What the SDK will not do
The API’s shape enforces these limits. No option, parameter or configuration turns them off.
It never hands out a key
No function in the SDK API returns a key or a wrapped key. Your application cannot store anything returned and use it to decrypt on its own later. Decryption happens inside the SDK, on the device holding the device key, and nowhere else. See The trust model for why.
It never returns storable ciphertext to reopen
objects.open returns plaintext that lasts until you call close(). It is not a copy your
application can write to disk and open again without the SDK. No key remains after close(). You
cannot store anything returned and open it again later. See
Plaintext lifetime.
It never shows a policy or a rule
Every call the tenant’s policies decide returns a decision: allow, deny or challenge. A
deny also carries a reason code and fixed text. The SDK never returns the rule behind the
decision or the active policy version. Your application cannot rebuild the tenant’s rules from it.
See Access decisions.
It never sends the customer’s subject identifier
SaveOptions.subject and a dataset’s subjectField both work with the customer’s own identifier
for a subject, such as a medical record number. Before anything leaves the device, the SDK
tokenizes that identifier into a subject ref under the tenant’s tokenization key. The SDK never
sends the identifier itself. evidence.subjectRef runs the same tokenization for a candidate
identifier. Your application can compare refs. No identifier crosses the network.
It never searches in the Seald Healthcare Cloud
folders.search opens every folder index it needs, one decision each, and searches the decrypted
indexes on the device. The access event records the indexes it opened, never the query. The SDK
API has no search in the Seald Healthcare Cloud. A query never leaves the device that ran it.
It never lets a person revoke the device they ask from
The device signs people.revoke after a fresh multi-factor sign-in. The call refuses to revoke the
device that makes it. Always revoke a lost or stolen device from another of that person’s devices.
Next
- The trust model for where decryption happens.
- Access decisions for what an outcome does and does not carry.
- Tenants, key domains and datasets for
subjectFieldand segment fields.