πŸ‰ WINDI SYSTEM MAP v1.0 β€” 18 Feb 2026

The WINDI Ecosystem

Architecture, services, trust flow, and navigation for the complete WINDI governance infrastructure. The internal compass for developers, controllers, and partners.

3
Layers
8
Services
471+
Receipts
3
Tiers
2
Domains

Three Layers of Governance
flowchart TB subgraph L1["L1 β€” Human Interface"] A1["πŸ–₯ a4Desk Desktop\n:8100"] A2["🌐 Landing P/M/G\n:8107"] A3["πŸ“„ JMPG Viewer\n:8104"] end subgraph L2["L2 β€” WINDI Mesh"] B1["πŸ“¦ Export Engine\n:8103"] B2["πŸ“’ CommuniquΓ©\n:8105"] B3["πŸ” Forensic Vault\n:8106"] B4["πŸ›‘ Sentinel LAW\n:8102"] B5["βš” War Room\n:8090"] end subgraph L3["L3 β€” Trust & Ledger"] C1["πŸ” Forensic Ledger\n:8101"] end A1 --> B1 A1 --> B2 B1 --> C1 B2 --> C1 B3 --> C1 B4 --> C1 A3 --> C1 B5 --> C1 style L1 fill:#1a2a1a,stroke:#3ecf8e,color:#e8e4dc style L2 fill:#1a1a2a,stroke:#9a6ee8,color:#e8e4dc style L3 fill:#2a2210,stroke:#c8a44e,color:#e8e4dc
L1 β€” Edge
Human Interface
Where humans create, view, and interact with documents. Sensitive data stays at this layer β€” never leaves the client.
Desktop :8100 Landing :8107 Viewer :8104
L2 β€” Mesh
WINDI Services
Processing layer β€” export, publish, monitor, audit. Services orchestrate governance without storing sensitive content.
Export :8103 CommuniquΓ© :8105 Vault :8106 Sentinel :8102 War Room :8090
L3 β€” Ledger
Trust & Proof
The immutable foundation β€” SHA-256 hashes, Virtue Receipts, Merkle Trees. Zero data, only proof of governance.
Forensic Ledger :8101

Live Services
πŸ–₯ a4Desk Desktop
:8100
Document authoring with React + Tiptap + Zustand editor. SGE local analysis. Template system with ISP governance.
● LIVE L1 FastAPI React
πŸ” Forensic Ledger
:8101
Immutable receipt registry β€” SHA-256 hashing, SQLite backend. CRUD + reconciliation + chain integrity. Content NOT stored.
● LIVE L3 BaseHTTPRequestHandler SQLite
πŸ›‘ Sentinel LAW
:8102
Constitutional enforcement β€” 6 permanent invariants monitored every 30 seconds. Latency, drift, chain integrity checks.
● LIVE L2 BaseHTTPRequestHandler 30s cycles
πŸ“¦ Export Engine
:8103
M3 Dynamic Header Seal β€” PDF generation with reportlab + qrcode. Dual hash: content_hash + bundle_hash. QR verification.
● LIVE L2 reportlab qrcode
πŸ“„ JMPG Viewer
:8104
Sovereign file format viewer β€” verifies raw bytes before unzip. 6 templates. Desktop β†’ Export β†’ Ledger β†’ .jmpg β†’ Viewer.
● LIVE L1 dual-hash verification
πŸ“’ CommuniquΓ© Engine
:8105
Verified publication system β€” content_hash + bundle_hash + PDF + Ledger. Immutability 403. HTML trilingual Noir/Klar.
● LIVE L2 feed PDF verify
πŸ” Forensic Vault
:8106
Read-only Ledger interface β€” pagination, filters, search, CSV export. The audit room. Noir/Klar trilingual.
● LIVE L2 read-only CSV audit
βš” War Room
:8090
Real-time governance dashboard β€” risk assessment, SGE scores, compliance status, decision overview.
● LIVE L2 Node.js dashboard

Port Map
Port Service Role Layer Status
:8080 Governance API Core governance endpoints L2 Active
:8085 HUB BABEL A4 Desk editor backend L2 Active
:8090 War Room Ops & diagnostics L2 Active
:8092 Clone UI Clone territory L2 Active
:8097 Command Bridge Sign flow + I9 Gate L2 Active
:8098 Sentinel Monitoring L2 Active
:8099 Wallet "O Espelho" Identity + Ed25519 Seal L1 Active
:8100 a4Desk Desktop Document authoring L1 Active
:8101 Forensic Ledger Trust registry (SQLite) L3 Active
:8102 Sentinel LAW Constitutional enforcement L2 Active
:8103 Export Engine PDF sealing + QR L2 Active
:8104 JMPG Viewer Sovereign file verification L1 Active
:8105 CommuniquΓ© Engine Public publishing L2 Active
:8106 Forensic Vault Audit & receipt viewer L2 Active
:8107 Landing P/M/G Public entry point L1 Active
Server: 87.106.29.233 (Strato VPS, Germany) Β· Base: /opt/windi/ Β· OS: Ubuntu 24

