1. Home
  2. Enterprise

Enterprise

Enterprise document generation: volume, control, and paperwork your legal team can sign

Batch runs instead of loops, your own storage bucket, signed webhooks with retries, and processing in the EU. The same API as the free plan — with the parts a procurement review asks about.

  • EU processing
  • Signed DPA
  • Your own S3 bucket

What makes a document API enterprise-ready?

Four things: volume that does not fall over, control over keys and environments, delivery you can audit, and paperwork your legal and security teams can sign. Rendering quality is table stakes. The rest is what decides whether an API survives a procurement review — and it is where most document APIs stop.

Key facts

Included volumeFrom 1,000,000 renders a month, PDFs and images combined; custom volume by agreement
Batch renderingJSON or CSV in one run, one file per record or a single merged PDF
StorageYour own S3-compatible bucket, or signed expiring URLs from ours
Processing regionEuropean Union
WebhooksStandard Webhooks, HMAC-SHA256 signed, 8 retries over about 28 hours
IdempotencyKeys honoured for 24 hours
EnvironmentsSeparate test and live keys; test renders are watermarked and cost nothing
TemplatesFully versioned, with rollback to any published version
SupportPriority email support
ContractsDPA with Standard Contractual Clauses, published sub-processors, SLA
PriceFrom €1,500 / month, custom volume and terms — see pricing

Volume: one job instead of five thousand calls

The naive way to produce 5,000 invoices is a loop with 5,000 HTTP calls, and it is the reason most integrations fall over at month-end. Batches take the whole set at once — as JSON or as an uploaded CSV — and return one file per record, or a single merged PDF when the output is a statement rather than a set. Batches are available on every paid plan, not just this one.

Renders are queued and processed asynchronously. Median render time is 216 ms and p95 is 516 ms1, so the limiting factor at volume is your own pipeline, not the engine.

Control

Test and live keys

Test keys render for free, return a watermarked file and keep it for one day. Development and CI never touch your quota or your customers' documents — and a key leaked from a test branch cannot produce a real invoice.

Idempotency

Send an idempotency key and a repeated request returns the original result instead of a second document. Keys are honoured for 24 hours, which covers the retry window of every reasonable job queue.

Template versions

Every published version of a template is kept. Pin a version for documents that must not change — a signed contract layout, an audited report — and roll back a design change without a deployment.

Team access

Separate accounts for the people who need them, with administrative actions recorded. Keys are stored as hashes and can be rotated; a key cannot be displayed again after it is created.

Delivery you can audit

MechanismWhat it gives you
Signed URLsExpiring links to the finished file, default one hour. Anyone with the link can open it until it expires, so treat links as secrets.
Binary response"delivery": "binary" returns the file in the response, when you would rather not touch a URL at all.
Your own bucketOutput written to your S3-compatible storage. The file never enters our retention window.
WebhooksStandard Webhooks with an HMAC-SHA256 signature, eight retries spread over roughly 28 hours, and a delivery log.

Writing to your own bucket is the answer to the question every security review eventually asks: where does the document live after it is made? With this setting the answer is “in your account, from the moment it exists”.

Data protection and procurement

Payloads and generated files are stored and rendered in the European Union. Everything else is written down rather than promised in a call:

  • A Data Processing Agreement on every paid plan, with Standard Contractual Clauses, the technical and organisational measures as a binding annex, and a 30-day notice period for sub-processor changes.
  • The sub-processor list is public, so your vendor register does not depend on asking us.
  • The security page describes encryption, tenant separation, sandboxed rendering and key handling.
  • Availability commitments are in the SLA.
  • Written answers to your security questionnaire, once a year and free of charge.

What we do not have

We hold no external certification: no SOC 2, no ISO 27001, no published penetration test report. If your policy requires a certificate before signature, we are the wrong vendor today, and we would rather you learned that here than in week six of an evaluation. What we can put in front of your auditors is the contractual annex, the questionnaire and a signed DPA.

When you do not need Enterprise

Most teams do not. Batch rendering, custom CSS, async processing, webhooks and the DPA are on every paid plan — the Enterprise plan adds volume, your own storage bucket and priority support. If you render fewer than a million documents a month, keep your files with us and have no bucket policy to satisfy, the Growth, Pro or Scale plan does the same work for a fraction of the price.

And if policy forbids sending document content to a third party at all, no plan solves that. Self-hosting a browser fleet is then the honest answer, and the operational cost is the price you pay for it.

1 Median render time 216 ms, p95 516 ms, measured over 1,664 successful renders: queue plus processing in the worker, excluding network time and API overhead.

FAQ

Frequently asked questions

What makes a document API enterprise-ready?

Four things: volume that does not fall over, control over keys and environments, delivery you can audit, and paperwork your legal and security teams can sign. Rendering quality is table stakes; the rest is what decides whether the API survives a procurement review.

Can I store generated files in my own bucket?

Yes. Enterprise plans can write output to your own S3-compatible bucket, so the files never sit in our retention window and stay inside your own compliance perimeter.

How do batches work?

Batches are available on every paid plan. You send many records as JSON or CSV in one run and get one file per record, or a single merged PDF. It is the difference between 5,000 API calls and one job.

How reliable are the webhooks?

Webhooks follow the Standard Webhooks specification and are signed with HMAC-SHA256. A failed delivery is retried eight times over roughly 28 hours, and idempotency keys are honoured for 24 hours so a repeated call does not produce a second document.

Where is our data processed?

Payloads and generated files are processed and stored in the European Union. A Data Processing Agreement applies to every paid plan, the sub-processors are published, and changes are announced in advance.

Do you have SOC 2 or ISO 27001?

No. We do not hold an external certification today and we do not claim one. What we can give your procurement team is the technical and organisational measures as a contractual annex to the DPA, written answers to your security questionnaire and a signed DPA including the Standard Contractual Clauses.

What does Enterprise cost?

Enterprise starts at €1,500 a month for 1,000,000 renders — PDFs and images count the same — with automatic top-ups from €1.20 per 1,000. Volume, limits and terms above that are agreed individually — talk to sales.

Bring us your volume.

Tell us what you render and we will tell you plainly whether we fit.

Talk to sales