Resources · Architecture

Enterprise architecture,
built to be trusted.

A modular, API-first platform with a governed AI control plane at its core. Designed for the architects and security teams who have to sign off on it.

Reference architecture

Every request passes through
one governed core.

Applications never call a model, OCR engine, vector store or agent directly. They call the platform; the AI Service Bus governs, routes, runs and records every step.

Clients

Web & MobileV-Workspaces · E-Services
15 Capabilitiesacross five families
External systems/api/v1 integrations

Edge & access

API Gatewayversioned · rate-limited
IdentitySSO · OIDC · SAML · RBAC

Governed AI control plane

AI Service Busrouting · policy · prompt orchestration · metering

Capabilities

Modelscloud · on-prem
KnowledgeRAG · graph
OCRdoc intelligence
Agentsgoverned
Governanceguardrails

Data & observability

Data FabricPostgreSQL
Vector & SearchQdrant · Elasticsearch
Object StorageS3-compatible
Audit Ledgeraudit log

Request lifecycle

One request.
One governed path.

Every AI request is routed, grounded, reasoned, checked and recorded the same way, every time.

Architectural pillars

Six pillars, one platform.

AI Service Bus

One governed entry point for every model, document and decision: routing, prompt orchestration, metering and security.

Identity & Access

SSO via OIDC/SAML, SCIM provisioning, role-based access and per-capability authorization.

Knowledge

Hybrid search, RAG grounding and a connected knowledge graph. Answers tied back to their sources.

Governance

Policy enforced on input and output: prompt-injection screening, PII detection & redaction, clearance checks.

Integration & APIs

A clean, versioned REST API for every capability, with webhooks and standard integration options.

Observability & Audit

Traces and an audit ledger record every significant event.

Defense in depth

Security at every layer.

Zero-Trust Access: authenticate & authorize every call Encryption: in transit and at rest Managed Secrets: rotation & key management PII Detection & Redaction: before models see text Tenant Isolation: row-level security & ABAC SSRF & Input Guards: hardened ingress Audit Human-in-the-Loop: approval gates

Scale & resilience

Built to run at
scale.

Horizontal Scale

Stateless services scale out behind the gateway; heavy work runs on asynchronous task queues.

High Availability

Redundant services, health probes and graceful degradation keep the platform serving under load.

Performance

Caching, connection pooling and vector indexing keep retrieval and inference responsive.

Multi-Tenancy

Isolated tenants with independent policies, quotas and data: one platform, many entities.

Backup & DR

Scheduled backups, retention and restore paths for data, configuration and the audit ledger.

Modular by Design

Adopt one capability or all of them. Every module is independently deployable and upgradable.

Open & integrable

An API-first platform.

Every capability is exposed under one versioned REST API, and the platform speaks the standards your stack already uses.

/api/v1 RESTOpenAPIWebhooksOAuth 2.0 / OIDCSAML 2.0SCIMDirectory servicesCalendar & collaborationS3-compatible storageKubernetes

Supported technologies

Built on, and integrates with,
your stack.

AICP runs on a modern, open foundation and connects to the AI providers, data stores and enterprise systems you already use.

All trademarks and logos are the property of their respective owners and are used solely to indicate supported integrations.

Reviewing VEEVRA for
a critical workload?

We’ll walk your architects through the reference architecture, security model and deployment topology in detail.