Identity
Argon2id password hashes, email verification, server-side sessions, CSRF checks, TOTP, recovery codes, lockouts, and session revocation.
Security
Virox Cloud combines workspace isolation, private object storage, request validation, and auditable administration.
Argon2id password hashes, email verification, server-side sessions, CSRF checks, TOTP, recovery codes, lockouts, and session revocation.
Every private operation resolves the current user, workspace membership, role, workspace state, and active entitlement on the server.
Buckets remain private. Internal object keys are random, downloads are mediated, and upload completion repeats quota checks.
Potentially active files download with safe disposition and MIME protections. Markdown is sanitized and uploaded code is never executed.
Structured logs redact secrets; health responses omit infrastructure addresses; sensitive actions produce immutable audit records.
Database, configuration, and object data have coordinated backup and restore procedures with verification.
When ClamAV is enabled, new files remain pending until scanned and infected files move to quarantine. When it is disabled, Virox reports files as not scanned.