For Florida law firms
Upload malware scanner (quarantine pipeline)
both lanes · Platform service
Current availability
Owner-gatedWaiting on the platform owner: SCANNER_* (absent); structural checks always run.
- Where it lives
- document-quarantine
- What unlocks it
- —
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- Owner-gatedThe upload quarantine on every ingress — signature, deep structure (PDF active content, OOXML integrity, image bounds), and the external scanner when armed — including the workspace's transient attachments.
Limits
- Structural validation always runs; the external malware scan runs only once the owner arms a private scanning destination; verdicts say which.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| unsupported | 415 | Only .pdf, .docx, .txt and .md attach. |
| invalid-file | 422 | The bytes fail the shared upload policy: name/content mismatch, structure, empty, oversized, or binary under a text name. |
| unsafe-file | 422 | The armed scanner reported the file; it is not read. |
| scanner-unavailable | 503 | The armed scanner could not be reached; retry later, nothing kept. |
| scan-required | 503 | SCAN_REQUIRED is set and no scanner is configured — fail closed, the file is not read. |
| unreadable | 422 | No text layer, an encrypted or damaged file, or the parser exceeded its time budget. |
Evidence
- src/lib/security/document-quarantine.test.ts
- docs/security/UPLOAD-QUARANTINE.md
Last reviewed 2026-09-24