File Upload & Scanning Pipeline · View 20 of 21 · Assurance
The two crossings
- The client writes into the untrusted plane with a credential that cannot read, cannot list and cannot delete — so a stolen upload credential yields nothing but the ability to write one blob
- The worker reads the untrusted plane with a credential that cannot change state — so a worker compromised by the object it is reading cannot declare that object clean
- Neither side can both see the object and decide its fate. That separation is the assurance claim, and it is structural rather than procedural.
Decisions
- The scan worker is treated as the least-trusted compute in the platform and architected as if it will be compromised by the object it is reading
- No inbound reachability, an egress allow-list of two destinations, no durable write access except the verdict sink, and destruction after each object
- Filenames, metadata and archive member paths are hostile input: a path traversal, a control character or an executable extension in a name influences nothing
Residual risk
- An engine zero-day that achieves code execution inside the detonation zone still sees one tenant's single object and an egress allow-list — a bounded loss, not an eliminated one
- Break-glass evidence reads are the one path by which a confirmed-malicious object leaves quarantine, and they are audited rather than prevented