Technical deep dive

Architecture at a glance

How the AST core is built: a NestJS core with an append-only journal as the source of truth, Proof of Transaction as the only economic gate, and a Next.js portal that admits institutions but never mints.

Stack

  • Core — TypeScript / NestJS services; the append-only journal (RocksDB) is the source of truth.
  • Portal — Next.js user interface with a separate edge service (BFF) and OpenAPI contract; admission only, never issuance.
  • Money arithmetic — decimal library, never floating point; all clocks in UTC.
  • Optional infrastructure — Postgres index mirror, Redis session assist, event export and JSON logs may be added, but none of them can become a source of truth.
  • On-chain representation — optional adapters may attest the journal tip for explorers; ERC standards are representation adapters, never the source of truth.
Module

proof_of_transaction_engine

Validates the fact of execution against criteria P1–P4 and returns a verdict with reason codes.

Module

nodechain_engine

Assembles execution snapshots, validates and appends them to the journal with cryptographic chaining.

Module

tokenomics_service

Issuance, burn and accounting of ArosCoin and tokens of rights — only after a positive verdict.

Module

settlement_controller

Commission pool and payment to nodes after confirmation.

Module

release_daemon · velocity_tracker

Track the reserve index and velocity; Release Phase activates only when both thresholds hold.

Module

node_reputation_service · resource_monitor

Node reputation and weight; resource intensity and energy cost of operations.

Process lifecycle

  • Intake — an allowlisted institution submits a document package through the portal edge; signature and package hash are verified.
  • Orchestration — the orchestrator assigns a process ID and drives the stages with per-step and whole-process timeouts.
  • Verdict — quorum validators evaluate P1–P4; one institutional certificate counts as one vote, however many nodes it runs.
  • Record — every significant state is appended to NodeChain before its effect is acknowledged.
  • Economics — issuance or burn, commission and node payment happen only after verified = 1.
  • Public view — anyone can read the redacted status of a process ID on the explorer.

Operational defaults (v1)

  • PoT confirmation timeout — 15 minutes; orchestrator step timeout — 5 minutes; process timeout — 30 minutes.
  • A positive verdict is final: it is not compensated or reversed. If issuance succeeded and settlement failed, settlement is retried — the issuance is not burned back.
  • Oracle failure fails closed: the process expires rather than proceeding on missing data.
  • A kill switch places the engine in read-only mode.
  • Environments — local, test, sandbox and production.

Security

  • Institution authentication at the edge by shared secret (pilot), mutual TLS map, or OIDC bearer tokens.
  • Detached X.509 verification of document-package hashes against configured trust anchors.
  • Idempotency keys generated with a cryptographically secure random source.
  • Human confirmation remains mandatory for any document-assist step; AST never appraises.

Release 1.2.0 is a pilot-ready baseline. It is not a regulated production certification, has not completed an external audit, and is not a multi-node mainnet — those steps are ahead.