Architecture
What runs where, where your data is stored, and how it is protected.
auth.ekairos.ai identity: people, organizations, keys
▲ validates every request
Browser / backend ──▶ <env>.domainruntime.cloud
│
runtime (Rust): routing, identity, actions
+ data engine: queries, subscriptions, permissions
├─ files, streams
│ ├─▶ PlanetScale Postgres data, 1 primary + 2 replicas
│ └─▶ Amazon S3 files and stream parts
└─▶ your action code
development: an isolated container per environment
production: an immutable release on a managed runnerThe runtime
One Rust service serves every environment: it routes by hostname, checks the caller, runs queries and keeps subscriptions live, admits and records action executions, and stores files and streams. At the data layer it is Instant-compatible — the same query language and real-time protocol — and it adds environments, actions, executions and identity on top.
Live queries are refreshed from the database's own change log, so a write by any process — an action, a workflow, another runtime — refreshes every affected subscriber.
Data
| What | Where | Protection |
|---|---|---|
Entities, links, $users, $files records, executions, stream metadata | PlanetScale Postgres, AWS sa-east-1 | encrypted at rest; TLS only; a primary and two replicas; automated backups |
| File contents and stream parts | Amazon S3, sa-east-1 | private bucket, encrypted at rest (SSE-S3), versioned, TLS only; reached through signed URLs |
| Identity: people, organizations, keys | DomainRuntime Auth | separate database; tokens validated on every request |
Each environment is isolated inside the database by its own application id: queries, permissions and live subscriptions never cross environments.
Your code
- Development: your action code runs in an isolated container per environment, with its own copy of the runtime, as an unprivileged user. Outbound internet is available.
- Production: your action code runs as an immutable build of your domain source on a managed runner in São Paulo. Workflows stay on the release they started on.
Region
All data is stored in São Paulo (sa-east-1).