Skip to content

PointSav Documentation

The engineering library for the PointSav platform — operating systems and services for regulated businesses that own their data, their AI, and their record-keeping outright. Where the monorepo holds the code, this wiki holds the reasoning: architecture, services, security, and the governance commitments that bind future development.

Historical revision — this record as it stood on 22 August 2026, not the current version. View the current record →

app-mediakit-marketing — agent-authored marketing landing server

app-mediakit-marketing is a Rust web server that delivers marketing landing sites — server-rendered, agent-first. A page is a typed manifest, not free-form Markdown or HTML: it composes a title, description, language, and an ordered list of typed sections (a hero, for instance) drawn from the shared app-mediakit-shell section vocabulary. The binary validates every manifest against that vocabulary before it can render, so a manifest either conforms or is rejected — there is no partial or malformed page.

Agent-first authoring, human-gated publish

Content on this platform is meant to be authored by an AI agent and approved by a human before it goes live, the same SYS-ADR-10/SYS-ADR-19 human-checkpoint pattern applied elsewhere on the platform. An MCP server, mounted at POST /api/mcp when explicitly enabled, exposes tools an AI author calls directly: list the available section types, read an existing page, validate a draft manifest against the section contract, propose a new or revised page, and list what's currently pending.

An AI author never writes to the live content tree. propose_page validates the manifest and stages it as a pending item; nothing is published until a human reviews the proposed manifest against what's currently live and approves it. There is no automated publish path.

Architecture

Binary

A single statically linked Rust binary (app-mediakit-marketing) runs the server, built on Axum. No runtime dependencies beyond the OS kernel and a libc.

Multi-tenant via environment variables

A single binary supports multiple tenants. Tenant identity is set at startup via SERVICE_MARKETING_MODULE_ID (e.g., woodfine, pointsav); content directory, bind port, and site title resolve from this value.

Two instances running the same binary on the same host demonstrate this:

Instance Tenant Domain Port
media-marketing-landing-1 woodfine home.woodfinegroup.com 9102
media-marketing-landing-2 pointsav home.pointsav.com 9101

Each instance is a systemd service with its own unit file and environment block. Neither instance knows about the other.

Sovereignty and Tier 0 alignment

The Compounding Substrate discipline defines Tier 0 as an operator-owned system that functions without any vendor cloud dependency. app-mediakit-marketing meets this bar:

  • Single binary with no external runtime dependencies
  • File-based content storage — page manifests on disk, no database
  • nginx reverse proxy handles TLS; no managed load balancer required
  • Runs on the smallest commercially available VPS ($7/month)

An SMB operator can run their own marketing landing site on hardware they own, with software built from auditable source, without any ongoing vendor relationship.

Deployment pattern

app-mediakit-marketing is deployed behind nginx. nginx handles:

  • TLS termination (Let's Encrypt via certbot)
  • Static file serving for robots.txt and sitemap.xml
  • HTTP→HTTPS redirect
  • Reverse proxy to the binary's loopback port

The binary never listens on a public port. All public traffic passes through nginx.

Internet → nginx :443 (TLS) → 127.0.0.1:PORT → app-mediakit-marketing
                              │
                              └→ CONTENT_DIR/ (page manifests)

Live reference deployments

Two deployments are active as of 2026-05-07 on foundry-workspace:

  • home.woodfinegroup.com — MCorp customer-tier marketing site. Demonstrates the customer pattern: operator-branded, operated under the customer's identity.
  • home.pointsav.com — PointSav vendor-tier open reference deployment. Demonstrates the vendor pattern: a public reference that prospective customers can inspect before deploying their own instance.

Both sites run the same app-mediakit-marketing binary. The difference is content and theme tokens.

See also

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is currently a trade name of Woodfine Capital Projects Inc. ("Woodfine"), planned to become a wholly-owned Woodfine subsidiary upon incorporation. PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. The full trademark notice appears in the footer of every page on this site.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →