GLYPHLOCK · NUPS
Workflow buyer demonstration · scene-locked male narration
Operating platformStripe nativeProcessor overlay
01 · VERIFY
Identity starts the record
01 / 06
Live identity intakeNEW TX · 9F2A4C
Government ID
Scanning
Guest name
Reading…
Date of birth
Reading…
ID number
Reading…
Identity status
VALIDATING
Operator role
WAITING
Transaction state
Building verified transaction shell
Open transaction
Create a new guest transaction shell
Pending
Scan identity
Read government-issued identification
Pending
Validate guest
Resolve identity into the guest record
Pending
Authorize operator
Apply role-scoped venue permissions
Pending
Start verified record
Bind guest and operator to transaction
Pending
NUPS is the operating and evidence layer for high-verification venue commerce. Every transaction begins with a verified identity and a role-scoped operator.
Male narration
Narration now drives visible product-state changes
GLYPHLOCK
19 functional domains · 250+ backend functions · 160+ entity schemas
CORE OPERATIONS
Identity · Register · contracts · GlyphBucks · payouts · audit · reporting
PAYMENT CONTROL
Stripe-native processing · external-processor overlay · adapter architecture
PLATFORM EXTENSIONS
DJ · messaging · marketing · offline-assisted continuity · dispute automation
Venue operating system + transaction evidence infrastructure

Run the venue.Control the transaction record.

NUPS consolidates identity, access, Register, contracts, GlyphBucks, payouts, audit, reporting, messaging, DJ and entertainer workflows, and dispute evidence around one transaction model. When GlyphLock/NUPS controls the payment path, Stripe is the native processing rail. When a venue keeps its merchant account or terminal, NUPS can bind that processor's approval, reference, receipt, contract, identity, and audit evidence into the same operating record.

Commercial architecture: one NUPS operating record with two payment paths. Stripe-native processing is available for GlyphLock/NUPS-controlled transactions; external processors can remain in place through evidence capture or deeper API/webhook integration.

Identity-Bound Commerce Workflow

One verified identity. One transaction record. Every downstream action linked.

NUPS carries the verified guest context through consent, service selection, payment evidence, approvals, contract generation, receipt creation, and verification references. The result is a transaction lifecycle built around continuity instead of disconnected tools.

01

Identify the guest

Scan an ID, upload a clear ID image, or choose a recent verified guest profile for the current venue.

02

Review and confirm identity

NUPS autofills the legal name, member reference, age status, and ID reference. The operator confirms the identity before continuing.

03

Review terms and consent

The guest reviews the applicable GlyphBucks and VIP terms, completes the required initials, and records clickwrap assent once.

04

Build and route the transaction

Select the suite and services, calculate the total, then use Stripe natively or bind an existing processor approval/reference to the same NUPS transaction record.

05

Sign and approve

The verified guest name becomes the purchaser name everywhere. The issuer representative and manager complete their approvals.

06

Seal, print, and verify

NUPS generates the contract and receipt from the same identity-bound record, then provides print and verification references.

Unified role-based access

One gateway routes the venue by verified role

Staff, entertainers, managers, and owners continue through the same entry point and are routed by their verified role.

Multiple Patents Pending
AZ Entity #23831258
DACO · Master Covenant
NUPS · FULL-STACK VENUE OPERATING PLATFORM

