Skip to content

What the SDK will not do

The API’s shape enforces these limits. No option, parameter or configuration turns them off.

It never hands out a key

No function in the SDK API returns a key or a wrapped key. Your application cannot store anything returned and use it to decrypt on its own later. Decryption happens inside the SDK, on the device holding the device key, and nowhere else. See The trust model for why.

It never returns storable ciphertext to reopen

objects.open returns plaintext that lasts until you call close(). It is not a copy your application can write to disk and open again without the SDK. No key remains after close(). You cannot store anything returned and open it again later. See Plaintext lifetime.

It never shows a policy or a rule

Every call the tenant’s policies decide returns a decision: allow, deny or challenge. A deny also carries a reason code and fixed text. The SDK never returns the rule behind the decision or the active policy version. Your application cannot rebuild the tenant’s rules from it. See Access decisions.

It never sends the customer’s subject identifier

SaveOptions.subject and a dataset’s subjectField both work with the customer’s own identifier for a subject, such as a medical record number. Before anything leaves the device, the SDK tokenizes that identifier into a subject ref under the tenant’s tokenization key. The SDK never sends the identifier itself. evidence.subjectRef runs the same tokenization for a candidate identifier. Your application can compare refs. No identifier crosses the network.

It never searches in the Seald Healthcare Cloud

folders.search opens every folder index it needs, one decision each, and searches the decrypted indexes on the device. The access event records the indexes it opened, never the query. The SDK API has no search in the Seald Healthcare Cloud. A query never leaves the device that ran it.

It never lets a person revoke the device they ask from

The device signs people.revoke after a fresh multi-factor sign-in. The call refuses to revoke the device that makes it. Always revoke a lost or stolen device from another of that person’s devices.

Next