How QCUL Protects Private Laboratory Storage

QCUL stores packages, checkpoints, manifests, evidence, and temporary operational artifacts under a protected private storage area rather than placing them in ordinary public content paths.

Private storage role

Current source uses a protected area under media/quantacade/qcul-private with run-scoped subdirectories for packages/checkpoints/evidence. QCUL creates restrictive filesystem/server-denial protections where supported.

Path validation

Laboratory runtime/install operations verify that package paths remain inside the allowed run-owned package vault before use. This prevents a signed lab-install call from being repurposed to install an arbitrary server file.

Operational care

  • Do not move private QCUL artifacts into a public downloads directory.
  • Maintain sufficient disk space/permissions for the protected directory.
  • Let QCUL lifecycle cleanup remove owned temporary data.
  • Treat a backup containing this directory as sensitive maintenance data.

Defense-in-depth principle

How QCUL Protects Private Laboratory Storage is one layer in QCUL’s security model. Keep Joomla ACL, CSRF tokens, private gate/storage, laboratory identity, runtime authorization, side-effect quarantine, production Super User checks, and careful handling of production-derived evidence together rather than weakening another control to make one workflow more convenient.


Community Discussion

Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.