Trust Center
Architecture deep-dive
Diagrams for the pilot as it runs today and for the design that is still ahead. Solid outlines run in the pilot; dashed outlines are designed and not built.
1. The pilot as built
Diagram: the v0.2.0 pilot. One shared hub serves four synthetic tenants; cross-tenant access was refused in every test.
- Field-level AES-GCM encryption for national IDs, MFA secrets and registration change history, under a hub secret.
- Sessions are random 256-bit bearer tokens stored only as hashes, and are revocable.
- Migrations are additive only, and a unit test forbids dropping or deleting.
- SQL sits behind one file to ease a later on-site port; only three files are hosting-specific.
2. The designed clinic
Diagram: the designed small-clinic deployment. Larger sites use multi-node clusters. None of this is built.
- The on-site database is the operational primary; the cloud copy is an encrypted backup replica. That inversion is what lets the clinic keep working when the cloud is unreachable.
- Patient records are never written to the ledger, so correction and deletion rights can be honoured where law allows.
- Sync bundles are signed, hash-chained and encrypted, with gapless sequence numbers and replay protection.
3. Network zones
Diagram: the zone model. Flow rules are in the design document; no network has been built to it.
4. Key hierarchy and data protection
Diagram: envelope encryption in the design. Rotation intervals are open; the pilot has one hub key and no rotation.
- Small sites may use a TPM-sealed or smartcard custody; the large tier calls for an HSM with a validated level still to be confirmed.
- Erasing a patient means destroying the keys by quorum, writing a tombstone and verifying the data is undecryptable. Whether that counts as erasure is pending legal opinion.
5. Audit, backup and safe degradation
Diagram: designed. The pilot has a hash chain and a verify button but no batching or anchor.
Diagram: the pattern. There is no backup in the pilot.
The safe-degradation ladder, from normal operation down to full local-only. A design proposal; thresholds are open.
6. Transfer, limiter and the parts we cannot yet vouch for
Diagram: designed. Key exchange is hybrid classical and post-quantum in the design, and is not implemented or independently evaluated.
Least mature parts
The analog timing layer, camera-resistant screens and sealed terminals are untested hardware ideas. The design’s own goal is “unharvestable, not unhackable”, and we make no claim about their effectiveness. The read limiter’s window lengths and quotas, the scroll-lock threshold and the multi-key threshold are open decisions.
Read the security whitepaper · Security answers in the help center
Walk through the architecture with us
We will show what runs today and what is still a plan.