Customer 360 & Real-Time Risk Intelligence Platform  ·  View 12 of 20

Integration Architecture

Every inbound and outbound interface, with its protocol, cadence and owner — the complete catalogue of how the platform touches other systems.

Editable source SVG draw.io All views
Inbound sources
Inbound sources
Core Banking
Oracle CDC
Core Banking...
Card Switch
Auth stream
Card Switch...
CRM
Salesforce
CRM...
Digital Channels
Mobile & web SDK
Digital Channels...
Partner Feeds
Bureau, sanctions
Partner Feeds...
Platform
Platform
Customer 360 Platform
Kafka + lakehouse
Customer 360 Platform...
Outbound consumers
Outbound consumers
Fraud Decisioning
Fraud Decisioning
Channel Applications
Profile lookup
Channel Applications...
BI Platform
BI Platform
ML Platform
ML Platform
Regulatory Reporting
Regulatory Reporting
CDC stream
CDC stream
Kafka 40k/s
Kafka 40k/s
hourly API
hourly API
HTTPS SDK
HTTPS SDK
SFTP daily
SFTP daily
Kafka, 2 s
Kafka, 2 s
REST 50 ms
REST 50 ms
JDBC gold
JDBC gold
Delta share
Delta share
signed daily
signed daily
Integration Architecture and Interface Catalogue
Integration Architecture and Interface Catalogue
External / third party
External / third party
Application we own
Application we own
event / async
event / async
batch
batch
synchronous
synchronous
Every interface has a named owner, a versioned contract and a published SLA.
Every interface has a named owner, a versioned contract and a published SLA.
v 1.0 · owner Integration Architecture · date 2026-08
v 1.0 · owner Integration Architecture · date 2026-08
Text is not SVG - cannot display

Interface standards

  • Inbound: Kafka for events, Debezium for CDC, SFTP or API pull for files
  • Outbound: Kafka for low-latency consumers, JDBC for BI, table sharing for ML
  • Every interface has a named owner, a versioned contract and a published SLA

Coupling control

  • No consumer reads another consumer's tables; all sharing is through published contracts
  • Point-to-point extracts are not permitted — they become an unmanaged interface estate
  • Deprecation of an interface requires 90 days notice and evidence of zero usage

Regulatory extracts

  • Signed, hash-verified extracts with a retained manifest of what was sent and when
  • Extracts expire after 90 days; regenerating them from gold is the supported path
  • Lineage from the extract back to source is queryable for any reporting period