System Architecture

§ 01 · Topology
◆ GLYPHLOCK · NUPS · 5-LAYER ARCHITECTURE ◆◆ GOVERNANCE · AUTHORITY · IP · POLICY ◆⬢ GOVERNANCEDACO Master Covenant71 clauses · Carlo authorityMultiple Patents Pending⬢ IP VAULTSteganographic EngineQR glyph generation · sealedplatform-owned · licensed out⬢ AUDIT · PLATFORMAuditEventvenue_id optional · securityplatform telemetry⬢ ACCESS MATRIX7-Tier RBACAdmin → Guest scopesvenue_id gated◆ PLATFORM SERVICES · MULTI-TENANT · OFFERED TO ALL VENUES ◆⬢ DISPUTE SHIELDEvidence Continuityevidence engine live · automation advancing⬢ SANDBOX MODESREAL · DEMO · DEVsk_live · sk_test · isolated tiers⬢ MARKETING ENGINEQR · SMS · Socialscheduler · platform-managed⬢ PAYMENT ORCHESTRATIONStripe Native · Externalprocess · overlay · API integration⬢ STEGANO ENGINEQR issuanceper-venue · IP-protected◆ GOVERNANCE BOUNDARY · POLICY ENFORCEMENT ◆◆ PLATFORM / VENUE ISOLATION BARRIER · TENANT SEPARATION ENFORCED ◆◆ VENUE OPERATIONS · TENANT-SCOPED VIA venue_id ◆COREMULTI-VENUE RUNTIMENEXUS UNIFIEDPORTAL SYSTEMvenue_id → tenant⬢ GUEST PROFILEMag-swipe → Accountcard · QR · name lookup⬢ DRIVER ONBOARDINGProfile + QR issuedscan → parametric payout⬢ ENTERTAINER · ISOLATED1099 · separate ledgerno tip pool · no payroll⬢ STAFF CLOCK-IN/OUTBiometric + Shift Loghours · breaks · OT · payroll⬢ VIP CONTRACTPrint · Sign · RescanET-5850 print → Epson WiFi scan⬢ DJ ROTATION ENGINEEntertainer Self-Serveplaylists · sets · live queue⬢ CAMPAIGN CONFIGVenue-side schedulingQR · SMS targeting⬢ PAYMENT EVIDENCE LAYERStripe · Terminal · APIone PaymentRecord · unified transaction proof⬢ Register CATALOGDrinks · Bottles · Covercash + card only · voids logged⬢ GLYPHBUCKS · SVCClosed-Loop CurrencyQR = tx_id = contract_id⬢ PAYOUT ENGINEDriver · Staff · Tip Poolparametric · entertainer excluded⬢ SYSTEMAUDITLOGFinancial · Operationalvenue-scoped · immutable⬢ REPORTINGShift close · drawer recondaily deposit · weekly P&L⬢ INVENTORYCost basis · par levelspour tracking · alertsaudit forwardingplatform-scopedpolicy · scope · access◆ INFRASTRUCTURE TRUST BOUNDARY · SECRETS ISOLATED FROM TENANT ◆◆ INFRASTRUCTURE SUBSTRATE · WHAT IT RUNS ON ◆⬢ DATA · PRIMARYEntity Store250+ fn · 160+ entity schemas⬢ DATA · CREDENTIALExternal SupabaseJWT · auth isolated⬢ HARDWARE · RegisterAmbir · Adesso · EpsonID · biometric · thermal⬢ HARDWARE · MGMTSamsung Tabletsoversight · mobile tier⬢ MESSAGING INFRATwilio · SendGridOTP · alerts · 1099⬢ PROCESSOR CONNECTOverlay or IntegrateBYO merchant account · APIs optional⬢ SESSION SECURITYMFA · JWT verifydevice attestation⬢ OBSERVABILITYLogs · metrics · tracesincident detectionGlyphLock LLC · AZ #23831258 · Multiple Patents Pending · DACO Master Covenant v3.0
Platform Policy Identity · Data Commerce · TX Audit · Evidence Blockchain Attest Isolation Barrier

Hospitality Integrations

§ INT · Oracle OHIP

Oracle Hospitality via OHIP

Partner Sandbox Response Validated
OPN Level 0 Active
Marketplace Program Active
Simphony Request Under Review

On August 24, 2026, NUPS completed an authenticated, controlled read-only room-configuration request against the Oracle Hospitality Integration Platform Partner Sandbox and validated the sanitized response. This establishes a technical path for connecting verified NUPS venue operations with OPERA Cloud property configuration while keeping Oracle credentials and tokens server-side. GlyphLock LLC’s Level 0 OPN membership has been active since August 19, 2026.

