Skip to content

Architecture

How the four modules fit together, where they run, where data sits in each topology, and how a deployed instance is configured and versioned.

1.0Modules

How the modules fit together

Conduit resolves incoming documents into typed records. Signal analyses them, routing what it cannot settle to a review queue where a reviewer decides. Trace retrieves and ranks across the checked records. Gauge sits underneath the other three as the measurement plane: it is the module responsible for scoring a proposed change against a fixed set of cases, and it never touches a production input.

Scroll the diagram sideways

imagesdocumentsmetadataMIXED SUBMISSIONSIngestConduitAnalyseSignaltyped recordsReview queuea reviewer decidescannot settledecision, recordedRetrieveTracechecked recordsEvaluateGaugefixed corpus, one scoring methodmeasures
Figure 1. The pipeline and its measurement plane. Gauge measures the other modules rather than running inside the flow. The dashed review queue represents the human-review step in Signal.
2.0Topologies

Deployment topologies

The preferred deployment runs every module inside the client environment. A hosted deployment exists as a negotiated exception, with its terms fixed in the agreement before any data moves.

Scroll the diagram sideways

YOUR ENVIRONMENTQuantscopeholds no client dataCHANGECONTROLSOFTWARE RELEASESModulesCDTSGLTRCGAUYour storageyour keysYour identity provideryour access modelCLIENT DATA NEVER LEAVES
Figure 2. The client-environment topology. A software release is the only thing that crosses the boundary, and it enters through your change control.
Where data sits in each deployment topology
TopologyWhere the modules runWho holds the dataWhat crosses the boundary
Client environmentInside your environment, against your storage, under your identity providerYou. Quantscope holds no client data and no encryption keyNothing inbound. Software releases enter through your change control
Hosted (negotiated exception)In an environment operated for the engagementDefined in the agreement: region, retention and deletion are set before any data movesDocuments in, structured records and findings out, as the data processing agreement defines
3.0Versioning

Configuration and versioning

Configuration
Connection and cadence settings are configuration, bundled with the code rather than modifiable at runtime. Source types, field maps and checks are defined in code.
Release record
What a release is required to name: the module versions it contains, and the evaluation scores that cleared it. See the module pages for what each module records today.
Change control
Changes enter a deployed instance through the agreed change control process, with re-evaluation triggered by the thresholds agreed upfront.
Separation of instances
A production instance is separated from development. Nothing reaches it except through a release.