Transfer Security Boundaries

Transfer Security Boundaries A data-flow diagram generated by Archify. 01 / Input 02 / Policy 03 / Credential 04 / Transfer 05 / Verify / publish Local File · 01 / Input Local File Upload Policy · 02 / Policy · no redirects Upload Policy no redirects Live Credential · 03 / Credential · epoch fenced Live Credential epoch fenced Scotty Session · 04 / Transfer Scotty Session Source Row · 05 / Verify / publish Source Row Asset URL · 01 / Input Asset URL Per-hop Policy · 02 / Policy · every redirect Per-hop Policy every redirect Scoped Auth · 03 / Credential Scoped Auth Media Response · 04 / Transfer Media Response Verify & Publish · 05 / Verify / publish · same-dir staging Verify & Publish same-dir staging admit selected backend validated URL credential boundary authorized bytes dedicated client finalize server indexes check auth GET stream chunks bounded Legend primary data policy / PII async batch data store data flow

Separate planes

  • • Uploads and asset downloads use dedicated lifecycle participants outside RpcExecutor
  • • The selected backend supplies the correct credential policy

No credential drift

  • • Each download hop revalidates URL policy before attaching credentials
  • • Android clears ambient cookies and never restores a bearer after leaving bearer hosts

Safe publication

  • • Limits and media signatures are checked before publication
  • • A same-directory staging file is atomically replaced only after a complete transfer