Virox

Security

Access decisions happen before object access.

Virox Cloud combines workspace isolation, private object storage, request validation, and auditable administration.

01

Identity

Argon2id password hashes, email verification, server-side sessions, CSRF checks, TOTP, recovery codes, lockouts, and session revocation.

02

Authorization

Every private operation resolves the current user, workspace membership, role, workspace state, and active entitlement on the server.

03

Storage

Buckets remain private. Internal object keys are random, downloads are mediated, and upload completion repeats quota checks.

04

User content

Potentially active files download with safe disposition and MIME protections. Markdown is sanitized and uploaded code is never executed.

05

Operations

Structured logs redact secrets; health responses omit infrastructure addresses; sensitive actions produce immutable audit records.

06

Recovery

Database, configuration, and object data have coordinated backup and restore procedures with verification.

Antivirus state is explicit

When ClamAV is enabled, new files remain pending until scanned and infected files move to quarantine. When it is disabled, Virox reports files as not scanned.