Terminology
2240 terms, tools, patterns and metrics an architect is expected to use precisely. Each one gets a short explanation of what it is, and — where it matters — what it is commonly confused with. Search filters as you type; the column headers sort.
All areas2240
Architecture Fundamentals77
Distributed Systems107
Data Architecture110
Cloud Architecture94
Networking88
API & Integration Architecture82
Reliability & Resilience80
Observability75
Performance & Capacity Engineering72
Security Architecture86
Cost Architecture & FinOps71
Business Architecture67
Architecture Communication67
Enterprise Architecture66
Legacy Modernization71
AI-Era Architecture74
Software Architecture & Engineering71
Architecture Patterns71
Architecture Decision-Making63
The Architect's Meta-Skills61
Delivery & Release Engineering66
Platform Engineering & Developer Experience70
Testing & Quality Architecture71
Data Platform Architecture69
Streaming & Real-Time Data69
Data Governance & Semantics74
Frontend & Experience Architecture66
Edge, Mobile & IoT68
Regulatory & Data Protection Architecture65
Assurance, Audit & Model Risk69
65 terms shown.
| Term | Kind | Topic | What it is |
|---|---|---|---|
| Access Geography Access as Transfer, Remote Viewing | concept | Cross-Border Transfer | The recognition that viewing data from another jurisdiction is a cross-border transfer, which makes access control and the location of the people using it a transfer control. |
| Communication Capture Obligation Off-Channel Risk, Supervised Communications | practice | Records Retention & Legal Hold | A duty to preserve and produce business communications, which fails whenever the compliant channel is less convenient than an available alternative - making channel design, not policy, the control that determi… |
| Compliance Perimeter Scope, In-Scope Estate | concept | PCI-DSS Scoping | The set of systems subject to a compliance regime - whose size is the dominant cost of that regime, and which is determined by architectural decisions rather than by the assessment. |
| Compliance Scope Boundary Scope Reduction, Cardholder Data Environment | practice | PCI-DSS Scoping | The set of systems subject to a compliance regime - determined by where regulated data flows, and reducible by architecture rather than by adding controls. |
| Concentration Risk Systemic Dependency, Single-Provider Exposure, Vendor Concentration | concept | Third-Party Risk | The exposure created when many organisations, or many parts of one organisation, depend on the same provider - so that a single failure is correlated across the system rather than isolated. |
| Consent Architecture | pattern | Consent Architecture | Capturing, storing and enforcing a person's permissions for specific processing purposes, across every system that acts on their data. |
| Consent Propagation Consent Enforcement, Withdrawal Fanout | practice | Consent Architecture | Carrying a consent decision - and especially a withdrawal - to every system and third party that processes on the basis of it, which is where most consent implementations fail. |
| Cross-Border Transfer Mechanism SCCs, Adequacy Decision, Transfer Impact Assessment | concept | Cross-Border Transfer | The legal basis required to move personal data from one jurisdiction to another, and the architectural evidence needed to support it. |
| Data Minimisation | concept | Lawful Basis & Purpose Limitation | Collecting and retaining only the personal data actually necessary for the stated purpose, treated as an architectural constraint rather than a policy statement. |
| Data Residency Data Localisation | concept | Data Residency | A requirement that data be stored, and sometimes processed, within a specified geography. |
| Data Subject Access Request DSAR, SAR | concept | Data Subject Rights | An individual's request for a copy of the personal data an organisation holds about them, which must be fulfilled completely within a statutory deadline. |
| Deemed Status Provisional Outcome, Presumed Result, Timeout Resolution Rule | pattern | Financial Services Regulation | A provisional outcome assigned to a transaction whose true result is unknown after a timeout, resolved later by reconciliation - because a payments rail cannot leave money in an indeterminate state indefinitely. |
| Deletion Horizon Erasure Horizon, Last-Copy Latency | metric | Data Subject Rights | The elapsed time after an erasure request until the last copy of the record is gone or unreadable, set by the longest-lived derived copy rather than by the live database. |
| Differential Privacy Budget | concept | Privacy-Enhancing Technologies | The cumulative privacy loss permitted across all queries against a dataset, which must be tracked and exhausted rather than applied per query. |
| Digital Sovereignty | concept | Digital Sovereignty | Requirements that data and the ability to operate on it remain under a jurisdiction's control — a stronger and more architecturally demanding constraint than residency. |
| Exit and Concentration Risk | concept | Exit & Concentration Risk | The regulatory concern that an institution cannot leave a critical provider, and that too much of the sector depends on the same few providers. |
| External Key Store Hold Your Own Key, External Key Manager, HYOK | pattern | Digital Sovereignty | Holding the key-unwrapping function in a system the cloud provider does not operate so that a decrypt requires a call outward, converting a contractual promise about foreign access into a technical dependency. |