Oracle PartnerNetworkMembership Active

Level 0 membership is active under OPN Company ID 4-463913260838 and enrollment #1654123 through August 18, 2027.

AuthenticationOCIM OAuth Verified

Client-credentials authentication completes through the configured OHIP gateway.

Sandbox PropertySandbox Property Configured

NUPS can identify the authorized sandbox hotel and distinguish properties without exposing environment identifiers.

Read-Only APIsProperty + Room Discovery

Sanitized chain, property, room-number, and room-type configuration can be validated before mapping.

Security BoundaryServer-Side Secrets

No Oracle secret, OAuth token, guest record, reservation, or raw response is exposed publicly.

Oracle Cloud MarketplaceProgram Enrollment Active

Oracle approved and activated GlyphLock’s Cloud Services / Oracle Cloud Marketplace enrollment #1655445 on August 25, 2026. Publisher-account status and a published NUPS listing remain separate gates.

Oracle SimphonyFormal Request Submitted

GlyphLock submitted the Simphony Integration Partner Program request on August 25, 2026. Oracle’s Partner Integration Team is reviewing the request; onboarding and Solution Validation have not begun.

Current status: Level 0 OPN membership is active, the August 24, 2026 read-only Partner Sandbox test reached response validated maturity, Oracle Cloud Marketplace program enrollment #1655445 is approved and active, and the formal Simphony integration request is under Oracle review. These milestones do not represent a published NUPS Marketplace listing, Oracle certification or endorsement, Simphony Solution Validation, a production customer connection, or an executed commercial partnership. Production access still requires the applicable Oracle application, environment, hotel authorization, and production credentials.

Stakeholder Protection

§ 02 · High-Risk Mitigation
Evidence-Driven Infrastructure

Bad business becomes self-evident.

High-risk commerce becomes expensive when identity, payment approvals, contracts, receipts, payouts, staff actions, and dispute evidence live in different systems. NUPS turns those fragments into one transaction-centered operating record. Stripe can serve as the native payment rail when GlyphLock/NUPS controls processing; when a venue retains another processor, NUPS preserves the same identity, consent, contract, receipt, approval, and audit continuity around that payment.

Moat: the payment rail is only one layer. NUPS controls the operational context, identity continuity, transaction evidence, venue workflow, and audit history that surround the money movement.

Protecting

The Bank

Without NUPSUnderwriting and review may rely on fragmented merchant records with limited transaction provenance.
With NUPSStructured transaction provenance gives underwriting and review teams a coherent identity, consent, payment, contract, and audit trail instead of merchant-supplied fragments. Final reserve, MATCH, and underwriting decisions remain with the bank or processor.
Protecting

The Processor

Without NUPSEvidence may be scattered across receipts, cameras, contracts, and staff recollection.
With NUPSProcessor references, receipts, identity, contracts, approvals, and audit events stay transaction-linked, giving dispute teams a structured evidence source instead of a reconstruction exercise. Outcomes still depend on network rules and case facts.
Protecting

The Venue

Without NUPSCash shrinkage, tip-pool disputes, contract claims, and fragmented operational records.
With NUPSThe venue operates from a shared transaction record spanning commerce, contracts, payouts, staff actions, reconciliation, and evidence. That reduces operational fragmentation while strengthening the quality of records available when something is challenged.
Protecting

The Guest

Without NUPSReceipts, terms, and identity records may be fragmented or difficult to retrieve.
With NUPSThe guest can be tied to a consistent contract, receipt, consent, transaction, and verification reference, making the commercial record easier to retrieve and understand.

