Risk Limits
Case volume, evidence size, approval SLAs, and retention holds.
Limits are per Risk project. Examiner-facing objects are never silently truncated.
Cases
| Limit | Enterprise default |
|---|---|
| Open + investigating cases | 5,000 |
| Notes per case | 2,000 |
| Status transitions per case per day | 50 |
| FC brief revises | 8 |
Evidence
| Limit | Enterprise default |
|---|---|
| Item size | 80 MiB |
| Items per case | 2,000 |
| Bytes per case | 20 GiB |
| Concurrent uploads | 10 |
413 document_too_large on item size. Split packs.
Assessments and reports
| Limit | Enterprise default |
|---|---|
| Concurrent assessments | 20 |
| Report PDF pages | 150 |
| Pending approvals per project | 200 |
| Approval TTL | 24 hours (max 72) |
Retention
| Record | Default |
|---|---|
| Case without hold | 7 years or order-form clock |
| Hold | Clock paused |
| Draft reports | Same as case |
| ZDR | Bodies 404; hashes and audit remain |
Financial-crime tenants often require the long clock. Confirm on the order form. South Africa, UAE, and Hong Kong booking entities can differ. The API enforces the project clock, not the office that staffed onboarding.
Rate limits
Risk routes share the project envelope with a lower default RPM than Dev completion. Headers: X-Eridian-RateLimit-*. See Rate Limits.
Support
contact@geteridian.com with case_id and request_id. Do not attach unredacted case files to email. Offices in Dubai, Hong Kong, and South Africa can join a bridge on Enterprise. They still do not receive the file unless the pin and DPA allow it.
See Risk API and Evidence Export.
Production API credentials are issued with an institution workspace. Contact sales if you need access.