A pipeline de renderização é uma fronteira de segurança.
Inputs não confiáveis não são executados como pedidos web normais no processo principal.
Limites de segurança em cada etapa.
Strong PDF infrastructure validates where data can go, how browsers run and who can access the resulting output.
Network controls
Private network targets, local addresses and unsafe redirects should be rejected before render execution.
Isolated browser context
Each render runs with explicit timeout and resource controls rather than inheriting shared customer state.
Credential discipline
API keys are identifiable, revocable and subject to plan limits, quotas and rate controls.
Temporary outputs
Generated files are treated as temporary artifacts and should use non-predictable delivery links.
Operational evidence
Important releases and production events remain observable instead of disappearing into generic success messages.
Controlled rollout
Canary releases and rollback paths reduce the blast radius of a bad template version.
Customer documents are infrastructure data, not training material.
The product direction is to collect only operational data needed to run the service, keep retention controlled and avoid using customer documents for AI training.