Skip to content

DebeluEngineering & Architecture Portal

Tier-1 Living Documentation, Escrow Contracts, API Specifications & Operational Runbooks

Debelu Master Documentation Portal ​


Quick Jump ​


I. Architecture & Core Explanations ​

High-level platform topology, domain-driven design, core state machines, and threat models.

DocumentDescription
System OverviewPlatform topology, multi-cloud infrastructure, C4 context diagrams, and external integrations
Escrow & Order LifecycleEnd-to-end payment collection → escrow locking → Delivery PIN verification → net payout state machine
Vendor LifecycleVendor onboarding, Tiered KYC verification, product catalog governance, seller tiers, and strike system
Campus OperationsUniversity campus commerce, student ambassador network, localized pickup hubs, and hostel logistics
Trust & Safety ArchitectureChatGuard (disintermediation shield), PriceGuard (anti-gouging), MediaModeration, and user safety
Financial Reconciliation & SettlementDouble-entry escrow ledger, Paystack settlement reconciliation, dual-authorization payouts, and wallet adjustments
Platform Governance & Change ManagementThe 4-Eyes Principle (Maker-Checker), configuration proposal lifecycle, commission rules, and staff RBAC
Authentication & Role-Based AccessSupabase Auth, JWT verification, session management, multi-role matrix, and RLS enforcement
Security Architecture & Threat ModelingSTRIDE threat model, OWASP Top 10 mitigations, API perimeter defenses, and database RLS policies
Nduzi AI Assistant ArchitectureGemini-powered multimodal conversational agent, intent routing, function calling tools, and semantic memory
Customer Support & Dispute SystemMulti-channel ticketing, in-app chat escalation, dispute state transitions, and staff arbitration flows
Architecture Decision Records (ADR)Canonical decision log capturing technical context, alternatives considered, and consequences

II. Regulatory Compliance & Governance (GRC) ​

Data privacy, financial compliance, anti-money laundering, and cardholder data boundary standards.

DocumentDescription
Data Privacy & NDPR ComplianceNigeria Data Protection Act/NDPR/GDPR posture, DSAR export engine, Right to Erasure, and PII inventory
Financial Compliance, AML & KYC StandardsCentral Bank of Nigeria (CBN) regulatory scope, Tiered KYC (BVN/NIN), AML velocity monitoring, and SAR
PCI-DSS Scoping & Cardholder Data DemarcationSelf-Assessment Questionnaire A (SAQ-A) qualification, client tokenization, and zero-CDE footprint guarantee

III. Developer Onboarding & Engineering Guides ​

Step-by-step developer guides, monorepo conventions, test suites, and terminology.

DocumentDescription
Domain GlossaryCanonical definitions for all Debelu business concepts, financial terminology, and technical acronyms
Local Environment SetupPrerequisites, local Supabase emulation, master environment variable setup, and dev servers boot
Monorepo Workflow & Toolingnpm workspaces, Turborepo pipeline caching, shared package linking, and dependency management
Testing Strategy & Test SuitesUnit testing (Vitest/Jest), integration tests, Pact contract testing, Playwright E2E, and load testing
Contributing Standards & Code StyleGit branching strategy, Conventional Commits, TypeScript strictness, and automated CI review gates

IV. Service Architecture & Packaging ​

Independent surface guides for the storefront, backend, marketing, native mobile, and shared packages.

DocumentDescription
Storefront Web ApplicationReact 18 SPA, Vite, TanStack Query, Zustand state stores, Tailwind design tokens, and Cloudflare Pages
Backend API ServiceExpress API, 38 route modules, 64 domain services, BullMQ queues, middleware pipelines, and Fly.io compute
Marketing & Public SiteNext.js 15, App Router, Incremental Static Regeneration (ISR), technical SEO, auth entry points, and Vercel
Mobile Application (Capacitor)Capacitor iOS and Android native packaging, push notifications, biometric auth, deep linking, and PWA
Shared Packages & Design System@debelu/ui shared component library, @debelu/core business utilities, and design token synchronization

V. Technical Reference & Contract Specifications ​

Exhaustive technical contracts, database schemas, API specs, and configuration matrices.

