Core, regional, edge — one signed data path.
A three-tier topology designed for sovereignty and survivability. The national core holds the tamper-evident ledger and AI enclave; regional nodes serve exam boards; edge kits at exam centres keep working when the network doesn't. Every hop is signed and one-way by default.
National core
Sovereign data centre with the tamper-evident ledger, HSM-backed key custody and on-premise AI enclave. Default-deny egress; M-of-N key ceremony for privileged operations.
Regional nodes
Exam-board presence for authoring, moderation and marking coordination. Reads from the core over signed, mutually-authenticated channels; writes are queued and confirmed.
Exam-centre edge
Offline-first devices with UPS/battery/solar backup. Local write-through cache; sealed uploads on reconnect; MDM-managed fleet with remote wipe.
Trust boundaries
- Every tier hop crosses a mutually-authenticated mTLS boundary.
- Payloads are signed at rest and in transit; ledger anchors are independent of transport.
- No tier can silently rewrite history — the ledger is append-only and anchored across tiers.
Failure modes
- Loss of a regional node: edge kits continue to write locally; core resumes on failover.
- Loss of connectivity at a centre: exam runs to completion; sealed upload resumes automatically.
- Loss of a device: MDM revokes keys; no candidate data leaves the enclave.
See it deployed.
The Deployment page walks through the sovereign hosting model, on-premise AI and the bill of materials for the edge fleet.
