Technical datasheet

The technical elements for an IT department, a security team or a tender.

In brief

This page gathers what an IT department, a security team or a tender will ask for: components, languages, compatibility, security, compliance.

Two points shape the rest. The architecture is tied to no hosting provider: it rests on standard building blocks, and porting means swapping the equivalent services. And no bank card number ever passes through the platform.

The platform carries no regulatory certification in itself: its architecture allows the operator or the customer to achieve compliance.

What it brings : You answer a tender or an audit with verifiable facts, without having to ask us.

In detail

The architecture is not intrinsically tied to one hosting provider: it rests on standard building blocks — containers, standard authentication, messaging, web interfaces. One implementation serves as the reference; porting to another cloud means adapting the equivalent managed services.

Cloud-side components

ComponentTechnologyService
Control plane interface, product-neutralGoManaged application service
Web consoleReact and TypeScriptStatic site hosting
Asynchronous job runnerGoDedicated ARM machine, for native builds without emulation
Zone reconciliation componentGoManaged containers
Control plane databaseSQLManaged database, authenticated by identity — no application password
Account databasesSQL — one database per account on a shared zone server, with its contained userManaged database: serverless and auto-paused by default, provisioned tier optional
Account sitesSite server and administration interfaceManaged containers, with custom domain and managed certificate
Account business interfacesGo — data and alerts, selling, payment in an isolated schemaContainers and functions, on an event-driven ingestion chain
Online payment providerConnector to the real provider, plus a simulated provider for demonstrationsPublisher secrets in the zone vault, merchant identifier per account
Object storageCompatible with the industry standardManaged object storage
Job queueMessage queueThe runner pulls jobs: no exposed entry point
Image registryContainer registryTokens scoped per team
Secret vaultManaged vault—
AuthenticationStandard identity protocolIdentity provider compatible with enterprise single sign-on

Device-side components

ComponentRole
Operating systemThe device's Linux distribution.
Embedded agent (single binary)Cloud communication, deployment convergence, maintenance sessions, remote agent updates.
Local communication busReal-time communication between the device's applications.
Container runtimeRunning the applications.
Local log storageKeeping and querying application logs.
Cloud synchronisationScheduled file upload and download, processing acknowledgements, managed secrets re-read live.
Hardware simulatorPlaying any declared "thing" — sensors, locks, readers, terminal — without hardware.
Application basesStarting points for the integrator's business code, in four languages plus the interface.
Full-screen displayTouch display, rotation per screen, remote screen mirror.
Boot screenThe customer's logo at start-up.
Network and firewallCascading network configuration, and a declarative firewall closed by default.
USB maintenance linkA network card over the cable and a local interface authenticated by certificate: on-site configuration with no network and no rewriting.
Hardware contractDeclaring "things" in the configuration: the same business code against the simulator and against real hardware.
Android payment terminalThe third device type, companion to a box or standalone, sharing its identity with the agent.

Application languages

LanguageUse
GoAgent, tools, low-footprint services.
Node and TypeScriptApplication services, file synchronisation, logs.
.NET and C#Application services, hardware modules, certified payment terminal.
PythonAudio, language processing, local machine learning, hardware drivers.
KotlinThe Android payment terminal application.
React and TypeScriptTouch user interface.

A library shared across languages — bus, logging, runtime state, sessions — exposes an interface aligned on six stacks, with parity enforced within the same release cycle.

Tools

  • Web console, in any modern browser.
  • Command line: authentication, deployment, status, diagnosis — five binaries covering Linux, macOS and Windows, on 64-bit Intel and ARM.
  • Card writing tool: writing the image to the card, standalone, with no network call and no token.
  • Technician bundle: short certificate, network settings over a USB cable, remote access.
  • The access client is built in, so a bare Windows machine is enough.
  • Development workstation as a device: it receives managed secrets and announces itself as a device of the fleet, without receiving deployments.

Compatibility

Devices64-bit ARM Linux (Raspberry Pi 4, 5, Compute Module 4, Pi Zero 2 W), 32-bit ARM Linux, 64-bit Intel industrial Linux, a development workstation declared as a device, Android payment terminal.
Development workstationsLinux (Ubuntu, Debian and derivatives), macOS (Intel or Apple Silicon), Windows 10 and 11 natively, with or without a Linux subsystem.
Development environmentsVisual Studio Code on every platform, Visual Studio 2022 on Windows for advanced C# debugging, and the JetBrains family.

Security

MechanismDescription
User authenticationStandard identity protocol, compatible with enterprise single sign-on through federation, with the profile created on first access.
Device authenticationOne key per image, signed at build time, never transmitted.
Cloud and device communicationAn encrypted channel, authenticated on every message.
Technician accessA short certificate — two hours by default, forty-eight at most — scoped to a device or a fleet, with the account's authority staying in the vault. Validated offline by the device, including over the USB link.
Secret storageEncrypted at rest, exposed only to authorised principals within their scope.
Managed device secretsNo token or key remains in the configuration: a time-limited storage access, bounded to the device's scope, is minted at each heartbeat; the cloud key comes from the vault. Both are re-read live, with no redeployment.
Distinct device keyThe ingestion key delivered to machines is distinct from the account's administration key, and its role is bounded to three entry points.
Scope isolationContexts are enforced server-side and closed by default, with a role per context.
Non-sequential identifiersRandom business identifiers: a sequential identifier would reveal activity volumes.
Image registry tokensScoped per team: a compromise opens one namespace, not the whole registry.
Isolation between accountsVerification precedes data access, and the out-of-scope answer is "not found" rather than "forbidden".
Device firewallBlocking by default, declarative and cascading.
Code protectionObfuscated and compressed binaries, with no opt-out; code is never in the clear inside an image.

Compliance

The platform carries no regulatory certification in itself: its architecture allows the operator or the customer to achieve compliance.

  • Personal data protection: strict isolation per account, full traceability, erasure per account.
  • Payment security: the terminal module is certified to the applicable standard.
  • No card number passes through the platform: online, the card is entered at the provider.
  • Only a token and a masked reference are kept.
  • VAT: append-only historical rates, breakdown at the date of sale, reports replayable to a date, periodic closing and accounting export on those facts.
  • Audit: a tamper-proof append-only record of configuration and production changes.
  • Data sovereignty: deployment on the customer's cloud — their data and their secrets stay with them.

Some orders of magnitude

Device heartbeatSixty seconds by default, configurable.
Interface latency, excluding long operationsUnder a hundred milliseconds.
Retry after a failed deploymentOne minute, then five, fifteen, and an hour at most.
Standard cloud synchronisationA quarter of an hour, configurable; a few seconds in urgent mode.
Compression of distributed binariesAround 70% reduction.
Lifetime of a storage accessSeven days, renewed at each heartbeat, with an alert less than twenty-four hours before expiry.
Detecting an offline deviceThree minutes by default, adjustable, with an alert to the account when it switches.
Device log retentionThirty days by default, through a nightly job, with archiving.
Size of the card writing toolAbout seven megabytes per platform.

This documentation is produced from the Arkipelis product base. It describes the capabilities of the platform.