
System Architecture
The structural blueprint defining the separation and bridge between Public Gateway (Front-End) and Private Console (Back-End).
Public Gateway
Front-End / Unauthenticated
Landing & Manifesto
Public-facing brand narrative, mission statement, and teaser content.
Xibalba Index
Public web search and limited semantic search capabilities.
Product Suites
Marketing pages for Enterprise, Network, and Cloud products.
Public Capabilities
- View Public Content
- Perform Web Searches
- Request Access / Waitlist
The Handshake
Identity Verification Protocol
Auth Boundary
Strict separation of concerns. No private data leaks to public gateway. Session tokens required for all "Private Core" routes.
Private Console
Back-End / Authenticated
Control Plane
System overview, notifications, and high-level metrics.
Operations
Project management, Distro Builder, and Agent orchestration.
Intelligence
Data synthesis, CRM, Finance, and Analytics dashboards.
Infrastructure
Server management, node provisioning, and network topology.
Operator Capabilities
- Full Database Read/Write
- Deploy Agents & Nodes
- System Configuration
Data Flow & Security Model
Public Access
Anonymous users can only access static content and perform proxied web searches via the LLM layer. No direct database access.
The Airgap
All sensitive entities (CRM, Finance, Nodes) are protected by Row Level Security (RLS) and require a valid session.
Service Role
Background agents operate with elevated privileges via the Service Role key, bypassing RLS for automated maintenance.