NERVE is live across local, private and approved-cloud deployments. Book an evaluation
Architecture
Durable information. Rebuildable discovery. Stable interfaces.
The NERVE reference architecture separates heavy processing from administration, and keeps exact evidence independent of search-engine internals.
Running in production deployments
Reference architecture
Six layers, read from the source inwards.
Read it top to bottom. Information enters on the left of each band and leaves through the service boundary at the end.
01
Approved sources
Files and archives
Documents and office content
Messages and email
Enterprise repositories
Databases and exports
APIs and feeds
Streams and sensors
Device and forensic packages
Historical holdings
Geospatial and media
Acquisition adapters sit at the edge. Each adapter accepts only what the approved source actually offers, and records how it was obtained.
02
Control plane
Source administration
Dataset administration
Policy
Schemas
Jobs
Service APIs
Administration is separated from processing, so a busy pipeline never slows down policy, schema or job management.
03
Data plane
Bounded acquisition
Scan
Decode
Parse
Normalise
Enrich
Index
Export
Workers are bounded and isolated. A hostile or malformed object fails inside its own worker without taking the pipeline with it.
04
Durable roles
Originals
Canonical records
Derived artefacts
Operational metadata and audit
Persistent queue
Five distinct durable roles. Each has its own retention, its own access rules and its own provenance.
05
Rebuildable discovery
Full-text index
Structured index
Time index
Geospatial index
Policy-approved vector index
Indexes are projections. Each one can be rebuilt from the canonical records without touching a single original byte.
06
Consumers
NERVE Operations
NERVE Explorer
CORTEX
Approved API consumers
Governed exports
Consumers arrive through the service boundary. Nothing reads a store directly, so authority is evaluated in one place.
The important split
What is retained, and what is rebuilt.
This one distinction drives the whole design. Evidence lives in the retained side. Everything that makes it findable lives in the rebuildable side.
Retained and authoritative
These are the system of record. They are never regenerated and never silently rewritten.
Originals: the exact accepted bytes, with acquisition context and cryptographic identity
Canonical records: the immutable common envelope, typed content and source extensions
Derived artefacts: OCR, transcripts, translations, thumbnails and identifier sets, each with its own provenance
Operational metadata and audit: who asked, what was authorised and what happened
Persistent queue: durable work intent that survives restarts
Rebuildable projections
These exist only to make retained information findable. Delete one and rebuild it; nothing authoritative is lost.
Full-text index: language-aware search across textual content
Structured index: fields, types and exact-match lookups
Time index: source, event, acquisition and processing times held apart
Geospatial index: location observations with their recorded accuracy
Policy-approved vector index: concept retrieval where policy allows it
The common envelope
Every canonical record carries the same fourteen things.
The envelope is the same whatever the source was. That is what lets a single query reach across families, and a single citation survive reprocessing.
Stable object identity
One identifier that never changes, whatever happens downstream.
Organisation, dataset, source, acquisition
Where this record belongs and which run produced it.
Original reference
A pointer back to the exact accepted bytes.
Object type and schema version
Which canonical family this is, and which version of the model it follows.
Source identity
How the source itself identified the thing, in the source’s own terms.
Source, event, acquisition and processing times
Four distinct times, held apart rather than collapsed into one.
Handling
The handling rules that travel with the record.
Privacy
Privacy characteristics recorded against the record, not assumed.
Authority and purpose
The authority the acquisition relied on, and the purpose it was acquired for.
Provenance
What produced this record, from what, using which version.
Typed content
The content itself, typed to the canonical family.
Namespaced extensions
Source-specific detail kept intact, under its own namespace.
Quality
What is known about completeness and confidence.
Publication state
Whether the record is discoverable, and under what conditions.
Canonical families
Fourteen families, in plain English.
A source is mapped to the family that genuinely fits. Where none does, GenericRecord keeps the structure faithfully rather than inventing a specialised mapping.
Document
A written artefact: a report, letter, note or office file.
Message
A single message sent from one party to one or more others.
Conversation
A thread or channel that groups related messages together.
CallRecord
A record that a call happened, and between which parties.
ContactRecord
An entry describing a person or organisation as the source held it.
AccountRecord
An account or identity as a system held it.
DeviceRecord
A device as described by whichever source reported it.
FileRecord
A file as it existed in a file system or container.
MediaRecord
An image, audio or video item with its technical description.
LocationObservation
A recorded observation of a location at a particular time.
Transaction
A financial or system transaction with parties and amounts.
CalendarEvent
A scheduled event with its times and participants.
NetworkObservation
An observed network connection, session or request.
GenericRecord
A faithful structured fallback for anything that does not fit a specialised family.
Interchange and exports
Three formats, each with a job.
Versioned JSON
Application interchange uses versioned JSON. The version is explicit, so a consumer always knows which semantics it is reading.
JSON Lines
Governed exports stream as JSON Lines wherever record-at-a-time processing is the right shape for the consumer.
Parquet
Columnar export for analytical work at volume. Parquet is an export format, not a replacement for the original file formats.
Schema changes are explicit
Breaking the semantics of a field requires a declared compatibility and migration path. The meaning of a field is never changed in place.
Query meanings stay stable
A query written against a supported version keeps returning what it meant when it was written.
Service contracts
The service boundary, route by route.
This page is contract documentation, not a live endpoint explorer. Nothing here is called from the website, and no credentials or engine syntax appear in it.
POST
/api/nerve/v1/sources
POST
/api/nerve/v1/datasets
POST
/api/nerve/v1/ingest/jobs
PUT
/api/nerve/v1/ingest/jobs/{jobId}/content
GET
/api/nerve/v1/ingest/jobs/{jobId}
POST
/api/nerve/v1/ingest/jobs/{jobId}/cancel
POST
/api/nerve/v1/search
GET
/api/nerve/v1/objects/{objectId}
GET
/api/nerve/v1/objects/{objectId}/lineage
GET
/api/nerve/v1/originals/{originalId}/content
POST
/api/nerve/v1/evidence/resolve
POST
/api/nerve/v1/exports
POST
/api/nerve/v1/connectors/{connectorId}/events
GET
/api/nerve/v1/schemas
GET
/health/live
GET
/health/ready
How access is evaluated
Six rules the boundary applies to every call.
Authentication
Every call is authenticated. There is no anonymous path to canonical records, originals or derived artefacts.
Organisation authority
Authority is scoped to the organisation the caller belongs to. Cross-organisation reach is not implicit.
Delegated human context
Where a machine acts for a person, the person is carried in the request, so audit records who actually asked.
Bounded cursors
Result traversal is bounded and cursor-based. A caller cannot walk the whole holding by paging indefinitely.
Safe errors
Errors say what went wrong without revealing the existence, shape or content of material the caller may not see.
Versioned evidence references
Evidence references carry their version, so a citation resolves to the same thing after reprocessing.
Administration is not content access
Broad administrative permission does not automatically grant access to protected content. Someone who can configure a source is not thereby entitled to read what it acquired.
Next
See the architecture against your own chain.
The quickest way to judge a reference architecture is to run one real source through it and then try to explain the result.