| Fail-Open Audit Boundary Audit Fail-Open Rule, Accountability Degradation Policy | pattern | Healthcare Data Protection | A pre-declared rule saying which classes of access may proceed when the audit trail cannot be written and which must be refused, so a logging failure does not become a safety failure or an invisible one. |
| Financial Services Regulation | concept | Financial Services Regulation | Architecture under financial regulation — where record-keeping, demonstrable resilience, and the ability to exit a provider are structural requirements. |
| Fourth Party Risk | concept | Third-Party Risk | The dependencies of your dependencies, which you did not choose, may not know about, and remain accountable for. |
| Functional Equivalence Switching Equivalence, Same-Service-Type Equivalence | concept | Sector Cloud Rules | The standard that a destination service must deliver the same output at the same performance and security after a switch, which is defined only between services of the same type and therefore does not rescue a… |
| Geo-Blocking Accuracy | concept | Geo-Restriction & Sanctions | The reliability of determining a user's jurisdiction from network signals, which is imperfect in both directions and therefore needs a designed handling of errors. |
| Geo-Restriction and Sanctions | practice | Geo-Restriction & Sanctions | Preventing prohibited access and transactions by location or party — where the control must be enforced, evidenced and current. |
| Healthcare Data Protection | concept | Healthcare Data Protection | Architecture for health information — where access must be broad enough for care, auditable in detail, and safe when the system is unavailable. |
| Immutable Store Erasure Conflict | concept | Erasure vs Immutability | The direct contradiction between architectures designed never to forget and obligations requiring data to be removed, which must be resolved in the design rather than in policy. |
| In-Country Processing | concept | Data Residency | Keeping data within a jurisdiction across every path it takes — including backups, logs, telemetry, support access and the disaster recovery region. |
| Key-Custodian Separation Token Vault Separation, Split-Custody Pseudonymisation | pattern | Pseudonymisation | Keeping the mapping or key that re-identifies pseudonymised data in a system with a different access path from the data itself - so a breach of the analytical store yields behaviour without people. |
| Legal Hold | practice | Records Retention & Legal Hold | Suspending deletion for specific records because of anticipated litigation or investigation, which must override the retention schedule and be provable. |
| Material Outsourcing Notification | practice | Sector Cloud Rules | The regulatory obligation to inform a supervisor before placing a critical function with a third party, which puts cloud adoption on a timeline architecture must respect. |
| Minimum Necessary Access | concept | Healthcare Data Protection | Restricting each user to the health information required for their specific role and, in the strong form, to the patients they are actually treating. |
| Objection Register Opt-Out Register | pattern | Lawful Basis & Purpose Limitation | The durable default-allow counterpart to a consent store, holding every objection and opt-out and consulted at use time by every job, because switching a lawful basis from consent to legitimate interests inver… |
| Obligation Mapping | practice | Regulatory & Data Protection Architecture | Translating each legal or regulatory requirement into the specific design constraints it imposes, so that compliance becomes a set of testable properties rather than a document. |
| Operational Resilience Requirement | concept | Financial Services Regulation | A supervisory expectation that a firm can continue delivering critical business services through disruption, expressed as an impact tolerance it must evidence. |
| Operator Independence | concept | Digital Sovereignty | The requirement that no foreign entity can be compelled to access or disclose data, which goes beyond where the bytes are stored to who controls the operator. |
| PCI DSS Scope Reduction | practice | PCI-DSS Scoping | Deliberately limiting which systems handle cardholder data so that the audited estate is small, since every in-scope system carries the full control burden. |
| Point-in-Time Reconstruction As-At Reporting, Reproducible Submission | practice | Regulatory Reporting Pipelines | The ability to regenerate a past report from the data and rules as they stood then - without which a regenerated figure differs from the submitted one and the difference cannot be explained. |
| Privacy by Design | practice | Privacy by Design | Building data protection into the architecture from the first design decision rather than adding controls to a system already built. |
| Privacy Enhancing Technology PETs | concept | Privacy-Enhancing Technologies | Techniques that allow useful computation over data without exposing the underlying records — differential privacy, secure multi-party computation, homomorphic encryption, federated learning. |
| Privacy Loss Accounting Budget Composition Tracking, Epsilon Accounting | practice | Privacy-Enhancing Technologies | Tracking cumulative privacy loss across every statistic released from a dataset, because differential privacy's guarantee holds over the whole publication rather than per query - and once the budget is spent, … |
