16. Deployment Architecture¶
16.1 Components¶
flowchart TD
Mobile["Mobile App"] --> Envoy["Envoy"] --> Vertical["Vertical Backend"]
Vertical --> Identity["Identity Platform"]
POS["POS / Scanner"] --> Identity
Personal["Personal Scanner"] --> Identity
Identity --> PalmVendors["Palm Vendors (via PalmVerifier Port)"]
Identity --> KYCProviders["KYC Providers (via KYC Port)"]
PalmVendors --> XTelcom["X-Telcom BioWave Pass"]
KYCProviders --> Nafath["Nafath"]
KYCProviders --> Onfido["Onfido"]
KYCProviders --> Sumsub["Sumsub"]
Deployment = Identity Platform + paired verification server, running one palm model (§7.10); migratable small→large (§7.11).
16.2 External Dependencies¶
| Service | Purpose |
|---|---|
| Social login | |
| Apple | Social login |
| SMS Gateway | OTP |
| Email Service | Password reset |
| Nafath | KYC (Saudi) — [POST-MVP], §6 |
| Onfido/Sumsub | KYC (Global) — [POST-MVP], §6 |
| X-Telcom BioWave Pass | Palm verification (sole vendor) |