Access Matrix — 7 Tiers

§ 03 · RBAC
TIER 00

Admin

  • All venues
  • Platform config
  • Billing / invoices
  • Role provisioning
  • Mode switch
TIER 01

Owner

  • Own venue(s) only
  • Full financials
  • Contracts access
  • Hire / fire staff
  • Dispute packages
TIER 02

Venue Mgr

  • Single venue ops
  • Staff clock-in/out
  • Shift reports
  • Sign contracts
  • Print GlyphBucks
TIER 03

Staff

  • Register · bar · door
  • Own shift data
  • Tip pool visible
  • Clock self in/out
  • No financials
TIER 04

Entertainer

  • Own earnings
  • Own hours
  • Own contracts
  • Biometric check-in
  • 1099 tax docs
TIER 05

Driver

  • Own QR code
  • Guest count log
  • Own payouts
  • Scan-only interface
  • No venue data
TIER 06

Guest

  • Own profile
  • Own contracts
  • Receipt lookup
  • GlyphBucks balance
  • Consent mgmt

Dispute Shield — Evidence Continuity

§ 04 · Chargeback Defense + Automation
Build Evidence Before a Claim

Make the transaction reviewable from the start.

NUPS does not wait for a chargeback to begin organizing the record. As the transaction develops, it links contracts, consent, receipts, audit events, identity references, processor approvals, and configured verification evidence into the transaction context. The evidence-source compiler and retrieval layer are implemented now.

When a claim lands, NUPS can retrieve those linked sources into a reviewable evidence record. Automated signed-PDF packaging and direct processor dispute-API submission are the next automation layer on top of an evidence foundation that already exists.

Illustrative Evidence PackagePKG-TX_9F2A4C
  • Signed contract / hash referenceSOURCE LINK
  • Video attestation, when enabledOPTIONAL
  • Verification still frames, when capturedOPTIONAL
  • Biometric match reference, when hardware-validatedHARDWARE
  • Processor receipt/reference + GlyphBucks QRLINKED
  • OpenTimestamps anchor, on supported sealed flowsSUPPORTED
  • Click-wrap consent and approval logLINKED

Driver Payout — Parametric Example

§ 05 · Formula

One formula. Every venue.

NUPS doesn't hardcode driver economics. Each venue supplies its own rate card — cover amount, card discount, per-guest driver payout, any bonus tiers — and the engine computes net cash due on every scan.

The example shown uses illustrative rates. Real venues set their own numbers in configuration.

FormulaNET_DUE = (COVER − CARD_DISC) × N − PAYOUT_PER_GUEST × N ± BONUS_TIER
EXAMPLE · 4 GUESTS ARRIVED WITH DRIVER #D-2271SIMULATED
$COVER
Cover × 4
$80
base gate intake
▶minus
$PAYOUT
Driver × 4
$60
per-guest payout
▶net
NET
House Net
$20
to venue ledger
Rate CardCover, card discount, per-guest payout, and bonus tiers are all venue-configurable.
VariablesN = guest count · $COVER = gate · $PAYOUT = driver per head · tiered bonuses allowed.
SettlementNetted at scan. Cash drawer updates in real-time. Driver statement emailed via SendGrid.

Under the Hood

§ 06 · Hardware · Software · Data
01

HardwareResilient venue infrastructure with offline-assisted workflows.

  • COMPUTERaspberry Pi 500+ — BCM2712, quad A76 @ 2.4GHz, 16GB LPDDR4X, 256GB NVMe. Wi-Fi 6, BT 5.2, dual 4K micro-HDMI. ~$200 per node
  • DISPLAY15" portable touch — 1080p IPS, 10-point capacitive, USB-C powered. Guest-facing for click-wrap signing. Swappable per station
  • MOBILE · OVERSIGHTSamsung tablets with AT&T SIM — manager oversight, roaming door/floor staff terminal, LTE fallback for outages. DeX + HDMI bridge
  • CAPTUREAdesso biometric + USB mag-stripe + chip reader + barcode/QR scanner + webcam. Full edge identity capture. Plug-and-play USB
  • PRINT · SIGNEpson ET-5850 prints contract → manual wet signature → Epson WiFi PDF scanner rescans signed hardcopy back into the record. Thermal receipt printer for Register. SVC machine for GlyphBucks issuance. Print → Sign → Rescan → Sealed
  • NETWORKVenue Wi-Fi plus LTE can be deployed as redundant connectivity. Supported offline writes use a local IndexedDB queue and retry on reconnect; automatic network failover is validated per venue. Offline-assisted · not zero-downtime guaranteed
02

