Skip to content

16. Deployment Architecture

16.1 Components

flowchart TD
    Mobile["Mobile App"] --> Envoy["Envoy"] --> Vertical["Vertical Backend"]
    Vertical --> Identity["Identity Platform"]
    POS["POS / Scanner"] --> Identity
    Personal["Personal Scanner"] --> Identity
    Identity --> PalmVendors["Palm Vendors (via PalmVerifier Port)"]
    Identity --> KYCProviders["KYC Providers (via KYC Port)"]
    PalmVendors --> XTelcom["X-Telcom BioWave Pass"]
    KYCProviders --> Nafath["Nafath"]
    KYCProviders --> Onfido["Onfido"]
    KYCProviders --> Sumsub["Sumsub"]

Deployment = Identity Platform + paired verification server, running one palm model (§7.10); migratable small→large (§7.11).

16.2 External Dependencies

Service Purpose
Google Social login
Apple Social login
SMS Gateway OTP
Email Service Password reset
Nafath KYC (Saudi) — [POST-MVP], §6
Onfido/Sumsub KYC (Global) — [POST-MVP], §6
X-Telcom BioWave Pass Palm verification (sole vendor)