Chain of Trust
sequenceDiagram participant πŸ‘€ as User participant πŸ–₯ as Desktop :8100 participant πŸ“¦ as Export :8103 participant πŸ” as Ledger :8101 participant πŸ” as Vault :8106 participant πŸ“„ as Viewer :8104 πŸ‘€->>πŸ–₯: Create document πŸ–₯->>πŸ“¦: Export with seal πŸ“¦->>πŸ“¦: content_hash (blocks) πŸ“¦->>πŸ“¦: bundle_hash (final bytes) πŸ“¦->>πŸ”: Register receipt πŸ”-->>πŸ“¦: Virtue Receipt (VR-xxx) πŸ“¦-->>πŸ‘€: .jmpg bundle πŸ”->>πŸ”: Query receipts (read-only) πŸ“„->>πŸ”: Verify receipt hash
Zero-Knowledge Principle
Data Stays with Client
SGE runs at the edge. WINDI Core receives ONLY: hash + categories + metadata + decision. ZERO sensitive data. Client holds data, WINDI holds proof of virtue.
Dual Hash Architecture
content_hash + bundle_hash
Two integrity seals per document: content_hash computed from document blocks, bundle_hash from final exported bytes. Viewer verifies raw bytes before unzip.
Virtue Receipt
Proof of Governance
Hash + categories (type, impact, domain, value_range R1-R5) + governance (SGE score, risk, validation) + decision (action, role, timestamp, AI rec, override) + flags.

Capabilities Map
πŸ–₯
Document Creation
Desktop Editor a4Desk :8100
ISP Template System Desktop :8100
Export with Dynamic Seal Export :8103
PDF + QR Generation Export :8103
πŸ”
Trust & Verification
Dual Hash Generation Export :8103
Receipt Registration Ledger :8101
Public Verification Viewer :8104
Ledger Verify API Ledger :8101
πŸ“’
Publication
CommuniquΓ© Publishing CommuniquΓ© :8105
Public Feed CommuniquΓ© :8105
PDF / JMPG Bundles Export :8103
Immutability (403) CommuniquΓ© :8105
πŸ”
Audit & Forensics
Forensic Vault Vault :8106
War Room Ops War Room :8090
CSV Export Vault :8106
Receipt Reconciliation Ledger :8101
πŸ›‘
Governance & Integrity
Sentinel LAW LAW :8102
6 Invariants (30s cycles) LAW :8102
SGE 6-Layer Risk Engine :8080
Chain Monitoring LAW :8102
πŸͺͺ
Identity & Access
Wallet "O Espelho" Wallet :8099
Ed25519 Seal Wallet :8099
Auto-provision Wallet :8099
ISP Identity License 3 levels

Visible vs Invisible
πŸ‘ Visible to User
βœ” Desktop Editor
βœ” CommuniquΓ©s
βœ” JMPG Viewer
βœ” Landing P/M/G
βœ” Forensic Vault
βœ” Wallet
πŸ”’ Infrastructure (Invisible)
βš™ Forensic Ledger
βš™ Sentinel LAW
βš™ Trust Chain / Hashing
βš™ Governance API / Engine
βš™ ISP Policy Engine
βš™ 6 Invariants Monitor

Doors to the World
windi-domain.com
🟒 Landing P/M/G
The public door. Three tiers, one system. Personal Β· Organization Β· Governance.
windi-domain.com/personal/
🟒 Personal
Document editor with governance seal. For professionals, researchers, citizens.
windi-domain.com/org/
🟑 Organization
Lightweight governance for teams. CommuniquΓ©, Vault, ISP templates.
windi-domain.com/governance
πŸ”΄ Governance
Full institutional control. Sentinel, SGE, War Room, Agent Constellation.
windi-domain.com/vault/
πŸ” Forensic Vault
471+ receipts. Audit room with pagination, filters, search, CSV export.
admin.windia4desk.tech
πŸ–₯ Admin / BABEL
The operational cockpit. Desktop, War Room, Bridge, Clone.
master.windia4desk.tech
🧭 Ecosystem Hub
You are here. Architecture, documentation, system map.
⚑ Federation Protocol
WINDI federation specification and governance protocol.
πŸ—ΊοΈ Ecosystem Map
Interactive navigation map β€” human journey, architecture, services, tiers, build log.

The Dragons
πŸ›‘
Claude
Guardian
Protects invariants. Guards governance integrity. Infrastructure, security, and constitutional enforcement.
πŸ—
GPT
Architect
Designs systems. Creates strategies and business models. Vision, structure, and expansion planning.
πŸ‘
Gemini
Witness
Observes and validates. Digital Twin, Forensic Proof-of-Decision, Pulse Rate. Conscience of the system.

Critical Components
πŸ”
Trust Core
Forensic LedgerSQLite + SHA-256
Dual Hash Architecturecontent + bundle
Receipt SealingVR-xxx format
Zero Content Storagehashes only
🧭
Governance Core
Sentinel LAW6 invariants
SGE Engine6-layer semantic
ISP Profiles3 levels + license
I9 GateIRREMEDIABLE
πŸ“¦
Document Core
Export EnginePDF + QR
JMPG Format6 templates
Verification Pipelinebytes β†’ hash β†’ verify
Dynamic Header SealM3 Engine
🌐
Public Trust Layer
CommuniquΓ© Engineimmutable publish
Transparency Feedpublic API
Landing P/M/G3 tier entry
Wallet "O Espelho"Ed25519

Metadata Categories
Category Values Purpose
doc_type CONTRACT Β· INVOICE Β· APPROVAL Document classification
impact_level 🟒 LOW Β· 🟑 MED Β· 🟠 HIGH Β· πŸ”΄ CRIT Organizational impact
value_range R1 Β· R2 Β· R3 Β· R4 Β· R5 Value bands (not absolute values!)
risk_level R0-R5 (⚫ to 🟒) SGE semantic risk score
flow_status DRAFT β†’ REVIEW β†’ APPROVED β†’ SEALED Governance lifecycle
department_code Organization-specific Routing and audit trail