A
AYONIX
ZOOMER

Infrastructure and Dependency Management Policy

Version 1.0 · Effective 25 September 2026 · Owner: Ayonix engineering · Reviewed annually

1. Architecture

ComponentPlatformPurpose
Application and APICloudflare WorkersServerless request handling. No customer-managed servers, no SSH, no operating system to patch.
DatabaseCloudflare D1 (APAC)Trainees, sessions, events, audit log.
Object storageCloudflare R2 (APAC)Encrypted evidence images and generated reports.
Realtime coordinationCloudflare Durable ObjectsLive dashboard state fan-out.
Edge securityCloudflareTLS termination, DDoS protection, WAF, CDN.
Face analysisOn-device, or a dedicated GPU hostInference. Deliberately kept off the serverless tier.

A serverless platform removes a large class of infrastructure risk — no unpatched operating systems, no exposed management ports, no long-lived instances to drift. It concentrates the remaining risk in configuration and dependencies, which is what the rest of this policy addresses.

2. Configuration management

3. Dependency management

4. Data residency and retention

5. Availability and recovery

6. Monitoring

7. Sub-processors

Cloudflare, Inc. (hosting, storage, edge security) and — where a customer connects it — Zoom Communications, Inc. Sub-processor changes are notified to customers before they take effect. Current detail is in the Privacy Policy.

8. Review

Reviewed annually and whenever the architecture materially changes.