SoftwarePlatform Runtime

  • PLATFORMBase44 app shell — App ID 697a087fb354faebb72df54b. Multi-tenant by venue_id. REAL · DEMO · SANDBOX modes
  • AUTHAuth0 + JWT — 7-tier RBAC, MFA-enforced for Tier 00–02, venue-scoped tokens. Role expires at shift end
  • COMMSSendGrid (email: contracts, receipts, 1099s, marketing blasts) + Twilio (SMS: OTP, driver alerts, shift notifications, guest re-engagement). Templated · tracked · GDPR opt-in
  • DJ · BOOTHEntertainer DJ subsystem — self-serve login, track library, set building, saved preferences, playlist generation, queue data, personas, crowd metrics, and diagnostics. Specialist subsystem · primary-surface integration advancing
  • MARKETINGQR marketing + social automation — track-and-trace QR campaigns, automated IG/TikTok/X posts, event-driven SMS/email blasts, guest re-engagement triggers. Campaign → scan → profile match
  • PAYMENTSHybrid payment architecture — Stripe is the native rail for GlyphLock/NUPS-controlled processing, while venues can retain an existing merchant account or terminal and bind its processor reference, approval code, amount, receipt, and evidence to the same PaymentRecord model. External processors can also be integrated more deeply through API/webhooks. Process native · overlay · integrate
  • CURRENCYGlyphBucks SVC engine — a closed-loop stored-value system tied directly to verified transactions and contracts. Denominations $10–$1000 (customizable), each note carries a steganographic QR. QR = tx_id = contract_id
  • SHIELDDispute evidence continuity engine — gathers linked contract, identity, receipt, verification-media, approval, processor, consent, and audit references from the same transaction context. Automated signed-PDF compilation and direct processor submission extend that existing source layer. Evidence foundation live · automation layer advancing
  • GOVERNANCEDACO enforcement layer — immutable rules (total_sales = cash + card ONLY, 1099 isolation, tip pass-through). Code-level guards · not config
03

DataStorage · Audit · Chain

  • PRIMARYBase44 entity store is the active application data layer for NUPS entities and venue-scoped records; Supabase services and functions are present for selected external/credential and edge workloads. Authoritative model depends on the specific module
  • OFFLINE QUEUEIndexedDB — local browser queue for supported transactions during connectivity loss. Records retry on reconnect and surface sync status to the operator. Durable queue implemented · workflow coverage growing
  • MEDIASupabase Storage + CDN for DJ audio tracks, VIP video attestations, still frames, ID scans. Signed URL access only. Per-venue bucket isolation
  • AUDIT · OPSSystemAuditLog — financial + operational events. venue_id REQUIRED. Immutable append-only. Venue-scoped tenant separation
  • AUDIT · PLATAuditEvent — platform + security telemetry. venue_id optional. For GlyphLock internal forensics
  • CHAINOpenTimestamps → Bitcoin anchoring is implemented for supported sealed GlyphBucks / contract flows. Production rollout and attestation completion are tracked per record; unsupported records are not represented as anchored. Cryptographic evidence with explicit status
  • RETENTIONRetention fields and policy hooks exist across financial, consent, identity, and media records. Venue production policy must be configured to the applicable legal and processor requirements. Policy-driven retention · compliance validated separately
  • SECURITYSigning keys stay server-side, sensitive reads are role-scoped, and newer biometric evidence models favor match scores / references over raw templates. Legacy media fields still require cleanup and policy validation. Security controls implemented · formal certification separate
  • OWNERSHIPAll venue data remains tenant-scoped and encrypted. Platform-level access is limited to audit and compliance enforcement. No cross-venue reads · no platform data mining

Guest Flow — Door to VIP

§ 07 · Sequence
01

Driver Scan

Driver arrives with guests, scans personal QR. System logs guest count, runs venue rate card, computes net payout.

→ BARCODE SCANNER
02

ID Swipe

Guest swipes ID at door. NUPS creates or retrieves profile — searchable by card, name, address, QR.

