Trust Center
Architecture: pilot versus design
The pilot runs in the cloud. The designed system adds an on-site server, a ledger of hashes and a ladder of safe degradation. The diagram marks which is which.
Solid elements run in the pilot. Dashed elements are designed and not built.
The pilot Pilot
- Electron client and a tablet web build, over HTTPS and secure WebSockets.
- A Cloudflare Worker with one Durable Object per facility for live fan-out and timers.
- One database with a clinic identifier on every tenant table (test-enforced).
- Additive-only migrations. Plain SQL behind one file to ease a later on-site port.
The design Designed
- A closed on-site server per clinic, cabinet-sized for small sites.
- A federated ledger per clinic or network holding only hashes, consent and audit events.
- Three backup copies on two media with one offsite and one offline; verified restores.
- Server-to-server transfer in three streams with hybrid post-quantum key exchange.
Safe degradation ladder
From normal operation down to full local-only. A design proposal. Thresholds are open decisions.
Not met today
The specification requires local operation without the network. The pilot is cloud-only, and a network outage stops alerts and messaging. This is a known defect, not fixed.