Skip to content

Production Readiness

What the DeepFrame API documents today, a launch checklist, and enterprise questions to confirm separately.

Use this page to decide whether an integration is ready for a controlled production evaluation. This portal documents the DeepFrame API's technical behavior, but it does not publish every commercial or enterprise commitment.

Alpha Is Not A Production Commitment

/api/v1alpha1 has no compatibility promise. This portal does not publish an SLA, support response time, regional hosting commitment, or commercial entitlement. Confirm those requirements separately before relying on the API in production.

What The Current Contract Covers

AreaDocumented behavior
AccessWorkspace opt-in, Public API Alpha keys, and operation-level permissions.
Workspace isolationThe API derives workspace identity from the key. Cross-workspace resources return the same 404 shape as missing resources.
Safe writesSupported state-changing POST operations accept Idempotency-Key; matching retries return the original response, except a completed webhook creation retry returns 409 conflict and cannot replay its signing secret.
Capacity signalsResponses expose rate-limit headers. A 429 response includes Retry-After.
Long-running workVideos, queries, and runs expose explicit states that can be polled. Terminal events can also be delivered by webhook.
Failure handlingRFC 9457 problem bodies include a stable type and a request_id; asynchronous failures use a structured error.
Evidence and uncertaintyFindings and answers preserve result state, limitations, and reviewable evidence instead of turning uncertainty into a clean pass.
Change visibilityThe alpha stability policy, deprecation headers, and changelog describe contract changes.

Follow Authentication, Conventions, Errors, Webhooks, and Policies for the exact behavior.

Launch Checklist

  • Keep API keys in a server-side secret manager. Never send them to browser code.
  • Use a dedicated key with only the permissions the integration needs.
  • Confirm that the Public API Alpha opt-in is enabled for the intended workspace.
  • For a supported state-changing POST request, preserve the same idempotency key and request body when retrying it.
  • Bound retries. Honor Retry-After for 429 and use backoff with jitter for retryable 503 responses.
  • Treat completed, failed, and canceled as distinct terminal outcomes. For video search, require status=completed before running analysis.
  • Verify webhook signatures against the raw body and reject stale or replayed deliveries.
  • Log request_id with your own correlation identifier, without logging secrets or sensitive request bodies.
  • Preserve found, not_found, uncertain, and not_checked, plus limitations and evidence, in downstream decisions.
  • Test one success, one validation failure, one permission failure, one rate-limit response, and one asynchronous failure before launch.

Confirm These Enterprise Requirements

The current portal does not state answers for the following items. Record an explicit answer for each one that matters to your organization:

  • Commercial availability, quotas, and expected workload limits.
  • Availability objectives, support hours, response targets, and escalation route.
  • Processing and storage regions, data residency, and cross-border transfer requirements.
  • Retention periods, offboarding deletion, legal hold, and backup handling.
  • Key-owner governance, rotation frequency, employee offboarding, and audit requirements.
  • Security, privacy, procurement, and vendor-risk evidence required by your organization.
  • Change-notice expectations while the API remains alpha.

Do not infer an enterprise commitment from an HTTP response or from behavior observed during an evaluation.

Get The Missing Answers

Use the contact agreed for your DeepFrame evaluation to confirm the unresolved items above. If you do not have an existing contact, visit deepframe.cloud for the current contact options. Include the workspace, intended workload, required region, and launch date; do not include API keys or customer data.

When those answers are recorded, run the Quickstart in a non-production workspace and use the API reference to verify every operation your integration calls.

On this page