Blake Medulan · Architecture Collection

A collection of architectures

Interactive architecture and concept diagrams spanning the Score Anything Loyalty platform I build at 3 Halves Labs, my independent, openly-built projects (Sepulchre, OSSS and more), and reference studies. Many have an Executive / Developer toggle, and there's a deliberate focus on AI architectures that make different methods and decisions — hosted multi-agent systems, on-box constrained-decoding models, and computer-vision and physics-based estimation — pulled together in the AI Architecture Decisions capstone.

The AI through-line across the collection

The pieces below live in different tracks, but they answer one question in different ways: what kind of AI does the job, given what matters most? This capstone puts them side by side.

AI patterns · schematic views
AI training data
LLM runtime · serving & safety
AI operations · lifecycle & orchestration
AI evaluation
Score Anything Loyalty 3 Halves Labs · product

The sports-loyalty platform end to end: how a signal becomes points, the data and AI that sit behind the loyalty markets, and the governance and compliance around them.

Edge
Tracking SDK
→
Spine
Data Platform
→
Consumer
AI Estate
+
Integration
Identity Federation
Governance underneath everything: the Privacy & Tracking Control Plane — consent, residency, lineage and access policy — spans all of it.
Enterprise architecture views
The platform, end to end
EdgeOpen ↗

Tracking SDK Architecture

@3halves-labs/score-tracker · web · iOS · Android

The full journey of a browser signal becoming loyalty points: capture → consent-gated enqueue → batching → the wire envelope → middleware queue → ERP rules → points. Includes the lifecycle, a system map, a subsystem catalogue and the contract & failure-mode reference.

Executive + DeveloperInteractive flowContracts & resilience
score-sdk-architecture.html
SpineOpen ↗

Player Data Platform

event-driven data backbone

The reference architecture between the edge and the models: a durable streaming bus, stream and batch processing, a bronze/silver/gold lakehouse, a feature store and activation — with cross-cutting governance, lineage, quality and SLOs. Every block names the industry archetype it maps to.

Executive + DeveloperMedallion lakehouseArchetype-mapped
player-data-platform.html
AI estateOpen ↗

AI Estate & Governance Map

every model, agent and data path

The map of the AI estate: where models and agents live, what data each touches, and the governance that binds them. The consumer end of the platform, sitting on the data spine and inside the guardrails.

AI inventoryData pathsGovernance
score-ai-governance-map.html
GovernanceOpen ↗

Privacy & Tracking Control Plane

consent · residency · lineage · access

The governance layer that spans the whole platform: consent capture and enforcement, data residency, lineage, and the access policy that decides who and what can read each class of data.

ConsentResidency & lineageAccess policy
score-privacy-control-plane.html
IntegrationOpen ↗

Architecture Console — Identity Federation

SCORE ↔ URC · OIDC + PKCE

The federation topology seen through analytical lenses — risk heatmap, blast-radius cascade, data classification, sovereignty and latency — plus the brokered OIDC flow and the embedded third-party SDK. Click any node or edge to open its risk register.

Multi-lens topologyBlast radiusThreat model
Architecture Console.html
Identity flowOpen ↗

How a User Is Created

Auth0 · Keycloak · Mongo · Odoo

A user is up to four records across four systems, linked by shared ids. Four entry paths — only two create a user — with a step-through of the primary lazy, JWT-triggered Auth0 → Mongo → RabbitMQ → Odoo flow, the cross-system identity trail, and the caveats the trace surfaced.

Path walkthroughIdentity trailCaveats & gaps
score-user-creation.html
The loyalty loop
AI governance & security
GuardrailsOpen ↗

Score AI Guardrails Architecture

MCP · least-privilege access · no public leakage

Defense-in-depth for Score AI as an MCP server, seen through three lenses (Security, Privacy, Executive). A request-trace simulator walks a request through all eight guardrail layers, an access evaluator and an egress simulator block over-reach and leakage, plus a threat model (OWASP LLM / MCP / ATLAS) and a conformance matrix to ISO 42001 / 27001 / 27701, SOC 2, GDPR and the EU AI Act.

Tri-lens (Sec / Privacy / Exec)Request-trace + simulatorsISO · SOC 2 · GDPR mapped
score-ai-guardrails.html
Multi-agentOpen ↗

Predictor Agents — multi-agent framework

supervisor · specialists · ensemble · market

The prediction service behind the loyalty markets, seen as executive or engineer. A supervisor orchestrates specialist predictor agents; an ensemble/critic/risk chain blends, calibrates and guards them; a market-maker prices the result; and a closed learning loop grades every outcome. Sits on the data platform, governed by the AI guardrails, exposed via the Score AI MCP.

Executive + EngineerTopology + lifecycle walkEnsemble · calibration · learning loop
score-predictor-agents.html
ComplianceOpen ↗

What SOC 2 Needs

Trust criteria · controls · journey · checklist

What Score has to put in place for a SOC 2, mapped to its actual stack. The five Trust Services Criteria with a scope selector, the nine Common Criteria (CC1–CC9) and the controls that satisfy them, the practical control domains, the road from gap assessment to a Type II report, and a 36-item readiness checklist.

Trust criteria + CC1–CC9Stack-mapped controlsReadiness checklist
score-soc2-compliance.html
ScoreMotion · markerless biomechanics
Delivery & promotion
Independent & open source my own projects · in the open

Projects I build and govern in the open, outside 3HL: a zero-knowledge credential broker, an open scheduling standard, an ISO 20022 MCP server, and an AI architecture-review tool.

