# Architecture and trust boundaries

```mermaid
flowchart TD
  TG[Telegram users / staff] --> BOT[Aiogram bot]
  WEB[React command dashboard] --> API[FastAPI gateway]
  BOT --> DB[(PostgreSQL 16)]
  API --> DB
  API --> CACHE[(Redis cache / rate-limit store)]
  API --> AUDIT[Append-only audit events]
  API -. optional provider boundary .-> AI[AI suggestion service]
  API -. later phase .-> VOICE[Voice service]
  API -. later phase .-> CHAIN[Blockchain audit adapter]
```

## Authentication
Short-lived signed access tokens, Argon2 password hashing via `pwdlib`, active-account lookup on every authenticated request, role checks in API dependencies. The current Phase 1 build has no refresh-token rotation, TOTP, or WebAuthn; those are required before production staff access.

## Data boundaries
KYC files should not be stored in public web roots or raw database blobs. Current schema only stores `document_refs` for the future private vault integration. Do not send sensitive onboarding documents to AI providers. Audit logs capture security-relevant actions but are not yet cryptographically chained or on-chain.

## Scale and performance
The Compose profile is a developer/single-node baseline. It is not proof of 100K concurrent users or 99.99% uptime. A real scale program needs load testing, queue workers, connection-pool tuning, horizontal replicas, managed PostgreSQL/Redis, WAF, SLOs, backups, failover, and region-by-region data residency review.