DocumentDescription
REST API Endpoints CatalogExhaustive catalog of all 38 backend route namespaces, HTTP verbs, payload parameters, and auth gates
API Standards, Versioning & ContractsREST design principles, RFC 7807 Problem Details error catalog, Idempotency-Key spec, and rate limits
Webhook Specifications & ProtocolsPaystack payment/transfer webhooks, WhatsApp API webhooks, HMAC SHA-512 signatures, and replay deduplication
Database Schema & Data ModelsPostgres entity catalog, foreign key relationships, performance indexes, and Row-Level Security policies
Database Migration History & GuidelinesChronological log of 97+ Supabase migrations, migration naming rules, and production deployment safety
Supabase Edge FunctionsDeno serverless edge functions (paystack-webhook, notification dispatchers), deployment, and secrets
Master Environment Variables MatrixComprehensive cross-surface environment matrix across development, preview, staging, and production
Feature Flags CatalogUnleash feature flag system, gradual rollout strategies, percentage targets, and emergency kill switches
Accessibility Standards (WCAG 2.1 AA)Contrast compliance, keyboard navigation traps, ARIA guidelines, screen reader semantics, and axe-core tests
Internationalization (i18n)i18next framework, locale detection, language resource bundles, and currency/date formatting conventions
SEO & Web Performance OptimizationDynamic XML sitemaps, OpenGraph metadata, Core Web Vitals (LCP, INP, CLS), and cache-control headers
Scripts & Tooling Catalog60+ repository utility scripts: database smoke tests, seeders, verification probes, and automation tools

VI. Operations, Reliability & Incident Management ​

Production infrastructure management, multi-cloud topology, monitoring, and release governance.

DocumentDescription
Production Deployments & TopologyMulti-cloud CI/CD deployment pipelines (Fly.io, Cloudflare, Vercel), branch automation, and rollbacks
Disaster Recovery & Business Continuity (BCP)Quantified RTO/RPO SLAs, Supabase PITR database restoration, multi-cloud regional failover, and BCP drills
SLOs, SLAs & Production MonitoringService Level Objectives (99.95% checkout), error budget burn rate alerts, health check probes, and Sentry
Monitoring, Observability & AlertingSentry distributed error tracking, 7-point deep health check engine, CWV telemetry, and Winston JSON logging
Incident Response PlaybookSEV-1 to SEV-4 incident classification, incident commander roles, war room protocols, and blameless RCAs
Release Process & Changelog StandardsSemantic Versioning (SemVer), pre-release verification gates, automated changelog generation, and SBOM

VII. Operational Runbooks & Standard Operating Procedures (SOPs) ​

Step-by-step Standard Operating Procedures for on-call engineers, dispute arbiters, and financial operations.

RunbookPurposeTarget Role
Payout Failure & Exception ResolutionTroubleshooting failed vendor bank transfers, Paystack exceptions, NUBAN verification, and retriesFinancial Operations & On-Call
Escrow Dispute ArbitrationEvidence collection, decision matrix, and manual fund release/refund via Maker-Checker command servicesSupport Lead & Arbiters
Vendor Suspension & EnforcementImmediate account freezes, delisting products, withholding payouts, handling in-flight orders, and appealsTrust & Safety Team
Secrets & Credential RotationZero-downtime rotation protocol for Paystack, Supabase, JWT, Gemini, and Cloudflare credentialsDevOps & Platform Leads

VIII. Historical Migration Records & Technical Audit Archives ​

Archived technical migration receipts, deployment checklists, and specific observation logs.

DocumentCategoryDate / Reference
API Key Setup GuideLegacy SetupThird-party credential configuration
Production Operations GuideLegacy OperationsBaseline service operations and access runbook
Infrastructure Migration PlanMigration PlanMulti-cloud hosting migration roadmap
DNS Migration PlanMigration PlanCloudflare DNS cutover strategy
Browser Migration RunbookPlatform RunbookBrowser engine compatibility migration
Command Center Implementation StatusSystem StatusOperations command center implementation tracker
Command Center Migration ChecklistChecklistPre-flight and post-flight operational checklist
Command Center Production Migration ReceiptAudit ReceiptProduction migration verification record (2026-10-05)
Command Center Queue ObservationsDiagnosticsBullMQ background worker queue telemetry
Command Center Recovery PlaybookPlaybookCommand center disaster and recovery procedures
Native Command Concurrency VerificationVerificationConcurrency and lock contention verification receipt
Product Improvement AuditAudit LogPlatform-wide UX and performance improvement audit (2026-10-02)
Subject Privacy Export DeliveryPrivacy AuditTechnical implementation notes for DSAR export delivery
Expanded Owned Privacy ExportsPrivacy AuditExpanded entity export inventory for compliance
Privacy Erasure Inventory PlansPrivacy AuditInitial technical blueprint for data erasure pipelines
Privacy Erasure Inventory Next SlicePrivacy AuditIncremental table deletion mapping for RTBF
Payout Exception ObservationsFinancial AuditTechnical observation log of payout transfer exceptions
Support Notification OutboxInfrastructureTransactional outbox pattern notes for customer support

Released under Proprietary Enterprise License.