Qavirio Software · Systems · Digital solutions
TECHNICAL REFERENCE

Architecture & Engineering

Technical answers for CIO/CTO, CISO, IT operations, procurement and technical reviewers. We publish enough to assess architecture, engineering discipline and security boundaries — without publishing credentials, internal endpoints, data schemas or hardening detail that would materially simplify abuse.

Technology stacks

Web applications

Python · Django · PostgreSQL · HTML/CSS · JavaScript

Server-side business logic, relational data, role-based workflows and hosted deployments.

Qavirio NERVE

C# · .NET · WPF · SQLite

Windows x64 desktop product with local evidence storage and current read-only source boundaries.

Qavirio QCE

Python · local-first services · local model routes

R&D stack for local cognitive workflows, controlled web intelligence and defensive monitoring.

Web & Digital

PHP · WordPress · WooCommerce · JavaScript

Professional websites, commerce, content and practical web tools when a CMS architecture is appropriate.

Architecture principles

Modular before distributed

Clear domain and module boundaries take priority over microservices for their own sake. Distribution follows only from real scale, integration or isolation requirements.

Server-side authorisation

UI visibility is not a security boundary. Sensitive access is enforced in application logic, queries and service boundaries.

Least privilege

Role, tenant, assignment, context and operational need determine access. Job title alone is insufficient.

Fail closed

Missing secrets, invalid deployment configuration or ambiguous authorisation fail closed where appropriate rather than silently continuing.

Environment separation

Development, controlled demo and production use separate secrets, accounts, datasets and deployment profiles.

Evidence over assumptions

Release claims follow relevant tests and target-runtime validation. A static check is not presented as production acceptance.

Secure development lifecycle
  • Define scope, data categories, roles and negative authorisation scenarios.
  • Use threat and misuse thinking for sensitive workflows.
  • Code/dependency review, secret scanning and package integrity before release.
  • Validate migrations, regression tests, security tests and role matrices together.
  • Safe stop/rollback when an acceptance gate fails.
  • Preserve release evidence: hashes, reports, relevant logs and test results.
Testing & acceptance
  • Unit and domain tests where business rules justify them.
  • Integration and HTTP flows including authentication, CSRF and session behaviour.
  • Positive and negative authorisation matrix per role.
  • Migration drift, schema and data continuity.
  • Browser/responsive sanity checks for critical workflows.
  • Target-runtime readiness before a hosted or enterprise release is called live.
Deployment & operations

HTTPS edge

Public web deployments terminate TLS at a controlled edge/reverse proxy. Application and database services are not directly published without need.

Secrets & configuration

Secrets stay outside source and packages; production configuration is injected and controlled per environment.

Backup & recovery

Backup, retention, restore testing and responsibilities are defined per deployment.

Monitoring & incidents

Health, relevant security events and operational failures should be detectable without unnecessary employee monitoring.

Data, privacy & logging
  • Data minimisation starts with purpose and professional need, not with what can technically be stored.
  • Historical snapshots may remain immutable where evidence, audit or financial traceability requires it.
  • Logs should support security and operations without duplicating sensitive content by default.
  • DPIA, retention periods, processors and hosting location are assessed per real deployment.
Dependencies & software supply chain
  • Dependencies are limited to what is functionally needed and inventoried at release time.
  • SBOM/dependency evidence is provided where product or procurement context requires it.
  • Release packages receive integrity hashes and are checked for unexpected secrets/local credentials.
  • Vulnerability response and update policy are defined per product baseline and distribution model.
Technical FAQ
Does Qavirio use one fixed stack?

No. The stack follows product type, deployment, maintainability and security requirements.

Does Qavirio use external AI?

Not as a generic default. NERVE 1.0 Final has no configured external AI provider. QCE is local-first R&D. Other products may use external services only when explicitly designed and disclosed.

Can NERVE modify source systems?

Current NERVE 1.0 Final connectors are read-only and the baseline contains no active action executor.

Where is Accueil Enfance hosted?

The demo and every real customer deployment are separate environments. Hosting region, processors, backup, retention and SLA are defined for the actual engagement.

Are you ISO 27001 certified?

Not yet. ISO/IEC 27001 is the first formal certification target. The site does not claim certification before independent issuance.

Can you provide a security document or architecture diagram?

Yes, for a concrete evaluation. Publicly we show system level; deployment-specific dataflows, network detail and controls are shared through controlled due diligence.

Available under controlled due diligence
  • Architecture & data-flow overview
  • Role & authorisation matrix
  • Security boundary summary
  • Hosting, subprocessors & data residency
  • Backup, continuity & retention
  • Test & acceptance evidence
  • SBOM/dependency information where applicable
  • Pentest/certification evidence once independently obtained
Not public
  • Credentials, tokens, private keys and production secrets
  • Complete internal endpoint and route inventory
  • Field-level data schemas without review need
  • Exact firewall and hardening recipes
  • Abuse-prevention thresholds or bypass-sensitive logic

Technical question about a deployment?

Use this page as the first technical reference. For customer- or deployment-specific details we provide additional documentation through a controlled process.