→ MAG-STRIPE READER
03

Cover + Card

Door economics auto-calculated from venue rate card. Payout netted at source before cash drawer updates.

→ EXISTING TERMINAL / OPTIONAL API
04

Bar & Bottles

Register handles drinks and bottle service. Card whitelist enforced; totals balance cash + card only.

→ REGISTER TERMINAL
05

Contract Print & Sign

ET-5850 can print the VIP contract for wet signature and rescan into the record. Supported sealed flows can then be hash-linked and submitted for OpenTimestamps anchoring.

→ PRINT → SIGN → RESCAN
06

GlyphBucks Issue

Once the signed contract is scanned and sealed, SVC issues denominated GlyphBucks. QR on each note links back to tx + contract + profile.

→ SVC PRINTER

Rate Card & Operations

§ 08 · Configuration
◆ Rate Card · Per Venue

Every line configurable.

Numbers shown are illustrative defaults. Each venue supplies its own rate card during onboarding — cover, discounts, driver payout, bonus tiers, bottle pricing, tip pool split.

Line Item
Variable
Cover no card
$COVER
Card discount
$CARD_DISC
Driver payout per guest
$PAYOUT
Driver bonus tiered
$BONUS_N
Bar drink floor
$DRINK
Bottle service
$BOTTLE
Every figure set at venue onboarding
◆ PARAMETRIC
◆ Operating Controls

Built for controlled execution.

Every venue runs on a configured operating profile with defined rates, permissions, reconciliation rules, and documented financial controls.

Rate Configuration Cover, payouts, pricing, and fee logic per venue
CONFIG
Permissions Matrix Access scoped by role and operational responsibility
RBAC
Reconciliation Rules Cash, card, contracts, and audit outputs stay aligned
LEDGER

Revenue Model

§ 09 · Commercialization
Platform License
Per-venue access to the NUPS operating, identity, commerce, audit, and reporting stack
Verified Commerce
NUPS transaction / verification economics distinct from the underlying card-acquiring fee
GlyphBucks Program
Closed-loop issuance, redemption, reconciliation, verification, and configurable program economics
Enterprise + Integration
Multi-venue, API, processor, underwriting, compliance, and strategic integration opportunities

NUPS Functional Value Stack

§ 10 · 19 Operational Domains
NUPS is valuable because it consolidates functions that venues normally buy, build, reconcile, or operate separately. The stack below spans identity, workforce, access control, hardware, payments, stored value, entertainer operations, DJ, contracts, dispute defense, audit, security, multi-venue control, reporting, inventory, data, continuity, messaging, and marketing while keeping those functions attached to the same venue and transaction context.
Identity

Searchable guest profiles.

Replaces / consolidates: paper ID logs, manual dancer files, sign-in clipboards.

Mag-stripe swipe creates a searchable profile instantly. Drivers and entertainers onboard once — scan QR forever.

Clock

Biometric shift tracking.

Replaces / consolidates: punch cards, When I Work, Homebase.

Biometric-aware shift tracking and payroll calculations are implemented in software. Production biometric matching still depends on a registered physical reader and venue-by-venue hardware validation.

Roles & Access

Scoped session permissions.

Replaces / consolidates: shared logins, manager-only register terminals.

Seven top-level access tiers span Admin, Owner, Venue Manager, Staff, Entertainer, Driver, and Guest, with venue-specific operational roles such as bartender, door, hostess, security, and DJ scoped underneath the operating model. Sessions carry role and venue context so one gateway can route each user into the controls relevant to that responsibility.

Hardware

Configured hardware stack.

Replaces / consolidates: piecemeal peripherals from five vendors.

Raspberry Pi edge nodes, Samsung oversight tablets, ID / mag-stripe / biometric readers, Epson contract printing, thermal receipts, and external card terminals are supported deployment components. Physical-device interoperability is validated per installed venue rather than claimed universally certified.

Payments

Process natively or integrate the processor already in place.

Replaces / consolidates: payment software that forces a merchant-account migration or leaves processor evidence detached from the operating record.

