Platform Architecture
State of Stick separates physical production, connected identity, customer experiences, authoritative business workflows, measurement, AI assistance, and security so each can evolve within its own responsibility boundary.
| Layer | Public responsibility |
|---|---|
| Physical layer | The emblem, display, package element, collectible, or installation |
| Connected identity layer | The managed reference that associates an approved object with an experience |
| Experience layer | Customer-facing content, stories, instructions, offers, or workflows |
| Workflow layer | Server-authoritative claim, registration, payment, fulfillment, signing, service, or ownership state |
| Analytics layer | Policy-scoped measurement of intentional interactions and outcomes |
| AI layer | Registered, source-aware assistance for research, drafting, interpretation, and planning |
| Operations layer | Customer provisioning, configuration, production handoff, approvals, support, and audit |
| Security layer | Access boundaries, validation, authorization, privacy, and operational safeguards |
Logical architecture
Section titled “Logical architecture”physical object ↓connected entry point ↓identity resolution ─────→ lifecycle and trust evaluation ↓approved experience ↓authoritative workflow ──→ payment / claim / fulfillment / service ↓policy-scoped events ↓quality controls ────────→ customer and internal reportingAdministrative control follows a separate path:
named identity ↓session + role + capability ↓customer or internal scope ↓validated state transition ↓audit recordPublic interaction and administrative control do not share one universal trust boundary.
Why the layers are separate
Section titled “Why the layers are separate”- Experience content can change without remaking every physical object.
- Programs can choose an interaction and trust level appropriate to their use case.
- Customer access can remain separated from internal administration.
- Measurement can follow a defined privacy policy rather than being embedded indiscriminately.
- Sensitive business rules stay controlled outside the public page and physical identifier.
- Physical interactions, participant identity, and business authorization can be evaluated separately.
- Raw event history can remain distinct from quality-filtered reporting.
- AI providers can change behind a stable, registered task boundary.
Architectural properties
Section titled “Architectural properties”Change without physical replacement
Section titled “Change without physical replacement”The object identity is managed separately from destination content. An approved experience can be updated, paused, or retired without remaking the physical object.
Lowest sufficient trust
Section titled “Lowest sufficient trust”Standard interactions handle content and ordinary engagement. A verified tier is selected only when the workflow needs stronger evidence of authentic physical presence.
Server authority
Section titled “Server authority”Eligibility, prices, permissions, payments, fulfillment, ownership transitions, and publication are determined by server-side state—not by URL parameters, browser claims, static copy, or AI output.
Scoped intelligence
Section titled “Scoped intelligence”Analytics follow the applicable collection and retention policy. AI tasks follow a registered purpose, model lane, sensitivity, schema, and review rule. Neither layer receives general authority over the application.
Replaceable infrastructure, durable domain model
Section titled “Replaceable infrastructure, durable domain model”The public system contract is expressed in customers, programs, objects, identities, experiences, interactions, workflows, outcomes, and reports. Specific infrastructure components may evolve without changing those core responsibilities.
Deployment posture
Section titled “Deployment posture”The web and edge platform is designed around Cloudflare services, including edge application execution, access boundaries, managed data services, AI routing, and deployment controls. This reduces the distance between an object interaction and the policy or experience that must be evaluated.
The public architecture does not depend on exposing infrastructure identifiers or presenting a vendor list as the product. State of Stick’s product is the coordinated physical-and-digital operating model implemented on that infrastructure.
For the domain and state model, see Data and Control Model. This is a public-safe architecture for evaluation and planning. Database schemas, infrastructure topology, credentials, secure-device configuration, internal routes, anti-abuse thresholds, and operational security procedures are intentionally excluded.