdict summary. They never carry a field value, a name, a date of birth or a document’s contents.
- Deliveries are signed with HMAC-SHA256 and a timestamp. See Webhooks.
- A webhook URL must be https and public. Loopback, private ranges and cloud metadata addresses are refused when you save it and again before each send. The address is resolved once per delivery and the connection goes to that checked address. Redirects are not followed.
Traffic
- Requests go to
https://app.sahlfinancial.com/api. The API refuses requests that do not come through Sahl’s own front door (403direct_access_refused). - 100 requests a minute per client IP on these routes.
- Each key call is logged with route, method, status, latency,
X-Request-ID, reference, environment and error code. The log is kept 90 days by default. Request and response bodies are not part of that record. - Cross-origin browser calls are accepted only from origins on Sahl’s allow-list.
Retention
- Each workspace has a retention setting (
retention_days, 90 by default in the data model). A retention routine removes, for documents older than that, the raw file, page images, OCR text, extracted field values, validation messages and review corrections. It keeps the rows (ids, statuses, timestamps, scores, counts) so billing and history still add up, and the append-only audit log. - A tenant admin can erase or export one case for a data-subject request.
- The
record_retention_daysvalue in a KYC policy records your retention commitment (for example 1,825 days for the FINTRAC preset). It does not delete anything by itself. - For an eID check the provider deletes the client’s personal details about seven days after the check. Fetch the result and the PDF before that.
Principles Sahl publishes
Report a security issue
Write to Sahl and quote theX-Request-ID of any call involved. Do not send keys or client data in the message.