Tenant isolation
Workspace and environment identifiers scope every control-plane operation and storage query.
Piqae protects credentials, gives every enrolled agent its own identity, separates customer workspaces, and keeps sensitive print data out of marketing analytics.
Workspace and environment identifiers scope every control-plane operation and storage query.
Enrolled agents authenticate requests with signed, replay-resistant device credentials.
Downloads, URIs, files, render work, and waits are constrained rather than trusted indefinitely.
API keys, enrollment tokens, device keys, lease capabilities, and documents are excluded from client telemetry.
State changes are append-oriented and the accepted-job usage event is idempotent.
Native spooler acceptance and reported completion are not presented as verified physical delivery.
| Data | Where it belongs | Control |
|---|---|---|
| Print content | Bounded object storage and the enrolled agent | Retention and deletion policy |
| Device credentials | Protected local secret storage | Revocable enrolment identity |
| Job metadata | Workspace-scoped database rows | Role and environment boundaries |
| Marketing analytics | Consent-gated PostHog events | No document, printer, key, or address fields |
Piqae Cloud operates the managed control plane. Self-hosted operators are responsible for their database, object storage, network, identity configuration, retention, upgrades, and backups. The native agent remains inside the printer network in either model.
Source-complete does not mean every platform is generally available. The checked-in support matrix and release gates are authoritative; the downloads page renders those limits instead of making broader claims.