Overview
3 min
File share overview
Klavi adheres to the following core principles to ensure secure and efficient data exchange:
- Bidirectional Flexibility: "Sharing" is defined as either a proactive Push or an authorized Pull.
- Balanced Architecture: We evaluate every integration based on a trade-off between security, compliance, automation, and operational complexity.
- Security Best Practices: We prioritize short-lived tokens and controlled interfaces over long-term credential sharing to minimize the attack surface.
Integration Patterns
Due to Klavi's infrastructure being hosted on AWS, you may choose one of the following two patterns based on your organization's infrastructure:
1.PUSH Pattern (Klavi → Partner)
In this pattern, the data provider actively(Klavi) pushes files into the requester's environment.
- AWS Cross-Account PUTAWS Cross-Account PUT: Direct upload to an S3 bucket in a different account using IAM roles.
- GCP WIF (Workload Identity Federation)GCP WIF (Workload Identity Federation): Secure, keyless authentication for pushing files to Google Cloud Storage.
- Azure SAS URL(Shared Access Signature)Azure SAS URL(Shared Access Signature): SAS URL can be compared to AWS S3's pre signed URL, but it is more flexible in terms of permission control.
The above different patterns are all based on the data provider's (Klavi) infrastructure being AWS.
2. PULL Pattern (Klavi ← Partner)
In this pattern, the requester retrieves files from the provider’s environment using pre-authorized access.
- AWS Presigned URLAWS Presigned URL: Temporary, time-limited URLs that grant secure access to specific objects without requiring IAM credentials.
- sFTP (Secure File Transfer Protocol)sFTP (Secure File Transfer Protocol): A traditional, robust method for transferring files over a secure data stream.
For detailed integration guides and architecture references, please consult the platform-specific documentation.