File Upload & Scanning Pipeline · View 16 of 21 · Runtime
Decisions
- Authorisation, lifecycle state and verdict currency are all re-evaluated at request time; nothing is cached from the upload decision
- Bytes are served direct from the store or the edge, never through platform compute, and nothing is cached at the edge before an object is available
- Any content type not on the scope's inline-render allow-list is served with headers that force download rather than in-browser rendering
The exposure bound
- A revocation cannot recall a credential already issued, so the credential's 5-minute life is the real bound on post-revocation exposure
- Demotion from the serving plane and edge invalidation complete within 60 seconds; the two numbers together are the honest statement of blast radius
- This is why the read credential is minutes rather than hours — a requirement derived from revocation, not a tuning preference
Stated assumptions
- Credential issuance p99 ≤ 80 ms, availability ≥ 99.99% monthly
- Revocation removes an object from the serving plane within 60 s
- Re-scan of objects clean within the last 30 days within 24 h of a material signature change