LEGACY by Merison

Trust

File Security & Trust

How LEGACY handles the files your organisation entrusts to it — before they ever reach your knowledge base, search or AI.

Last updated: 11 September 2026

1.Quarantine-first handling

Every file uploaded to LEGACY, or imported from a connected source such as SharePoint or OneDrive, is stored in a private quarantine area first. It is not publicly reachable, no shareable or preview link exists for it, and no part of the platform reads its contents until automated file security validation has completed.

Uploading and readiness are separate steps. You can leave the page after uploading; validation and processing continue in the background, and each file shows its own status.

2.Multi-layer file security validation

Before a document enters the knowledge and AI pipeline, LEGACY runs automated file risk checks that examine the file itself rather than trusting its name or the type your browser reports. These checks confirm the file is a supported knowledge-document type and inspect its structure for unsafe or unsupported characteristics.

Categories LEGACY can detect and block include:

  • disguised executable, installer or script content presented as a document;
  • active document content, such as embedded actions or scripting features;
  • embedded payloads and objects carried inside document packages;
  • macro-enabled office content;
  • malformed, excessively nested or otherwise high-risk archive structures;
  • files that cannot be safely inspected, including password-protected or encrypted files;
  • file types outside the supported set.

A cryptographic fingerprint (SHA-256) is recorded for each file so security and audit workflows can reference it precisely without exposing its contents.

3.Files that fail validation are blocked

Files that fail security validation are blocked from downstream processing. That means no text extraction or OCR, no summaries, no embeddings, no semantic search, no Knowledge Graph extraction, no AI answers referencing them, and no preview or download of the unvalidated file.

Enforcement happens on our servers and in the database, not only in the interface. If validation cannot be completed — for example while a service is temporarily unavailable — the file stays blocked and is retried. It is never let through by default.

4.Additional malware-detection engines

LEGACY is built so that a dedicated malware-detection engine can be enabled for a deployment, and where enabled its clean verdict can be required in addition to the checks above. Where such an engine is enabled, a file it flags as malicious is permanently blocked and cannot be released.

Your administrators can see, inside the platform, which layers are active for your deployment. LEGACY does not describe files as antivirus-scanned unless a malware-detection engine is actually enabled.

5.Security records and audit

Security-relevant file events — validation started and completed, the resulting status, blocked uploads and imports, and any administrative action — are recorded with the organisation, document and actor involved, plus safe technical metadata. File contents are never written into these records.

When a connected source contains a file that fails validation, only that file is blocked. The rest of the synchronisation continues and the blocked count is reported.

6.Important limitation

LEGACY does not guarantee that files are free of malware. Automated file security validation substantially reduces risk and keeps unsafe or uninspectable files out of your knowledge base, but it is not a substitute for endpoint protection on your own devices, nor for a dedicated malware-detection engine where one is not enabled.

Questions about file security for your deployment can be sent to contact@merisontechconsulting.com.