Keystone architecture + integration.
Written for engineering, security, and procurement reviewers. Data model, five downstream engines, integration surfaces (ingest, event stream, per-asset API, index API, webhooks), signature and audit primitives, tenant isolation model, deployment posture. The append-only lifecycle event log is the source of a per-unit warranty and lifecycle audit trail that survives ownership changes, refurbishment, and downstream deployment. Print-friendly for internal circulation.
Keystone architecture: three reading levels.
Same concept. Three depths. Pick the one that matches how much time you have. The full detailed page is below.
Keystone is API-first data infrastructure: a per-asset signed and hashed record, a deterministic quality score (KeyScore 0–99), and five downstream engines that read the same record. Not a monolith; every engine is independently adoptable. Not a regulated entity; NRSRO / MGA / broker-dealer / Treasury partners handle every regulated function. Managed SaaS with per-partner tenant isolation and immutable per-tenant audit log.
If your team is doing engineering, security, or procurement review on Keystone, this page is the single-source technical brief. Keystone has eight architectural surfaces: (1) the per-asset record with published CC0 schema; (2) five downstream engines each with its own contract and API; (3) five integration surfaces (Ingest API, event stream, per-asset API, index API, webhook subscriptions); (4) ECDSA-signed records with hash-chained lifecycle events; (5) row-level tenant isolation with capability-scoped API keys; (6) managed SaaS deployment with per-region data residency at Enterprise tier; (7) an explicit list of what Keystone does not do (issue ratings, bind insurance, move funds, run your factory); (8) a defined engineering-review path via the DPA + vendor questionnaire. The interactive ROI calculator and the print-friendly economic framework quantify per-archetype return. Request the DPA and vendor questionnaire from daniel@callistobridge.com.
Full technical detail is documented in the sections below. Highlights for reviewer speed: record schema is published CC0 with three sample records; every attribute has a documented source (factory sensors, third-party inspection, materials cert QR codes, notarized attestation). KeyScore is a deterministic function reproducible by any party with the record; the formula is public. Signature is ECDSA over canonical serialization at insert; every lifecycle event appends hash(event, prev_hash). Integration is authenticated REST with per-partner API keys and capability scopes (ingest / read-per-asset / read-index / event-subscribe are separately scoped). Downstream engine outputs reference the specific asset record and KeyScore inputs used, making reconstruction deterministic. Regulatory posture: Keystone does not issue credit ratings, bind insurance, hold or move customer funds, or run the factory (see section 7 below). Compliance path: DPA, vendor questionnaire, and SOC 2 roadmap available on request from daniel@callistobridge.com. Six-week design-partner pilot is the fastest path to end-to-end integration validation on your data.
1. Data model
The Keystone record is a signed, hashed, per-asset passport. Every physical asset ingested into the registry receives one record. Every lifecycle event on that asset (built, inspected, certified, installed, in-service, retired) appends an immutable event to the record. Downstream engines never read raw source data; they read the record.
The record schema is published under CC0 at callistobridge.com/datasets/. Every attribute has a documented source (factory sensors, third-party inspection systems, materials certification QR codes, notarized attestation from a licensed party). No self-reported values.
The KeyScore is a deterministic function of verifiable attributes. Two identical assets get identical scores. Any party with the record can reproduce the score from the inputs. The formula is public, not proprietary. Downstream engines (Capital Rail pool grading, Insurance Rail pricing, Disbursement Rail release gating, Modular Index aggregation) all read the same score.
2. Five downstream engines
Each engine is an independent API-first service that reads the per-asset record. Every engine can be adopted or ignored independently. Every engine has its own commercial contract; a manufacturer that only wants Registry pays Registry; an HFA that only wants Disbursement Rail pays Disbursement Rail. See pricing.
- Module Registry. Per-asset passport + KeyScore. The source of truth every other engine reads. Unregulated SaaS.
- Capital Rail. Pool-grade pre-screen (AAA → NR indicative). NRSRO partners issue the official rating. SEC-registered broker-dealers handle placement.
- Disbursement Rail. Verified-release gate over existing government payment rails (federal, state, Treasury). Keystone signs the release-authorization; existing rails move funds. Not a money transmitter.
- Insurance Rail. Resilience-priced pricing engine licensed to state-licensed MGAs and specialty carriers. MGA partner binds on carrier paper. Not an MGA.
- Modular Index. Live industry benchmark aggregated from the registry. Licensable like CoStar or Verisk.
3. Integration surfaces
Every integration point is an authenticated REST API with signed request payloads and per-partner API keys. Webhook-driven change notifications are available for every downstream engine.
| Surface | Direction | Payload |
|---|---|---|
| Ingest API | Inbound (from your factory or program) | Per-asset attributes; batch or per-event |
| Event stream | Inbound / Outbound | Lifecycle state changes on any registered asset |
| Per-asset API | Outbound (to downstream engine or partner) | Full signed record + KeyScore for a specific asset ID |
| Index API | Outbound (to Modular Index licensees) | Aggregated benchmark queries; Std / Pro / Ent tiers |
| Webhook subscriptions | Outbound | Notification of asset registration, state change, or engine output |
4. Signature and audit primitives
- Every asset record is signed with ECDSA over the canonical serialization at insert.
- Every lifecycle event appends a hash chain:
hash(event, prev_hash). Any auditor can detect insertion, deletion, or reordering. - Every downstream engine output (pool grade, disbursement authorization, insurance quote) references the specific asset record and KeyScore inputs used. Reconstruction is deterministic.
- Immutable event log per tenant. Any Inspector General, program auditor, or partner rater can query historical state directly.
5. Tenant isolation
- Row-level tenant boundaries in the underlying database. Cross-tenant reads require explicit sharing configuration, per policy.
- Per-partner API keys with capability scopes. Ingest, read-per-asset, read-index, event-subscribe are separately scoped.
- Audit trail on every cross-tenant sharing action.
6. Deployment posture
- Managed SaaS on a hardened cloud infrastructure. No on-prem deployment required for the launch tier.
- Per-region data residency available on the Enterprise tier.
- Uptime posture and RTO / RPO commitments are documented in the partner Data Processing Addendum. Available on request; see security.
7. What Keystone does not do
- Does not issue credit ratings. NRSRO partners issue ratings from the record.
- Does not bind insurance. Licensed MGA partners bind on carrier paper from the pricing engine output.
- Does not hold or move customer funds. Existing federal / state / Treasury / fiscal-agent rails move funds gated on the verified-release signal.
- Does not run the factory. Your MES, ERP, project-management, or QA systems continue to run the factory; Keystone reads their outputs.
8. Next steps
Engineering / security review: request the Data Processing Addendum + vendor questionnaire from daniel@callistobridge.com.
Data + integration walkthrough: apply to the six-week design-partner pilot and bring 25 to 100 anonymized records.