---
title: Sensitive egress gates
description: Control which copies of names and file bytes leave Seal (webhooks, convert, AI)
---

# Sensitive egress gates

Enterprise foundation (SEA-70). Seal keeps document bytes in your org’s R2
bucket by default. Extra copies leave when you enable convert/AI workers, send
signing email, or deliver webhooks. This page documents those paths and the
org settings that shut them off.

## Paths that leave Seal

| Path | What leaves | Gate |
| --- | --- | --- |
| **Transactional email** | Recipient email, document title, signing link | Product notifications settings; cannot void signing without email unless you use API-only agent flows |
| **Webhooks** | Event JSON to your HTTPS endpoint | `egress.webhook_payload_mode`: `full` (default) or `minimal` |
| **Convert worker** | Office/CSV bytes → PDF | `egress.allow_convert` (default `true`) |
| **Anydoc / AI** | PDF/Office bytes for parse + field candidates | `ai.enabled` (default `true`) |

Convert and anydoc are **same-account Cloudflare service bindings** on hosted
Seal (and on self-host when you bind them). They are still a second processing
surface — disable them when policy forbids extra file-byte handling.

## Settings API

```http
PATCH /api/v1/settings
Authorization: Bearer seal_…
Content-Type: application/json

{
  "ai": { "enabled": false },
  "egress": {
    "allow_convert": false,
    "webhook_payload_mode": "minimal"
  }
}
```

| Setting | Effect |
| --- | --- |
| `ai.enabled: false` | AI routes return `403` `{ "error": "ai_disabled" }`; anydoc parse is skipped |
| `egress.allow_convert: false` | Convert attempts return `403` `{ "error": "convert_disabled" }` |
| `egress.webhook_payload_mode: "minimal"` | Webhook `data` keeps ids, status, timestamps, counts; drops email/name/title/IP/signature/free text. Envelope includes `payloadMode: "minimal"` |

GET `/api/v1/settings` returns the current values (defaults shown above when
unset).

## Minimal webhook example

Full mode may include recipient email / document title. Minimal mode:

```json
{
  "eventId": "…",
  "eventType": "recipient.signed",
  "timestamp": "2026-09-25T17:00:00.000Z",
  "payloadMode": "minimal",
  "data": {
    "documentId": "…",
    "recipientId": "…",
    "status": "signed",
    "signedAt": "2026-09-25T17:00:00.000Z"
  }
}
```

SIEM push (`audit.entry.created`) respects the same mode — prefer pulling
NDJSON audit export when you need full actor/IP fields under a locked-down
webhook policy.

## Related

- [Privacy & incidents](/getting-started/privacy)
- [Webhooks](/webhooks)
- [HIPAA scoping](/getting-started/hipaa)
