Skip to content

PointSav Documentation

The engineering library for the PointSav platform — operating systems and services for regulated businesses that own their data, their AI, and their record-keeping outright. Where the monorepo holds the code, this wiki holds the reasoning: architecture, services, security, and the governance commitments that bind future development.

ArchitectureIndex

PointSav is composed from three concentric rings with strict one-way dependencies, a deterministic data pipeline that runs fully without AI, and a sovereignty discipline that allows customers to fork the entire stack on day one. Architecture articles describe the structural decisions behind those properties — why they are designed the way they are, how they compose, and what invariants must hold across every deployment.

The three-ring model is the load-bearing frame: Ring 1 handles per-tenant boundary ingest, Ring 2 provides deterministic knowledge and processing, and Ring 3 adds optional AI inference that never writes to the authoritative record. Articles in this category explain the rings, the security model that enforces their boundaries, the AI routing logic, and the customer-ownership principles that govern the platform's commercial architecture.

Start here: Three-ring architecture — the load-bearing frame every other article in this category assumes: three concentric rings with strict one-way dependencies, AI structurally optional throughout.

Where to start

Twenty-nine articles describe the structural decisions behind the platform. These nine are the frame: the composition model everything else assumes, who builds it, what the customer owns, how code reaches them, and the one domain architecture that sits outside the software stack.

  • Three-ring architecture — Three concentric rings with strict one-way dependencies, the AI ring structurally optional. Every other article in this category assumes it.
  • PointSav — company overview and three-organisation structure — Who builds this, and how the vendor, customer, and parent entities relate to one another.
  • Customer hostability — The commitment that every artefact runs on the customer's own hardware and keys, which makes self-hosting the canonical pattern rather than an option.
  • Three-layer architecture — The one-way supply chain from vendor monorepo to customer catalogue to private running instance, and why nothing flows back.
  • Six-tier sovereignty matrix — Six directory prefixes that make the monorepo self-documenting and enforce dependency hygiene by convention rather than by tooling.
  • Economic model — community and SMB customer tiers — A free Community tier as the adoption funnel, and a paid SMB tier aimed at regulated businesses hyperscale billing cannot serve.
  • PointSav software distribution substrate — Release server, storefront, and payment watcher: compiled binaries delivered against on-chain payment, with no accounts and no subscriptions.
  • Totebox session — The standard unit of contributor work: one session, one archive, declared repositories only.
  • Asset-anchored BIM vault — A building's authoritative record as git-versioned flat files that travel with the property deed — the domain architecture the BIM work is built on.

Platform structure

The foundational structural articles — the patterns that compose every PointSav deployment.

  • Three-ring architecture — The durable composition pattern for the platform: three concentric rings with one-way dependencies, where the AI ring is structurally optional and data flows without it.
  • Three-layer stack — The Three-Layer Stack is the infrastructure decomposition pattern across PointSav deployments, separating raw compute, isolated platform execution, and secure operator access.
  • Three-layer architecture — Strict one-way flow of PointSav deliverables through three layers — vendor monorepo, customer showcase catalogue, and private running instances.
  • Six-tier sovereignty matrix — Six fixed directory prefixes organising the PointSav monorepo by purpose, making the repository self-documenting and enforcing dependency hygiene by convention.
  • PointSav architecture 2030 — a planned overview — The planned scope for PointSav's future constitutional charter — not yet ratified or written; described here in planned/intended terms only.
  • Leapfrog 2030 architecture — Structural positioning thesis pairing customer-owned hardware, data, and adapter weights with transactional rather than subscription revenue.
  • PointSav — company overview and three-organisation structure — PointSav Digital Systems is a technology vendor building sovereign, on-premise-capable operating systems for record-keeping, within a three-organisation structure.
  • Platform architecture overview — The platform's cryptographic consistency rests on a real Merkle-chained ledger; sovereign bootability — collapsing a deployment into one portable image — is a design goal, not yet a shipped feature.
  • Architecture overview — PointSav platform — A map of the PointSav platform's major architectural surfaces: compute substrate, software distribution, GIS intelligence, and the editorial pipeline.
  • PointSav platform — architectural overview — The planned scope for a future constitutional charter intended to encode foundational commitments and structural claims governing PointSav engineering decisions — not yet written or ratified.
  • Three-binary architecture: os-console, os-totebox, os-orchestration — Totebox Orchestration is delivered through three binary operating environments — os-console, os-totebox, os-orchestration — each with a distinct role and target.
  • DataGraph Federation: From app-orchestration-slm to app-orchestration-graph — How PointSav federates sovereign per-archive DataGraphs through a single auditable gateway, and the conditions under which that gateway becomes a dedicated service.
  • PointSav software distribution substrate — A three-component system — release server, storefront, payment watcher — delivering compiled binaries against on-chain USDC payments, no accounts or subscriptions.

Customer ownership and deployment

The principles and mechanisms by which customers own their deployment outright.

Location intelligence and domain

Architectural decisions for the location intelligence and real-property domain.

  • Hardware co-location methodology — A structured approach for ranking hardware co-location candidates across jurisdictional, network, infrastructure, and cost dimensions, regulatory requirements first.
  • Flat-file BIM leapfrog — The Building Design System is built on five architectural constraints — flat-file storage, open standards, Rust and Tauri, offline-first operation, and Apache 2.0 licensing. Asset-anchored ownership, offline field use, IoT ingestion, and convergence of the model with lease and financial records follow from the architecture rather than being added on top.
  • Building Design System — A planned coordination layer for the built environment: a canonical, machine-readable library of building-element specifications that independent BIM authoring surfaces consume by reference, the way a software design system keeps independent product teams consistent.
  • Asset-anchored BIM vault — A building's authoritative digital record structured as plain-text and standardized-binary files in a git-versioned directory, qualifying as an ISO 19650-conforming Common Data Environment that travels with the property deed.

An additional planned article for the location-intelligence and BIM/real-property domain — covering regional development taxonomy — is not yet written.

See also

  • Core Concepts — foundational mechanism concepts: the compounding, apprenticeship, citation, and disclosure substrates
  • Design Patterns — named design patterns realised across the platform
  • Governance and Standards — the formal decision records, licensing posture, and compliance requirements
  • Infrastructure — fleet deployment topology, cloud runtime, and physical infrastructure

Cite this record: /wiki/architecture-index — revision 2b7310c2, last updated 6 September 2026.

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is currently a trade name of Woodfine Capital Projects Inc. ("Woodfine"), planned to become a wholly-owned Woodfine subsidiary upon incorporation. PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. The full trademark notice appears in the footer of every page on this site.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →