Skip to content
SkyKeephelp

Archive intake opens uploads safely, one document per file

A zip or tar.gz archive uploaded to the vault is opened entirely in

memory and every file inside travels the full intake pipeline on its

own: both scan gates, the uploader's own compartment bounds, and its own

audit record. Anything hostile — a file named to climb out of the

archive, a decompression bomb, an archive hiding inside an archive — is

held for review instead, and never stops the honest files beside it.

Every file in an archive becomes its own document

A file named to climb out of the archive is held for review

An archive holding more files than the vault allows is refused

A decompression bomb is refused

An archive hiding inside an archive is held unopened

An upload whose name and contents disagree is refused

A member uploads a zip through the portal and finds every notestack