File Upload & Scanning Pipeline  ·  View 20 of 21  ·  Assurance

Security Zones

Six zones, and the two crossings that carry the entire security argument.

Editable source SVG draw.io All views
Internet — fully untrusted Member device Public form submitter The uploaded bytes assumed hostile Perimeter — authenticated, nothing stored Front Door + WAF API gateway authn, quota Admission gate size, type, scope Control plane — trusted, no bytes Session & state services Credential minting platform identity Metadata & transition log Detonation zone — least trusted compute Scan worker ephemeral, no inbound Egress allow-list feed + verdict sink only No state-change credential reads bytes, writes verdicts Untrusted data plane — deny by default Unscanned container no issuable read SAS Quarantine + evidence break-glass only Serving data plane — reachable Available objects short read SAS Edge cache available only control: OAuth 2.0 admitted session write-only SAS read bytes verdict only promote on clean never reachable Security Zones — Where an Object Is Allowed to Be Dangerous External / third party Risk / gap Interface / broker Decision point Application we own Security / platform Data store synchronous event / async failure / alternate Two crossings carry the whole security argument: the client writes into the untrusted plane with a credential that cannot read, and the worker reads the untrusted plane with a credential that cannot change state. Neither side can both see the object and decide its fate. v 1.0 · zones 6

The two crossings

  • The client writes into the untrusted plane with a credential that cannot read, cannot list and cannot delete — so a stolen upload credential yields nothing but the ability to write one blob
  • The worker reads the untrusted plane with a credential that cannot change state — so a worker compromised by the object it is reading cannot declare that object clean
  • Neither side can both see the object and decide its fate. That separation is the assurance claim, and it is structural rather than procedural.

Decisions

  • The scan worker is treated as the least-trusted compute in the platform and architected as if it will be compromised by the object it is reading
  • No inbound reachability, an egress allow-list of two destinations, no durable write access except the verdict sink, and destruction after each object
  • Filenames, metadata and archive member paths are hostile input: a path traversal, a control character or an executable extension in a name influences nothing

Residual risk

  • An engine zero-day that achieves code execution inside the detonation zone still sees one tenant's single object and an egress allow-list — a bounded loss, not an eliminated one
  • Break-glass evidence reads are the one path by which a confirmed-malicious object leaves quarantine, and they are audited rather than prevented