# uploads Uploads are tenant-scoped through their parent application. File names are normalized with `Path.GetFileName` and stored under generated names inside the configured attachments root. The API enforces allowed types, a per-file size limit, and the account's total storage entitlement. Downloads resolve the owned database record before opening a file. Files selected for AI are explicit; uploading alone does not send content to a provider.