Architecture

Five planes, one contract each.

The separation between planes is the architecture, not a diagram drawn after the fact. Each plane owns a single concern, exposes a contract to the estate, and can fail without taking the others with it.

Plane 01 of 05

Substrate

Compute, runtime and tenancy

The execution foundation every AXIS business deploys onto. One runtime contract, one deployment shape, one set of guarantees — so a service written for one business runs unchanged for another.

Owns

  1. A single runtime and deployment contract across the estate
  2. Tenancy boundaries that isolate each business's workloads
  3. Environment parity between development, staging and production
  4. Capacity and cost accounting attributed per business

Plane 02 of 05

Data Plane

Storage, movement and lineage

Where the estate's data physically lives and how it moves. Every dataset has a declared owner, a declared retention posture and a traceable path from origin to consumer.

Owns

  1. Durable primary storage with declared ownership per dataset
  2. Ingestion and replication between AXIS businesses
  3. Lineage — every derived dataset traceable to its source
  4. Retention and deletion enforced by the platform, not by convention

Plane 03 of 05

Intelligence Plane

Models, inference and evaluation

The model and inference substrate the AXIS intelligence products are built on. Models are versioned artefacts with recorded inputs and measured behaviour, not opaque endpoints.

Owns

  1. Versioned model artefacts with recorded provenance
  2. Shared inference serving with per-caller quotas and attribution
  3. Evaluation harnesses run before a model reaches production
  4. Recorded inference history for review and incident reconstruction

Plane 04 of 05

Control Plane

Identity, authorization and audit

Who may act, on what, and what record that leaves. Access is denied by default and every privileged action is written to durable audit before it is considered complete.

Owns

  1. Deny-by-default identity and session verification
  2. Per-resource authorization, separate from authentication
  3. Secret custody with rotation and revocation
  4. Durable audit — if the record cannot be written, the action is refused

Plane 05 of 05

Edge Plane

Delivery, routing and assurance

How the estate reaches the public internet. Routing, transport security, caching policy and the verification that runs before any release is allowed to serve traffic.

Owns

  1. Global delivery and canonical routing per business domain
  2. Transport security and header policy applied at the edge
  3. Caching policy declared per surface rather than inherited by accident
  4. Release verification that must pass before promotion

Next

What each plane offers the estate.

The planes describe ownership. The capabilities describe what an AXIS business actually consumes.

Principles

Next route 02CapabilitiesThe infrastructure services offered to the AXIS estate.