exa-data-handling
Exa Retrieved-content Governance
Overview
Govern queries, public-web retrieval, generated summaries, citations, and downstream copies across their full retention lifecycle. Treat credentials, queries, retrieved content, generated output, spend, and destructive state as separately governed boundaries.
Prerequisites
- The target repository, environment, Exa team, product surface, and accountable owner.
- The workload's data classification, latency and freshness promise, cost ceiling, and retention policy.
- Current first-party documentation plus credentials only for a narrowly approved live check.
Current Contract
Search and Contents can return page text, highlights, summaries, links, images, and subpages; Agent and Answer can generate cited output. Public availability does not remove privacy, copyright, contractual, prompt-injection, or retention obligations. Enterprise Zero Data Retention and request-scoped HIPAA behavior require explicit enablement.
Authentication
For normal REST work, inject EXA_API_KEY from an approved server-side secret manager and send it only as Authorization: Bearer to the configured first-party Exa API host. Team Management service keys, hosted MCP OAuth or enterprise managed authorization, and payment-protocol calls are separate trust models. Never print, commit, place in a URL, or expose a credential to an untrusted client.