Solution Architecture Erlang Elixir Digital Wallet Platform 1. Purpose of the Document This document describes the solution architecture for the Erlang Elixir Digital Wallet Platform. It provides a layered, service-oriented view of the system, explaining how digital channels, APIs, security, core wallet services, integrations, data persistence, and operations work together to deliver a secure, scalable, and resilient wallet platform. The architecture is designed to be: • Microservices-aligned in concept • Event-driven where appropriate • Strongly consistent for financial data • Compliant with regulated financial environments 2. Architectural Principles The solution follows these key principles: 1. Layered Architecture – Clear separation of concerns 2. Domain-Driven Design – Financial, business, and orchestration domains separated 3. Event-Driven Core – Internal domain events over tight coupling 4. Security by Design – DMZ, private zones, token-based access 5. Scalability & Resilience – Horizontal scaling, async processing 6. System-of-Record Clarity – Explicit ownership of financial data 7. Operational Visibility – Logging, monitoring, and auditability 3. High-Level Architecture Overview The platform is organized into the following logical layers: 1. Digital Frontend Engagement Layer 2. API Engagement Layer 3. DMZ & Security Layer 4. Private Secure Zone – Core Wallet Platform 5. Integration & Adapter Layer 6. Data Persistence & Core Banking Layer 7. Observability, Operations & Security Each layer has a clearly defined responsibility and interacts with adjacent layers through well-defined interfaces. 4. Digital Frontend Engagement Layer Purpose Provides user-facing and partner-facing access to the wallet platform. Components • Web Application (Phoenix LiveView) • Mobile Application (React Native, BFF-backed) • Admin Portal (Phoenix LiveView) • Partner / External Systems (REST / gRPC APIs) Characteristics • Stateless clients • Secure HTTPS communication • No direct access to core services • All traffic routed via API layer 5. API Engagement Layer Purpose Acts as the controlled entry point for all external traffic. Components • Global Load Balancer (GLB) • API Gateway (Kong / Nginx) Responsibilities • Request routing and load balancing • Rate limiting and throttling • API versioning • Forwarding authenticated requests to core services This layer enables the platform to scale horizontally while protecting downstream systems. 6. DMZ Zone & Security Layer Purpose Implements edge security controls and isolates the private core network. Components • Auth & Token OTP Service (Guardian-based) • Session, Token & Rate-Limit Cache (Redis) Responsibilities • Authentication and OTP validation • Token issuance and validation (JWT) • Session management • Rate limiting and abuse prevention No core business logic resides in this layer. 7. Private Secure Zone – Core Wallet Platform This is the heart of the system, implemented as Elixir OTP applications. 7.1 Internal Real-Time Backbone Component • Distributed Phoenix PubSub (OTP-based, Cluster-wide Event Backbone) Purpose • Acts as an internal event bus • Enables low-latency communication between core services • Supports real-time domain events, workflow signaling, and cache invalidation Microservices Mapping Functionally similar to an internal event bus used in microservice architectures, optimized for in-cluster communication. 7.2 Financial & Account Domain Components • Wallet & Account Service • Transaction Processing & Ledger Service • Transfer & P2P Payments Service Responsibilities • Wallet lifecycle and balance management • Transaction authorization and posting • Immutable ledger entries • P2P and account transfers This domain owns wallet-side financial system of record. 7.3 Value-Added & Business Domain Components • Onboarding & KYC/KYB Orchestration • Lending Engine • Rewards & Offers Service • VAS & Utility Services Responsibilities • Customer onboarding workflows • Business value-added services • Non-core financial features KYC data orchestration occurs here; sensitive data storage is externalized or encrypted. 7.4 Process Orchestration & Risk Domain Components • Journey Coordinator (GenServer / OTP) • Rules, Limits & Fees Engine (Broadway) • Fraud Detection Engine (GenStage / Streaming) Responsibilities • End-to-end transaction orchestration • Limits, fee calculation, and policy enforcement • Real-time fraud detection and risk scoring This layer enables business process consistency without tight coupling. 7.5 Async Processing & Background Workers Components • Notification Service (Phoenix Channels) • Settlement & Reconciliation Workers (Oban / Quantum) Responsibilities • Asynchronous notifications • Settlement processing • Reconciliation and exception handling Async processing ensures that core transaction flows remain fast and resilient. 7.6 Distributed State Store Component • Distributed State Store (Mnesia / ETS) Usage • Workflow state • Idempotency keys • Locks and coordination metadata This store is not used for financial data and does not replace relational databases. 8. Integration & Adapter Layer Purpose Decouples core services from external systems. Components • Payment Gateway Adapters • Core Banking Adapter (Oracle, ISO8583 / gRPC) • 3rd Party VAS Adapters • External Fraud Providers Benefits • Protocol abstraction • Reduced vendor lock-in • Controlled failure handling 9. Data Persistence & Core Banking Layer Components • Wallet DB (Postgres) – Wallet System of Record • Ledger DB (Append-Only) – Financial Ledger • Oracle CBS – External Banking System of Record • Event Stream (Kafka / CDC, on demand) Key Design Points • Database-per-service model • Immutable ledger for auditability • Clear separation between wallet SoR and bank SoR • Kafka used selectively for cross-system streaming 10. Observability, Operations & Security Observability • Centralized Logging (ELK) • Telemetry & Monitoring (BEAM / OpenTelemetry) Security • Secrets Management (Azure Vault) • Hardware Security Module (Thales HSM) • Security Monitoring (SIEM) Operational Capabilities • End-to-end traceability • Audit readiness • Incident response and alerting 11. Non-Functional Characteristics Area Description Availability No single point of failure Scalability Horizontal scaling at each layer Performance Low-latency core transactions Security Token-based, zoned architecture Auditability Immutable ledger & logs Maintainability Modular OTP applications 12. Summary The Erlang Elixir Digital Wallet Platform architecture delivers a secure, scalable, and event-driven wallet system, aligned with modern microservices principles while leveraging the strengths of Elixir OTP.