Docs · 10
Architecture
Three layers, who sees what, and the stack that runs it.
Three layers#
| Layer | Does | Sees |
|---|---|---|
| Your device | Encrypts and decrypts, signs the login and the payment | Plaintext, the content key, your private key |
| EVERYNTH | Stores ciphertext and wrapped keys, freezes orders, verifies transactions, releases keys, invites on GitHub | Ciphertext, wrapped keys, orders, sessions |
| Solana | Moves SOL between wallets, confirms in seconds | Addresses, amounts, reference keys |
The stack#
- Next.js 16 (App Router) for pages and route handlers, deployed on Vercel.
- Web Crypto in the browser for AES-GCM; Node
cryptoon the server for key wrapping, HMAC sessions and ed25519 verification. - @solana/web3.js and the wallet adapter for signing and sending; no custom program.
- Neon Postgres for products, purchases, reports and blocks (embedded PGlite locally, same SQL).
- Vercel Blob for file ciphertext, uploaded directly from the browser.
- GitHub REST for repository invitations.
It is short on purpose. Every component that is not there is one that cannot be compromised.
Data model#
products id, creator, title, description, category, price (lamports), kind,
file_name, file_type, payload (secret ciphertext) | payload_url (blob),
github_repo, wrapped_key, cover, cover_type, status live|removed
purchases id, product_id, buyer, reference (unique), creator, creator_amount,
treasury, fee, signature (unique), status pending|paid, github_user
reports product_id, reporter, reason (unique per product+reporter)
blocked_wallets wallet, reasonPayout terms are copied onto the purchase at order time, so later edits to the product cannot change what an open order settles at.
Trust summary#
- Money: never held by EVERYNTH. Trust the chain.
- Goods: encrypted before upload; EVERYNTH can unwrap keys in v1 (why). Trust the operators for that, nobody else.
- Identity: your wallet. No accounts, no passwords, nothing to leak.