Skip to main content
Certyneo
Glossary term · V

Antivirus verification of uploaded documents

Definition

Before a document is integrated into a signature workflow, any responsible platform must submit it to antivirus (AV) analysis. Threats targeting PDFs include: embedded macros, malicious JavaScript (AcroForms), PDF parser exploits (CVE-2019-12657, etc.). Cloud scanning solutions (ClamAV open-source, OPSWAT MetaDefender, VirusTotal API) analyze the file in milliseconds. ISO 27001 and SOC 2 Type II compliance requirements impose AV analysis of all incoming documents. An infected document in a signature workflow is particularly risky because it is sent to all signers, amplifying the attack vector. AV verification must be done before database storage, not after. Certyneo analyzes each uploaded document via ClamAV (in-process daemon) and blocks suspicious files with an explicit error message, never propagating them to the workflow.

Ready to put these concepts into practice?

Certyneo allows you to create eIDAS-compliant signature envelopes in a few clicks, without installation.