Hosted Architecture
Scope of this page
Section titled “Scope of this page”This page explains the customer-visible architecture of Hosted Nostos: what kinds of systems exist, what they are responsible for, and which boundaries matter to your data.
It deliberately does not publish private operator topology, provider configuration, internal resource names, service credentials, exact database layout, deployment thresholds, or recovery runbooks. Those are implementation and operations details, not customer product contracts.
Product-level architecture
Section titled “Product-level architecture”Browser / installed PWA | vHosted Nostos application | +---- account & authentication | +---- subscription & entitlement state | +---- library / notes / concepts / writing data | +---- uploaded book and audio media | +---- managed Ask Nostos & voice | '---- backup & recoveryThe hosted service composes these managed responsibilities around the same Nostos product model and customer-facing application used by the public SelfHosted project.
Account and authentication boundary
Section titled “Account and authentication boundary”Hosted Nostos requires an authenticated account.
The browser receives the product state needed to use Nostos; private service credentials and infrastructure selectors are not part of the customer-facing contract.
Authentication identity, subscription state, and library content are separate concerns. An email address is not used as a browser-controlled selector for another customer’s library.
Subscription boundary
Section titled “Subscription boundary”Hosted product access is decided from server-side account and entitlement state.
Checkout redirects or browser return URLs are not authoritative proof that a subscription or refill has been paid. Hosted access and paid capacity change only after billing state has been verified by the service.
Billing does not live inside the library domain: payment failure, cancellation, or plan changes do not themselves delete books, notes, concepts, or writing.
Data boundary
Section titled “Data boundary”Hosted Nostos manages two broad classes of durable customer content:
- structured library information such as books, progress, notes, concepts, collections, and writing;
- uploaded media such as EPUBs, PDFs, covers, and audiobooks.
The service also keeps the minimum operational account, entitlement, recovery, and usage state needed to provide the hosted product.
See Your Data in Hosted Nostos for the user-facing data model.
Managed AI boundary
Section titled “Managed AI boundary”Hosted Nostos provides managed Ask Nostos and voice transcription without exposing provider credentials to the user.
Ask Nostos is retrieval-first: product behavior is centered on retrieving canonical Nostos material, preserving source scope and provenance, and orienting you back to the material used.
The managed-AI allowance controls usage capacity. It is not a switch between different reasoning modes.
See Ask Nostos & Voice.
Backup and recovery boundary
Section titled “Backup and recovery boundary”Hosted Nostos includes automated daily backups and a managed recovery process.
Recovery exists to restore the hosted service. Portable export exists so the customer can keep and move an independent copy of supported library data.
The public contract does not depend on a particular infrastructure provider or expose the operator procedure used to perform a restore.
SelfHosted comparison
Section titled “SelfHosted comparison”SelfHosted Nostos replaces these managed hosted responsibilities with infrastructure controlled by the operator:
- local SQLite instead of hosted relational storage;
- a local persistent data volume for media and backups;
- no hosted account or subscription requirement;
- operator-configured AI services when AI features are used.
The product and portability model remain shared between deployment modes.