Built to fail closed.
Last updated August 20, 2026
Identity and separation
Customer scan pages require sign-in. Job reads are restricted to the submitting account, while owner review requires a separate administrator allowlist. The service does not rely on customer-supplied role headers for authorization.
Private document handling
Accepted file types are limited, size-bounded, signature-checked, hashed with SHA-256, and stored under non-public quarantine keys. Files are treated as untrusted input. Public media routes are separate from scan storage.
Engine boundary
Diagnostic dispatch uses a server-side HTTPS endpoint, server-held credential, idempotency key, bounded response, and timeout. If a verified engine or receipt is unavailable, the job remains on engine hold and no scan is claimed.
Callback integrity
Engine updates require a timestamped HMAC signature, a short replay window, an expected job receipt, and an idempotent event key. Callback output cannot declare itself approved.
Human governance
AI may generate proposed findings. It cannot release them. Evidence-linked output remains hidden from customer decision-making until an authorized reviewer approves it; approval, rejection, and proof requests are recorded in the proof chain.
Limits
No system is risk-free. Do not upload prohibited sensitive data. Promptly report suspected misuse or security issues through Eimers Business Solutions.