A claims service receives files over TLS, decrypts them at a gateway, writes a temporary plaintext copy to shared storage, and later imports them into an encrypted database. The shared storage permits reads by an unrelated support group. The architecture review currently lists the entire flow as encrypted. Which change most directly closes the identified access gap while preserving the legitimate processing flow?