API Architecture

Revised · architecture/README.md ↗ · 0fa48e326878 ↗

Data flow and network diagramDownload PNG ↓

Nothing that identifies a user reaches our servers. It leaves Cloudflare only for sign-in (GitHub, Google) and billing (Stripe).

Components

Cloudflare is the only way in.

  • dash.isotope13.ai: customer accounts. GitHub or Google sign-in; mints API tokens.
  • api.isotope13.ai: is this PURL, URL, hash, or file hostile? A bearer token resolves to an org for quota.

Cloudflare storage:

  • OID→Org mapper (Workers KV): OAuth IDs, orgs, tokens. Only dash reads identities.
  • Quota tracker (Analytics Engine): request counts per org.
  • Edge cache (Workers Cache) and global cache (Workers KV): verdicts.

Scan servers run in four US colos.

Verdict master stores artifacts on disk and verdicts in PostgreSQL. Scan servers fail over to a replica.

vLLM grades borderline results from the scanner's evidence, never the file or the caller. OpenRouter is the fallback.

Data

Data Personal? Where it goes
IP address, user agent Yes Cloudflare edge only; never logged
OAuth account ID, username or email Yes dash and its KV; GitHub or Google
Name, email, address, card Yes Stripe
Org ID, request counts No Quota tracker
PURLs, URLs, hashes, files, verdicts Rarely, inside a file; public Caches, scan servers, verdict store

Retention: Privacy Policy.

Trust boundaries

  1. Internet → Cloudflare: TLS; OAuth for dash, bearer token for the API.
  2. Cloudflare → colos, and colo → colo: Cloudflare Tunnel public hostnames, bearer token. No inbound ports.
  3. Colos → OpenRouter: TLS, API key.