File security & virus scanning
Every file uploaded anywhere in the workspace (Drives, task and record attachments, employee and training documents, and guest uploads) is automatically scanned for malware before anyone can download it. This is on by default and needs no setup.
- Clean files behave normally and are downloadable immediately.
- Infected files are deleted automatically and can never be downloaded.
- Pending (scan in progress) or Error (scan could not finish) files stay un-downloadable until a clean result, the system fails safe, never open.
Admins can review anything the scanner flags under Administration ▸ File security. Owners and admins see their own workspace; platform staff can see every tenant.
- 1
Review flagged files
Open Administration ▸ File security. Filter by Infected, Error, or Pending. Each row shows the file, where it lives, the scanner verdict, and when it was seen.
- 2
Re-scan
For a file held on Error or Pending, click Re-scan to check it again. A clean result releases it for download automatically. There is deliberately no manual "mark clean". That would bypass the scanner.
- 3
Delete or dismiss
Delete removes the file and its record. For an infected file that was already auto-removed, Dismiss just clears the leftover record.
Platform staff manage the antivirus engine on the API keys page (File scanning card): turn scanning on or off, rotate the provider key, and set per-organization and global daily scan limits that cap external scanning cost. If a daily limit is reached, new uploads are held (never marked clean) and admins are alerted.