Components

P

Cloudflare Pages

Static React dashboard plus a same-origin /api proxy. It holds no Cloudflare token, and browser credentials stay on the adopter’s Pages origin.

W

Worker + D1

Authorization, validation, scrypt auth, AES-GCM integration secrets, audit trails, attendance, exports, and provider calls.

π

Raspberry Pi + R503

LAN-limited first pairing, loopback-only operational tools, serial sensor I/O, local mappings, atomic offline queue, protected networking/maintenance, and hashed bearer pairing.

Security invariants

Verification and source reference

CI runs workspace typechecks, Node unit tests, Worker runtime tests, production builds, dependency auditing, and sanitizer checks. Read docs/ARCHITECTURE.md, docs/SECURITY.md, and docs/BACKUP-RESTORE.md in the repository for durable technical detail.