File Upload & Scanning Pipeline · View 01 of 21 · Context and scope
In scope
- Upload initiation, credentialing and admission — every rejection that can happen before a byte moves
- Resumable chunked transfer up to 50 GB, content identity, and deduplicated verdict reuse
- Scan orchestration across multiple engines, the quarantine state machine, and the authorised download path
Out of scope
- Preview and thumbnail generation — a subscriber to the available event, not a stage of the pipeline
- DLP classification and content indexing — they consume verdicts; they do not gate them
- The product surfaces that render attachments, and long-term archival policy
Why the public-intake caller sits with the people
- An external submitter to a form is not a tenant's backend; it is an unauthenticated stranger with a credential good for one blob path
- That path carries the strictest ceiling and the narrowest type allow-list in the platform, and no scope declared backend-only
- Drawing it beside the members rather than beside the product backends is the honest placement, because the trust level is the same
Stated assumptions
- 40 million monthly active members across 12 product tenants
- 60 million objects a day, mean 2.4 MB, p99 240 MB, maximum 50 GB
- Engines are licensed vendor images, pulled, not built here