NERVE is live across local, private and approved-cloud deployments. Book an evaluation

Architecture

Durable information. Rebuildable discovery. Stable interfaces.

The NERVE reference architecture separates heavy processing from administration, and keeps exact evidence independent of search-engine internals.

Running in production deployments

Reference architecture

Six layers, read from the source inwards.

Read it top to bottom. Information enters on the left of each band and leaves through the service boundary at the end.

01

Approved sources

Files and archives

Documents and office content

Messages and email

Enterprise repositories

Databases and exports

APIs and feeds

Streams and sensors

Device and forensic packages

Historical holdings

Geospatial and media

Acquisition adapters sit at the edge. Each adapter accepts only what the approved source actually offers, and records how it was obtained.

02

Control plane

Source administration

Dataset administration

Policy

Schemas

Jobs

Service APIs

Administration is separated from processing, so a busy pipeline never slows down policy, schema or job management.

03

Data plane

Bounded acquisition

Scan

Decode

Parse

Normalise

Enrich

Index

Export

Workers are bounded and isolated. A hostile or malformed object fails inside its own worker without taking the pipeline with it.

04

Durable roles

Originals

Canonical records

Derived artefacts

Operational metadata and audit

Persistent queue

Five distinct durable roles. Each has its own retention, its own access rules and its own provenance.

05

Rebuildable discovery

Full-text index

Structured index

Time index

Geospatial index

Policy-approved vector index

Indexes are projections. Each one can be rebuilt from the canonical records without touching a single original byte.

06

Consumers

NERVE Operations

NERVE Explorer

CORTEX

Approved API consumers

Governed exports

Consumers arrive through the service boundary. Nothing reads a store directly, so authority is evaluated in one place.

The important split

What is retained, and what is rebuilt.

This one distinction drives the whole design. Evidence lives in the retained side. Everything that makes it findable lives in the rebuildable side.

Retained and authoritative

These are the system of record. They are never regenerated and never silently rewritten.

Originals: the exact accepted bytes, with acquisition context and cryptographic identity

Canonical records: the immutable common envelope, typed content and source extensions

Derived artefacts: OCR, transcripts, translations, thumbnails and identifier sets, each with its own provenance

Operational metadata and audit: who asked, what was authorised and what happened

Persistent queue: durable work intent that survives restarts

Rebuildable projections

These exist only to make retained information findable. Delete one and rebuild it; nothing authoritative is lost.

Full-text index: language-aware search across textual content

Structured index: fields, types and exact-match lookups

Time index: source, event, acquisition and processing times held apart

Geospatial index: location observations with their recorded accuracy

Policy-approved vector index: concept retrieval where policy allows it

The common envelope

Every canonical record carries the same fourteen things.

The envelope is the same whatever the source was. That is what lets a single query reach across families, and a single citation survive reprocessing.

Stable object identity

One identifier that never changes, whatever happens downstream.

Organisation, dataset, source, acquisition

Where this record belongs and which run produced it.

Original reference

A pointer back to the exact accepted bytes.

Object type and schema version

Which canonical family this is, and which version of the model it follows.

Source identity

How the source itself identified the thing, in the source’s own terms.

Source, event, acquisition and processing times

Four distinct times, held apart rather than collapsed into one.

Handling

The handling rules that travel with the record.

Privacy

Privacy characteristics recorded against the record, not assumed.

Authority and purpose

The authority the acquisition relied on, and the purpose it was acquired for.

Provenance

What produced this record, from what, using which version.

Typed content

The content itself, typed to the canonical family.

Namespaced extensions

Source-specific detail kept intact, under its own namespace.

Quality

What is known about completeness and confidence.

Publication state

Whether the record is discoverable, and under what conditions.

Canonical families

Fourteen families, in plain English.

A source is mapped to the family that genuinely fits. Where none does, GenericRecord keeps the structure faithfully rather than inventing a specialised mapping.

Family

What it means

Document

A written artefact: a report, letter, note or office file.

Message

A single message sent from one party to one or more others.

Conversation

A thread or channel that groups related messages together.

CallRecord

A record that a call happened, and between which parties.

ContactRecord

An entry describing a person or organisation as the source held it.

AccountRecord

An account or identity as a system held it.