Stripe is the native payment rail for GlyphLock/NUPS-controlled transactions. For venue-owned processing, NUPS can capture the approval code, processor reference, amount, receipt, contract, identity, and audit evidence without taking over settlement. The same adapter model also supports deeper API/webhook integrations.

Currency

GlyphBucks closed-loop SVC.

Replaces / consolidates: hand-stamped funny money, paper scrip, IOU systems.

GlyphBucks issues denominated notes ($10–$1000, customizable). QR on each note ties to contract, transaction, and user. Tracked as a liability — never commingled with sales.

Entertainer

Self-serve earnings visibility.

Replaces / consolidates: paper count sheets, "ask the manager" earnings questions.

Nightly, weekly, monthly earnings + hours. 1099-ready earnings export. Fully isolated from staff tip pool — independent contractor by design.

DJ Booth

Entertainer-run rotation.

Replaces / consolidates: DJ-controlled rotation, paper request slips, song bribes.

The DJ subsystem already supports entertainer login, track libraries, sets, preferences, playlist generation, queue data, personas, crowd metrics, and diagnostic tooling. The current consolidation step is bringing that specialist subsystem more deeply into the primary NUPS operating surface.

Compliance

Print. Sign. Rescan.

Replaces / consolidates: paper waivers, scattered consent forms.

ET-5850 prints the contract. Guest and entertainer wet-sign the hardcopy. Epson WiFi PDF scanner rescans the signed document back into the record. Chain of custody sealed end to end.

Defense

Evidence-first dispute workflow.

Replaces / consolidates: scrambling for evidence after a chargeback hits.

Linked evidence-source collection and transaction retrieval are implemented now. Automated final-PDF assembly and direct processor dispute-API submission extend that foundation into a more automated delivery workflow.

Audit

Dual-track immutable ledger.

Replaces / consolidates: spreadsheet logs, "trust me" reconciliation.

Every financial event logged to SystemAuditLog with venue scope; every platform and security event logged to AuditEvent. Regulator-ready export.

Security

MFA on every privileged action.

Replaces / consolidates: a sticky note under the keyboard.

Platform-wide MFA, JWT-signed sessions with role and tenant claims, device attestation, and session controls. Refunds, voids, role changes, and data wipes require multi-factor confirmation.

Multi-Venue

One platform, many rooms.

Replaces / consolidates: separate systems per location.

Every venue is a venue_id tenant. Separate data, separate tax, separate payouts — one pane of glass.

Reporting

End-of-night, automated.

Replaces / consolidates: end-of-night Excel templates, manual deposit slips.

Shift close, cash drawer reconciliation, daily deposit summary, and weekly P&L generated automatically. Total sales = cash + card. GlyphBucks tracked separately as liability.

Inventory

Par levels & pour tracking.

Replaces / consolidates: clipboard counts, eyeballed reorders.

Register product catalog with cost basis, par levels, and pour tracking. Bartender voids and comps logged to audit trail.

Data

Row-scoped tenant isolation.

Replaces / consolidates: single-vendor lock-in, opaque entity models.

Primary entity store with row-scoped isolation by venue_id. The current codebase contains 250+ backend functions and 160+ entity schemas under platform governance, supporting the breadth of NUPS operational modules from commerce through audit and venue workflow.

Continuity

Decoupled credential layer.

Replaces / consolidates: single-vendor lock-in on user authentication.

External Supabase credential layer holds user and client identity independently of the core platform. Credential storage and platform logic are decoupled — a foundational layer for the failover and resilience roadmap.

Messaging

Twilio + SendGrid pipeline.

Replaces / consolidates: personal cell phones for staff coordination.

OTP login, driver alerts, shift push notifications, 1099 delivery, and transactional sends via Twilio + SendGrid. Opt-in, audited, and templated at the platform layer.

Marketing

Scan-to-profile attribution.

Replaces / consolidates: tabletop QR codes that go nowhere, generic Mailchimp blasts.

Every QR scan ties back to a real guest record. Scheduled social posts across Instagram, TikTok, and X. Event-driven SMS re-engagement triggers based on visit history.

