Skip to content

PointSav Documentation

The engineering library for the PointSav platform — operating systems and services for regulated businesses that own their data, their AI, and their record-keeping outright. Where the monorepo holds the code, this wiki holds the reasoning: architecture, services, security, and the governance commitments that bind future development.

Historical revision — this record as it stood on 5 September 2026, not the current version. View the current record →

service-fs — the WORM ledger backbone

Every record written to the PointSav platform — identity anchors, email communications, document artifacts — lands in service-fs, a per-tenant Write-Once-Read-Many (WORM) immutable ledger. Once written, records cannot be modified or deleted; the ledger is the tamper-evident backbone that Ring 2 services query and Ring 1 services write to. The WORM ledger design article describes the WORM design philosophy in detail.

service-fs is not a general-purpose filesystem. A local filesystem permits reads, writes, modifications, and deletions through a standard directory tree. service-fs exposes a narrow, append-and-verify surface: writing a new record, reading forward from a point in the log, and producing a signed proof of the ledger's current state — plus the cryptographic operations that let a caller verify a specific entry or confirm two checkpoints are consistent with each other. This narrow surface is what makes the ledger's integrity guarantees structurally sound rather than policy-enforced.

Key takeaways

  • The service exposes append, read, checkpoint, and both single-entry and cross-checkpoint verification, over HTTP and over MCP — all implemented, not planned.
  • The ledger is per-tenant — each Totebox holds its own isolated ledger; no cross-tenant reads are possible at the storage layer.
  • Every entry chains cryptographically into the one before it (a linear SHA-256 hash chain), and a dedicated audit-log sub-ledger records every read event alongside the primary record ledger.
  • Recurring Sigstore Rekor anchoring by FS anchor emitter creates an external, publicly verifiable timestamp chain for the entire ledger, running on a monthly cadence.
  • Today's deployment is a standard Linux/BSD daemon with process-level isolation — a real but weaker guarantee than a microkernel-enforced boundary would provide. A seL4 microkernel envelope was explored as a bare-metal unikernel design under this same package name; that design now lives in its own separate vendor package, and no seL4 target is under active development inside the current service-fs codebase.

The layered architecture

service-fs separates concerns into layers that can change independently:

  • Anchoring: monthly work performed by FS anchor emitter, anchoring signed checkpoints to the public Sigstore Rekor log.
  • Wire protocol: an HTTP interface (via axum) and an MCP server interface, both exposing the same underlying operations to different kinds of callers.
  • Ledger contract: a stable Rust trait — append, read since a cursor, checkpoint, and both proof operations — that the wire layer and the storage layer both compose against, so either can change without breaking the other.
  • Storage: today, a per-tenant POSIX-file-based hash-chain log using the C2SP tlog-tiles format for the on-disk tile structure and C2SP signed-note format for checkpoints.

Durability

The ledger's on-disk format follows open standards rather than a proprietary schema — C2SP tlog-tiles for the log itself, C2SP signed-note for checkpoints — so a future reader could decode the raw files with standard tools even without the platform's own software. Every write also lands in the audit-log sub-ledger, an independent WORM record of read activity alongside the primary data.

Threat model

  • Operator tampering. Even an administrator with direct access to the storage can't alter a past record without breaking the hash chain — and a broken chain is detectable both locally and against the externally-anchored Rekor checkpoints.
  • Vendor obsolescence. The open-standard on-disk format is designed to outlast any particular vendor's software.

See also

Important Information

Corporate structure. PointSav Digital Systems ("PointSav") is currently a trade name of Woodfine Capital Projects Inc. ("Woodfine"), planned to become a wholly-owned Woodfine subsidiary upon incorporation. PointSav does not itself offer, sell, or solicit any security. Any securities offering associated with Woodfine's real-property direct-hold solutions is made exclusively by Woodfine, and only by means of the applicable Private Placement Memorandum.

No investment advice. This wiki's content is provided for engineering, operational, research, and development purposes. Nothing on this wiki constitutes investment advice or a solicitation to invest in any Woodfine partnership or direct-hold solution.

Intellectual property. The PointSav name, trade name, wordmark, and marks, together with all current and future PointSav- and Totebox-branded products, services, and offerings — and the software, source code, documentation, design system, and all related materials — are proprietary to Woodfine and its affiliates, except for components identified as open source. No rights are granted except as expressly set out in a written license or agreement. The full trademark notice appears in the footer of every page on this site.

Open source components. Portions of the platform are made available under permissive open-source licenses identified in the accompanying repository. Use of those components is governed by their respective license terms.

No warranty; informational use. Content on this wiki is provided for general informational purposes only and does not constitute a representation, warranty, or commitment with respect to product functionality, availability, pricing, or roadmap. Some articles describe planned or intended features, capabilities, and milestones — language such as "planned," "intended," "targeted," "may," and "expected" marks this forward-looking content, which is subject to change and does not constitute a commitment regarding future performance.

Confidentiality. Where an article describes an operational or deployment detail that is not intended for public disclosure, that article is not published on this wiki. Content here is general-purpose engineering documentation, not customer-specific configuration.

Jurisdiction. Woodfine Capital Projects Inc. is organized in British Columbia, Canada. References to the Sovereign Data Foundation on this wiki describe a planned or intended initiative only, not a current equity holder or active governance body.

Changes to this notice. PointSav may update this notice from time to time; the version posted on this page governs.

Not a filing system. This wiki is not a securities filing system, an electronic disclosure repository, or a substitute for SEDAR+ or any other regulatory filing system. Formal securities filings are made through the applicable regulatory filing system, not through this wiki.

Full disclaimer. This notice supplements, and does not replace, the full Disclaimers article. In the event of any conflict, the full Disclaimers article governs.

Read the full disclaimer →