Sepulchre · zero-knowledge credential broker

Built on Vault and vendor-neutral by design, where the operator's inability to read tenant secrets is enforced by policy and provable from the audit log — with an on-box AI substrate so its AI features never ship data to a third party.

Project · SepulchreOpen site ↗

Sepulchre — the full architecture site

zero-knowledge credential broker · complete deep-dive

Start here for the whole picture: the standalone Sepulchre architecture site brings the system design, the zero-knowledge guarantee and the on-box AI substrate together in one place, with the reasoning behind each. The individual diagrams below drill into the pieces.

Vault coreZero-knowledgeOn-box AI
/architecture-site/index.html
SystemOpen ↗

Sepulchre — System Architecture (v2)

credential broker on Vault · vendor-neutral

The v2 architecture: a stateless broker over a Vault cryptographic core, Postgres for metadata only, a signed audit pipeline, and pluggable roots of trust. Five actors, pooled and siloed tenancy from one binary, the two canonical data flows, and the deployment topologies with a bounded-blast-radius failure model.

Vault corePooled + siloedData flows + failure modes
sepulchre-system-architecture.html
Zero-knowledgeOpen ↗

Sepulchre — The Zero-Knowledge Guarantee

by policy, not by promise

How the operator's inability to read tenant secrets is enforced and proven. Walk an attempted operator read through the policy, code, CI and operational layers that each stop it independently, then the per-tenant key hierarchy, the signed hash-chained audit event and the continuous attestation that makes the empty human-read list provable. BYOK for the strongest form.

Defense-in-depth walkHash-chain attestationBYOK
sepulchre-zero-knowledge.html
AI substrateOpen ↗

Sepulchre — Embedded AI Substrate

on-box SLM · grammar-constrained decoding

Audit Q&A and compliance narratives without a hosted API: an in-process small language model (Qwen2.5-1.5B via node-llama-cpp) that never sees plaintext, runs in a credential-less worker, and is grammar-constrained (GBNF) to emit only a whitelisted audit-query object — never free-form SQL. The architecture, an interactive constrained-decoding walkthrough, the decision record and the benchmark plan.

On-box SLMGBNF constrained decodingZero-knowledge
sepulchre-ai-substrate.html
Structured Streaming · open-source engine
Open Sports Scheduling Standard
Open Banking · ISO 20022 MCP
AI tools
Reference & studies study · not my product

Reference and solution architectures, plus interactive tools — some designed from scratch for a platform or a role, some built to study a published design.

Solution architectureOpen ↗

Secure AI on Azure Databricks

conversational + agentic AI on the Lakehouse

A reference architecture for conversational and autonomous-agent AI on the Azure Databricks Lakehouse: ingestion → medallion → Unity Catalog governance → serving, the chat/voice/agent layer with governed retrieval and tools (plus Vertex AI / Gemini as a multi-cloud model option), six security pillars (Entra ID, Unity Catalog row/column security, Private Link, customer-managed keys, Mosaic AI Gateway guardrails, audit), a quality layer (data-quality tests, agent evaluation, a CI gate, and Lakehouse Monitoring for data and model drift), and a governed request walk. The through-line: the AI inherits the platform's access controls, so it can never surface data the user isn't entitled to.

Databricks + Unity CatalogRow/column security into RAGCMK · Private Link · GatewayEval + drift monitoring
databricks-secure-ai.html
Deployment · scalingOpen ↗

Azure Databricks — Landing Zone, Compute & Cost

deploy · scale · cost the secure-AI platform

The deployment and scaling companion to the secure-AI architecture: the Azure landing zone (control-plane vs data-plane split, injected VNet with host/container subnets, front-end and back-end Private Link, ADLS and Key Vault behind private endpoints, controlled egress), compute scaling (serverless vs classic per workload, model-serving concurrency, Vector Search sizing), and a cost model showing what each component's bill is proportional to and which lever bends it — including the monitoring and evaluation costs that scale with traffic.

Control / data planeServerless vs classicCost & attribution
databricks-deployment-scaling.html
Reference archOpen ↗

Open Banking on AWS

AWS reference architecture · rebuilt

A clean, interactive rebuild of AWS's "Open Banking on AWS" reference architecture: nine zones from consumer through edge, API Gateway (mTLS + OAuth 2.0 + TSP), ECS/Fargate microservices and the hybrid path to the bank core, all 18 numbered components clickable, plus Account-Information and Payment request-flow walkthroughs. Architecture and service names © Amazon Web Services.

9 zones · 18 componentsRequest-flow walksAWS reference
open-banking-aws.html
ReferenceOpen ↗

Front-End Data Caching — Playground

cache-first · network-first · stale-while-revalidate · …

Pick a caching strategy, fire a read, and watch data move between the component, the client cache and the origin — with freshness, latency and offline outcomes. Includes a comparison matrix and a mapping to Cache-Control, TanStack Query, SWR, Apollo and Workbox.

Interactive simulatorStrategy comparisonAPI mapping
frontend-caching-playground.html
Architecture collection by Blake Medulan  ·  Score Anything (3 Halves Labs), independent open-source projects (Sepulchre, OSSS), and reference studies
marks an AI architecture  ·  dashed cards are in progress  ·  contact blake@3halves-labs.com