Hybrid Architecture

§ 11 · Edge + Server
Our primary technical objective is a cloud-forward NUPS architecture that can communicate with legacy venue hardware during transition—without being constrained by it. NUPS maintains operational continuity while venues migrate to secure, modern, API-capable devices; legacy equipment is replaced whenever it limits security, reliability, automation, or support.
◆ Edge · Client Layer
Raspberry Pi nodes and Samsung tablets are supported venue surfaces for identity capture, Register activity, hardware-assisted verification, and floor operations. Supported writes can queue locally when connectivity drops; some validation still requires the server.
OPERATING LAYER · OFFLINE-ASSISTED
◆ Server · Cloud Layer
System of record. Handles persistent storage, audit logging, dispute-package assembly, cross-venue orchestration, and reporting. All evidence lives here.
PERSISTENT · AUTHORITATIVE
◆ Sync Behavior
Supported offline transactions queue in IndexedDB and sync on reconnect. Server-side records become the canonical audit source after sync. The durable queue is implemented now, with additional NUPS workflows being brought under the same recovery pattern.
DURABLE QUEUE · COVERAGE GROWING BY WORKFLOW
System of record: the cloud server. The edge is the capture surface — fast, offline-capable, and authoritative only until sync. After sync, the server is the canonical ledger for audit, dispute, and reporting.

Failsafe & Resilience

§ 12 · Continuity
◆ Offline-Assisted Operation
Supported transaction writes can queue locally during an outage; server-required validation is clearly blocked rather than faked.
◆ Sync on Reconnect
Queued IndexedDB transactions are retried when connectivity returns and successful sync is surfaced to the operator.
◆ Dual-Network
Venue Wi-Fi plus LTE failover is a deployment option; automatic network failover must be validated per installed venue.
◆ Recovery Roadmap
Durable local queuing exists now; full end-to-end recovery certification across every NUPS workflow remains in expansion.

Platform Readiness

§ 13 · Capability + Deployment Map
NUPS is a broad operating platform, not a single feature pretending to be a suite. This map separates the implemented operating foundation, deployment-specific modules that require venue or hardware validation, and the payment/integration layer that can be activated without changing the underlying transaction model.
◆ Operating Platform
Implemented in the current build; venue configuration activates the applicable workflows
  • ◆ Multi-tenant platform + role-scoped access controls
  • ◆ Identity capture workflows (ID · mag-stripe · QR)
  • ◆ Register + cash drawer reconciliation
  • ◆ GlyphBucks issuance, redemption, ledger + QR verification
  • ◆ Stripe API payment verification + webhook infrastructure
  • ◆ Driver QR / payout infrastructure
  • ◆ SystemAuditLog + AuditEvent audit layers
  • ◆ Ed25519 sealing + OpenTimestamps submission for supported sealed flows
◆ Deployment-Specific + Advanced Automation
Functional modules and automation layers completed or being validated for specific hardware, venue, or processor environments
  • ◆ VIP contract workflow — venue-by-venue production validation
  • ◆ Physical biometric hardware validation + shift tracking rollout
  • ◆ Dispute evidence final-PDF compiler + one-push operator workflow
  • ◆ Direct processor dispute-API submission
  • ◆ DJ rotation integration into the primary NUPS operating surface
  • ◆ Expanded offline coverage + recovery certification
  • ◆ Multi-venue cross-reporting
◆ Payment + Integration Layer
One NUPS transaction model supports Stripe-native processing, external processor evidence capture, and deeper API/webhook adapters
  • ◆ Stripe-native processing path for GlyphLock/NUPS-controlled transactions
  • ◆ Bring-your-own processor / existing terminal evidence overlay
  • ◆ Optional native API / webhook integrations for external processors
  • ◆ Rate card (cover · payouts · bonuses)
  • ◆ Tip pool split configuration
  • ◆ GlyphBucks denominations + expiry
  • ◆ Role matrix customization
  • ◆ Video attestation capture
  • ◆ SMS / email campaign templates