DeviceRecord

A device as described by whichever source reported it.

FileRecord

A file as it existed in a file system or container.

MediaRecord

An image, audio or video item with its technical description.

LocationObservation

A recorded observation of a location at a particular time.

Transaction

A financial or system transaction with parties and amounts.

CalendarEvent

A scheduled event with its times and participants.

NetworkObservation

An observed network connection, session or request.

GenericRecord

A faithful structured fallback for anything that does not fit a specialised family.

Interchange and exports

Three formats, each with a job.

Versioned JSON

Application interchange uses versioned JSON. The version is explicit, so a consumer always knows which semantics it is reading.

JSON Lines

Governed exports stream as JSON Lines wherever record-at-a-time processing is the right shape for the consumer.

Parquet

Columnar export for analytical work at volume. Parquet is an export format, not a replacement for the original file formats.

Schema changes are explicit

Breaking the semantics of a field requires a declared compatibility and migration path. The meaning of a field is never changed in place.

Query meanings stay stable

A query written against a supported version keeps returning what it meant when it was written.

Service contracts

The service boundary, route by route.

This page is contract documentation, not a live endpoint explorer. Nothing here is called from the website, and no credentials or engine syntax appear in it.

POST

/api/nerve/v1/sources

Define an approved logical source.

Define an approved logical source.

POST

/api/nerve/v1/datasets

Create a governed grouping.

Create a governed grouping.

POST

/api/nerve/v1/ingest/jobs

Create durable acquisition intent, or an upload slot.

Create durable acquisition intent, or an upload slot.

PUT

/api/nerve/v1/ingest/jobs/{jobId}/content

Stream bytes for original acceptance.

Stream bytes for original acceptance.

GET

/api/nerve/v1/ingest/jobs/{jobId}

Inspect explicit progress and outcomes.

Inspect explicit progress and outcomes.

POST

/api/nerve/v1/ingest/jobs/{jobId}/cancel

Stop eligible future work while retained originals stay under policy.

Stop eligible future work while retained originals stay under policy.

POST

/api/nerve/v1/search

Query currently authorised canonical and derived information.

Query currently authorised canonical and derived information.

GET

/api/nerve/v1/objects/{objectId}

Retrieve an exact record.

Retrieve an exact record.

GET

/api/nerve/v1/objects/{objectId}/lineage

Traverse bounded, independently authorised provenance.

Traverse bounded, independently authorised provenance.

GET

/api/nerve/v1/originals/{originalId}/content

Stream exact retained bytes under permission and reason policy.

Stream exact retained bytes under permission and reason policy.

POST

/api/nerve/v1/evidence/resolve

Resolve a stable opaque citation to exact authorised content and locator.

Resolve a stable opaque citation to exact authorised content and locator.

POST

/api/nerve/v1/exports

Prepare a governed package with provenance.

Prepare a governed package with provenance.

POST

/api/nerve/v1/connectors/{connectorId}/events

Accept authenticated source events under replay policy.

Accept authenticated source events under replay policy.

GET

/api/nerve/v1/schemas

Discover supported model semantics.

Discover supported model semantics.

GET

/health/live

Confirm the process is responding.

Confirm the process is responding.

GET

/health/ready

Confirm safe readiness for the declared role.

Confirm safe readiness for the declared role.

How access is evaluated

Six rules the boundary applies to every call.

Authentication

Every call is authenticated. There is no anonymous path to canonical records, originals or derived artefacts.

Organisation authority

Authority is scoped to the organisation the caller belongs to. Cross-organisation reach is not implicit.

Delegated human context

Where a machine acts for a person, the person is carried in the request, so audit records who actually asked.

Bounded cursors

Result traversal is bounded and cursor-based. A caller cannot walk the whole holding by paging indefinitely.

Safe errors

Errors say what went wrong without revealing the existence, shape or content of material the caller may not see.

Versioned evidence references

Evidence references carry their version, so a citation resolves to the same thing after reprocessing.

Administration is not content access

Broad administrative permission does not automatically grant access to protected content. Someone who can configure a source is not thereby entitled to read what it acquired.

Next

See the architecture against your own chain.

The quickest way to judge a reference architecture is to run one real source through it and then try to explain the result.