| Object |
One uploaded file as the platform tracks it: an identity, an owning destination scope, a content identity, a policy version, a lifecycle state and a pointer to its current verdict. |
The unit of state, access control and audit. |
A "file", which conflates the bytes with the record of what the platform believes about them. |
| Content identity |
A cryptographic hash of the bytes, independent of filename, path and owning tenant. |
The key for deduplication and for verdict reuse, and the join between an object and the judgements made about identical bytes. |
A "file hash", which usually implies a checksum used for integrity rather than an identity used for decisions. |
| Lifecycle state |
The object's position in an explicit state machine: initiated, transferring, finalised, scanning, available, quarantined, deleted. |
The sole authority on whether any reader may obtain the object. |
A "status", which is usually a display string with no authority attached. |
| Untrusted plane |
Storage holding finalised-but-unscanned, quarantined and evidence objects, with no identity entitled to issue a read credential for it. |
Where an object is allowed to be dangerous. |
A "staging bucket", which implies a workflow step rather than a trust boundary. |
| Serving plane |
Storage holding only objects whose current verdict is clean and whose state is available. |
The only storage any reader or edge cache can reach. |
"Production storage", which says where it runs rather than what is true of its contents. |
| Verdict |
A versioned claim about a content identity, naming the engine build, signature-set version, outcome, any detection identifier, any bound hit, the decision time and a revocation field. |
The evidence that justifies an object's state, and the thing a re-scan replaces rather than overwrites. |
"Scan result", which suggests a transient output rather than a durable, citable claim. |
| Indeterminate |
A terminal verdict meaning the scan could not complete within its declared bounds, naming the bound that was hit. |
The third outcome that stops a timeout being silently read as a pass. |
"Unknown" or "error", both of which invite a caller to treat the object as fine. |
| Promotion |
The state-machine-directed move of an object from the untrusted plane to the serving plane after a clean verdict. |
The priced step at which an object becomes reachable. |
"Publishing", which implies a product action rather than a storage and access-control transition. |
| Revocation |
Withdrawing a clean verdict and returning the object to quarantine when later knowledge contradicts the earlier judgement. |
What makes clean a claim rather than a property, and what bounds the liability window for new intelligence. |
"Re-quarantine", which describes the movement and omits that a recorded judgement has been withdrawn. |
| Lane |
A priority class — interactive, background or bulk — with its own admission limits, published time-to-verdict target and position in the shedding order. |
How a weekend migration is prevented from starving a Monday attachment. |
A "queue", which is the mechanism rather than the promise. |
| Oldest-unscanned age |
The age of the oldest object awaiting a verdict in a lane. |
The scaling trigger, the alarm, and the input to the shedding bands — chosen over queue depth because the promise being kept is time-to-verdict. |
"Backlog" or "queue depth", which cannot distinguish a deep queue that is draining from a shallow one that is stuck. |
| Dwell time |
The expected maximum time an object should remain in a given non-terminal state for its size class. |
What the reconciler compares against, making silent loss detectable. |
A "timeout", which implies an automatic failure rather than an investigation trigger. |
| Reuse isolation level |
The declared boundary within which a verdict may be reused for identical content: destination scope, tenant, or platform-wide. |
The single policy field that decides whether the dedup index can act as a cross-tenant existence oracle. |
"Dedup scope", which sounds like a storage optimisation rather than a confidentiality boundary. |
| Residency boundary |
An independently deployed stack for a declared geography, with no replication relationship to any other boundary. |
How the residency promise is kept by absence of mechanism rather than by correctness of configuration. |
A "region", which is a cloud construct that says nothing about jurisdiction. |