System Architecture & Technical Specifications

High-Performance Stack & Cryptographic Specifications

Connecto is engineered with asynchronous non-blocking Python, peer-to-peer WebRTC mesh infrastructure, and audited cryptographic authentication standards.

Multi-Tier System Topology

Client Tier (PWA & Native Android)
Hardware Accelerated

Responsive vanilla JS & CSS3 web app powered by Service Workers (v4.0.5) alongside a native Jetpack Compose Android client with hardware-backed biometric keystore.

Edge & Anycast Ingress
DDoS Protected

Global Cloudflare Anycast edge layer enforcing TLS 1.3 strict encryption, automatic DDoS rate limiting, HTTP/2 proxying, and zero open port forwarding.

Asynchronous Application Core
Non-Blocking I/O

FastAPI and Uvicorn runtime powered by Python 3.13 asyncio event loop. Handles bi-directional WebSockets, RESTful endpoints, and background workers concurrently.

Real-Time Messaging & Voice Mesh
Low-Latency Relay

Full-duplex WebSocket broadcast channel manager coupled with decentralized WebRTC mesh audio lounges utilizing dynamic STUN/TURN ICE candidate exchange.

ACID Data Engine
WAL Mode Tuned

SQLAlchemy AsyncSession with SQLite WAL (Write-Ahead Logging), 64MB page cache, 10s busy timeout, non-blocking online backups, and covering indexes.

AI Intelligence Pipeline
Multi-Modal AI

Autonomous multi-modal career screening and rubric evaluation powered by Google Gemini API with structured JSON output and n8n webhook automation.

Protocol & Cryptographic Specifications

Layer Protocol / Standard Key Length & Parameters Purpose
Edge Transport TLS 1.3 / HTTP/2 ECDHE-ECDSA-AES256-GCM Edge-to-origin transit encryption and forward secrecy.
Voice Media DTLS 1.2 + SRTP AES-256-CTR / HMAC-SHA1-80 Peer-to-peer mesh audio encryption with ICE candidate negotiation.
Password Storage Argon2id (RFC 9106) m=65536, t=3, p=4 OWASP-recommended memory-hard hashing resistant to GPU/ASIC attacks.
Session Tokens Cryptographic Bearer Nonce 256-bit CSPRNG entropy Stateful session identification with instant revocation capabilities.
Android Keystore AndroidKeyStore Hardware Biometrics AES-256-GCM hardware-backed Connecto Vault biometric app lock and device credential protection.
Data Integrity SHA-256 + HMAC SHA-256 (32 bytes) Message nonces, APK download verification, and anti-tamper validation.