What it means
Anti-virus capabilities are built into Pega Cloud environments to scan supported files and uploads for potential malware.
-
If a scanned file is clean, it can continue through the supported upload or storage flow.
-
If a scanned file is flagged, the suspected file is quarantined.
-
Pega Cloud Security Operations Center (CSOC) is notified when a scan detects potential malware.
What it does
-
Provides workload protection across Pega Cloud environments.
-
Scans file and attachment uploads that follow standard upload flows.
-
Covers SFTP uploads, Data Transfer Service (DTS), and Cloud File Storage.
-
Quarantines suspected files when potential malware is detected.
How it works
What users may see
-
If a case attachment is flagged, users may see an error when the file is attached or when they try to access it.
-
For SFTP and DTS uploads, a flagged file becomes inaccessible.
-
No client action is needed to handle the quarantined file.
Best practices / learner callouts
-
Use standard Pega upload flows where possible, because the documentation explicitly identifies protection for standard upload flows using the out-of-the-box Pega file attachment rule.
-
Be careful with client-created custom upload flows, because the documentation states those custom flows are not protected.
-
Set expectations that flagged files are quarantined and may be inaccessible to users.
-
Point learners to the Pega Cloud Security and data protection documentation and the Pega Platform Security Checklist for broader security context.
Technical documentation: Anti-virus on Pega Cloud – docs.pega.com

