Virus scanning

Every upload is scanned, and infected files are quarantined.

Built on ClamAV

Plans: Every plan, including the free app

What you get

  • Every upload scanned after it arrives
  • Infected files moved to quarantine
  • Quarantined files refused when read
  • An alert to the business when a file is caught
  • Nothing to install or set up in the app
  • The same scanning on a bucket your business owns

How it works

When an app authorises an upload, Whisk schedules a scan of that file for a couple of minutes later. The file is scanned with ClamAV, the open-source antivirus engine, on the server that runs the app. The scanner is given access to that one file and nothing else in storage.

An infected file is moved to a quarantine folder and the original is deleted. Reading it afterwards returns the error OBJECT_QUARANTINED, so the app can show a clear message. The business is told which file was caught and what it was flagged as.

Files larger than 100 MB are marked as not scanned rather than scanned. Scanning is part of file storage on every plan, and the app needs no code for it.

Example

An accounting practice runs a client portal where clients upload invoices, receipts and bank statements. An attachment that carries a known virus is moved to quarantine and the practice is notified. Staff who try to open it see a message instead.

For your coding agent

storage: true

Handle OBJECT_QUARANTINED when reading an upload back; whisk errors OBJECT_QUARANTINED prints the full entry. Every code is in the error reference.

All features