| Private Set Intersection PSI, Private Join and Compute | protocol | Privacy-Enhancing Technologies | A cryptographic protocol that lets two parties learn the size of - or an aggregate over - the overlap between their datasets without either learning the other's non-matching members. |
| Processor Instruction Boundary Controller-Processor Line, Own-Purpose Test | concept | Third-Party Risk | The line at which a vendor stops acting only on your documented instructions and starts pursuing purposes of its own - which decides your lawful basis, your consent gating and your breach clock. |
| Provider Exit Plan | practice | Exit & Concentration Risk | A documented and tested plan for moving a workload off a provider, whose credibility is measured by what has actually been rehearsed rather than described. |
| Pseudonymisation | practice | Pseudonymisation | Replacing identifying fields with a reference so records cannot be attributed to a person without separately held additional information. |
| Purpose Binding Purpose Metadata, Use Limitation Tagging | practice | Lawful Basis & Purpose Limitation | Recording with the data the purpose it was collected for, and carrying that constraint through derivation, so a later use can be checked against what was agreed at collection. |
| Purpose Limitation Use Constraint, Purpose Binding, Secondary Use Control | concept | Lawful Basis & Purpose Limitation | The requirement that personal data collected for one stated purpose is not used for another, which architecture enforces by binding a purpose to every dataset and evaluating it at the point of use rather than … |
| Quasi-Identifier Set Indirect Identifiers, Re-identification Vector | concept | Pseudonymisation | The combination of attributes that singles out an individual even after direct identifiers are removed - which is why deleting names and ids does not anonymise a dataset, and why free text and behavioural hist… |
| Re-Identification Risk | concept | Pseudonymisation | The probability that pseudonymised data can be linked back to individuals, which is what keeps such data within the scope of data protection law. |
| Records Retention and Legal Hold | practice | Records Retention & Legal Hold | The obligation to keep specified records for a defined period, and to suspend all deletion for material relevant to anticipated litigation. |
| Register of Information ICT Third-Party Register, Contractual Arrangements Register | practice | Sector Cloud Rules | A maintained record of every contractual arrangement with a technology provider, including its subcontractors and which critical functions it supports, which converts supplier dependency from a question requir… |
| Regulatory Architecture | concept | Regulatory & Data Protection Architecture | Designing so regulatory obligations are properties of the system rather than commitments the organisation makes on its behalf. |
| Regulatory Reporting Pipeline | concept | Regulatory Reporting Pipelines | A data pipeline whose output goes to a regulator, where correctness, reproducibility and demonstrable lineage matter more than latency or elegance. |
| Restatement Record Correction Record, Submission Versioning | practice | Regulatory Reporting Pipelines | Preserving the original submission alongside its correction, with the reason and the difference explicable - so that a restated figure strengthens the audit trail instead of destroying it. |
| Retention Clock Retention Trigger Event, Governing Event | concept | Records Retention & Legal Hold | The business event from which a retention period is measured - not the row's creation - which must be recomputed rather than stored because late events move it. |
| Right to Erasure Right to be Forgotten | concept | Erasure vs Immutability | An individual's right to have their personal data deleted, which collides directly with append-only and immutable architectures. |
| Scope Reduction | practice | PCI-DSS Scoping | Shrinking the set of systems that store, process or transmit cardholder data, because the cost of the standard is proportional to the number of systems in scope. |
| Screening Enforcement Point Sanctions Control Placement, Party Screening Gate | pattern | Geo-Restriction & Sanctions | The place in a system where a restriction is actually enforced - which must match what the obligation is about, since sanctions apply to parties and licensing restrictions apply to locations, and a control pla… |
| Sector Cloud Rules | concept | Sector Cloud Rules | Sector-specific rules governing cloud use — outsourcing notification, audit rights, concentration risk and exit — which shape provider and service choices. |
| Secure Aggregation Private Aggregation, Cohort-Level Aggregation | protocol | Privacy-Enhancing Technologies | A cryptographic protocol that lets a server learn only the sum of many clients' model updates and never any single client's update, which is what makes an on-device training claim survive scrutiny. |
| Subject Access Fulfilment | practice | Data Subject Rights | The operational path from a request to a complete, verified, delivered response within the statutory period, across systems that were never designed for it. |
| Submission Deadline Architecture | concept | Regulatory Reporting Pipelines | Designing a reporting pipeline around a fixed external deadline, where late is a breach and the recovery window is part of the schedule rather than a contingency. |
Nothing on this page matches. Search the whole glossary.