// Reference Architecture
Referenced Stack
How the products we carry in Japan fit together, on one drawing. Data moves up from source systems through ingestion, storage, and AI to the applications people use, with Kubernetes underneath and identity, keys, and compliance spanning every tier. Security appears in two forms: a security-analytics use case running on the same engines that hold the data, and standalone point solutions for email authentication and device risk. Solid lines carry data, dashed lines carry control. This is an indicative architecture shown for illustration only, and actual technical integration varies by product and deployment.
Referenced Stack
SC-RA-01 · REV B · 2026.07
T0External
Data Sources
Customer systems of record, event producers, mail flow, and the device fleet, outside the platform boundary.
OLTP / Legacy Databases
db.oltp · cdc-enabled
ERP & SaaS Applications
app.erp · saas
Event Streams & Logs
mq.kafka · logs
Files & Object Storage
obj.s3 · files
Data Warehouse & Lakehouse
db.warehouse · lakehouse
3rd-Party APIs
api.rest · external
Outbound / Inbound Mail Flow
smtp.mta · sending domains
IoT / OT Devices
edge.iot-ot · unmanaged
T1
Integration & Ingestion
Change data capture and streaming ETL carry source data in with sub-second latency.
VendorCDC Pipelines
svc.cdc · exactly-once
Real-Time Streaming
svc.stream · sub-second
In-Flight Transformation
etl.in-flight · sql
Data Replication
svc.replicate · migrate
T2
Processing & Storage
One distributed SQL engine carries transactional, analytical, and vector workloads.
VendorUnified Data Store (OLTP + OLAP)
db.htap · distributed-sql
Hybrid Query Engine
sql.oltp+olap · mpp
Vector Store & Search
db.vector · ann-index
Unified Object Storage
obj.unlimited-storage
T3
AI / ML
Training, serving, and retrieval. Features and vector search are served by the same engine that holds the data.
Model Training
gpu.train · ml/dl/rl
Model Serving & Inference
svc.infer · realtime+batch
Global LLM
llm.global · hosted-api
Sovereign LLM
llm.sovereign · self-hosted
RAG & Semantic Search
svc.rag · semantic-search
Feature Store & Serving
db.features · low-latency
T4
Decision Intelligence
A model-independent layer above the models: persistent decision state, orchestration across any LLM, a continuous learning loop, and provenance. It keeps the stack portable and sovereign as the underlying models change.
Decision State
intel.state-store · persistent
Model Orchestration
svc.model-router · any-llm
Continuous Learning
svc.learn-loop · closed-loop
Provenance & Lineage
svc.provenance · federated
Sovereign Control
policy.sovereignty · self-hosted
T5
Serving & Applications
Where results reach people: embedded analytics, APIs, applications, and agents.
VendorEmbedded Analytics & Dashboards
ui.embed · white-label
API Gateway
net.gateway · rest/sql
Business Applications
app.custom · frameworks
AI Agents
app.agent · llm-backed
S0
Cloud / Kubernetes Substrate
Every tier above runs as containers. Predictive AIOps keeps the cluster right-sized.
VendorKubernetes Orchestration
k8s.control-plane
Predictive Autoscaling
k8s.hpa · federator.ai
GPU / CPU AIOps Monitoring
obs.aiops · gpu/cpu
Ingress & Load Balancing
net.ingress · l4/l7
Multi-Cloud & Hybrid
cloud.hybrid · on-prem
schedules, scales, and observes every tier above
Deployment
UC
What the platform delivers
One stack, several outcomes. Analytics, AI applications, and security monitoring all run on the same engines, so a security use case reuses the same engines the platform already runs on.
Real-Time Analytics
Live dashboards and operational reporting over data that lands in seconds.
Powered byStriimSingleStoreLogiAI & RAG Applications
Retrieval, model serving, and agents built on vectors held next to the source data.
Powered byStriimSingleStoreProphetStorSecurity Analytics / SIEM
Security logs stream in, get queried for threats in sub-second time, and reach the SOC as dashboards.
Powered byStriimSingleStoreLogiCustomer 360 & Data Hub
One current view of a customer or product, joined live from every source system.
Powered byStriimSingleStorePredictive Operations
AIOps that forecasts load and right-sizes GPU and cluster capacity before it runs short.
Powered byProphetStorSingleStoreDevice & Email Trust
Continuous device risk scoring and email authentication, run as their own point solutions.
Powered byDeviceTotalValimailSEC
Security Point Solutions
CybersecurityTwo focused security products that run on their own, with or without the platform. Each is a pipeline you can read left to right.
SEC-1
Email Authentication Pipeline
Every message is checked against SPF, DKIM, and DMARC. Enforcement at p=reject stops spoofing, BIMI puts the verified brand mark in the inbox, and aggregate reports feed telemetry.
01SPF / DKIM / DMARC Checks
auth.spf/dkim/dmarc
02Policy Enforcement (p=reject)
policy.p=reject · dns
03BIMI Brand Indicators
brand.bimi · vmc
04DMARC Reporting & Telemetry
rpt.rua/ruf · telemetry
SEC-2
Device, IoT, OT & Network Security
Agentless discovery inventories IT, IoT, OT, and network assets. Risk intelligence correlates firmware-accurate CVE data from 874 vendor sources into posture, supply-chain exposure, and a ranked remediation queue.
01Agentless Asset Discovery
inv.agentless · vendor/model/fw
02Vulnerability Intelligence (CVE)
intel.cve · 874 vendor feeds
03IoT / OT Risk Posture
risk.firmware · eol/eosl
04Supply-Chain Device Risk
risk.supply-chain
05Prioritized Remediation
act.remediate · ranked
verdicts, risk scores, and remediation actions feed the tiers above
// Vendor Placement
Where each product sits.
Want your product mapped to this stack?
Send us your product architecture. We reply with where it fits in this stack, and what gaps remain.
