Platform Architecture
Stack9 Experience Platform Architecture delivers enterprise-grade infrastructure with multi-tenant isolation, comprehensive data management, and API-first design. Built on AWS with modern cloud-native principles, it provides the scalable foundation that powers all DXP capabilities while ensuring security, compliance, and operational excellence.
What is Platform Architecture?
Stack9's Platform Architecture provides three foundational systems that enable enterprise-scale digital experiences:
- ✅ Multi-tenancy - Complete tenant isolation with per-tenant resource provisioning and scaling
- ✅ API-First Design - RESTful architecture with OpenAPI specifications and consistent patterns
- ✅ Data Management - Entity versioning, audit trails, and comprehensive compliance support
This enterprise-grade foundation ensures Stack9 Experience can support organizations from startup to global enterprise scale while maintaining security, performance, and compliance requirements.
Multi-tenancy
Enterprise-Grade Tenant Isolation
Complete data separation ensures each tenant operates as if they have their own dedicated platform:
- Data isolation - Zero data sharing between tenants
- Resource separation - Dedicated infrastructure components per tenant
- Security boundaries - Complete access control and permission isolation
- Performance isolation - One tenant's usage doesn't affect others
This architecture enables multiple organizations, brands, or business units to share the same platform infrastructure while maintaining complete independence and security.
Per-Tenant Resource Provisioning
Dedicated infrastructure for each tenant ensures optimal performance:
OpenSearch Indices:
- Separate search indices for each tenant's content and data
- Independent scaling based on tenant usage patterns
- Isolated search performance and relevance tuning
- Tenant-specific index configurations and mappings
Storage Resources:
- Dedicated file storage for attachments and media
- Isolated backup and recovery procedures
- Tenant-specific retention policies
- Secure asset delivery with presigned URLs
Webhook Endpoints:
- Individual webhook configurations per tenant
- Isolated event processing and delivery
- Tenant-specific integration patterns
- Independent monitoring and error handling
Tenant Provisioning and Bootstrapping
Automated tenant setup ensures consistent, reliable onboarding:
Bootstrap Process:
- Tenant creation - Establish unique tenant identifier and configuration
- Resource provisioning - Create OpenSearch indices, storage buckets, and webhooks
- Configuration setup - Initialize email settings, sender identities, and preferences
- Validation testing - Verify all systems are operational before activation
Configuration Management:
- Default settings - Pre-configured sensible defaults for immediate use
- Custom configurations - Adapt settings to specific tenant requirements
- Environment separation - Separate development, staging, and production configurations
- Rollback capabilities - Restore previous configurations if needed
Scalable Infrastructure and Independent Scaling
Cloud-native architecture enables elastic scaling per tenant:
- Auto-scaling groups - Infrastructure adapts to tenant usage automatically
- Load balancing - Distribute traffic efficiently across resources
- Geographic distribution - Deploy closer to tenant users for better performance
- Resource optimization - Right-size infrastructure based on actual usage patterns
API Reference: Multi-tenant management uses /admin/tenants, /admin/tenant/{tenant_code}/setup, and tenant administration endpoints with comprehensive tenant lifecycle management and resource provisioning.
API-First Design
RESTful Architecture and Consistent Patterns
Modern API design ensures predictable, developer-friendly integration:
RESTful Principles:
- Resource-based URLs -
/campaigns,/subscribers,/email_templates - HTTP verbs - GET for retrieval, POST for creation, PUT for updates, DELETE for removal
- Status codes - Proper HTTP status codes for all responses
- Stateless operations - Each request contains all necessary information
Consistent Patterns:
- Bulk operations -
/listendpoints for retrieving multiple items - Search functionality - POST requests for complex search queries
- Hierarchical relationships -
/campaigns/{code}/emailsfor related resources - Version tracking - All entities include version numbers for optimistic locking
OpenAPI 3.0 Specifications
Complete API documentation enables rapid integration:
{
"openapi": "3.0.3",
"info": {
"title": "Stack9 Experience API",
"description": "Stack9 Content, Marketing and AI services",
"version": "1.7.4.1-c838b60"
}
}
Documentation Features:
- Complete schemas - Full object definitions with properties and validation rules
- Example requests - Working examples for all endpoints
- Response formats - Detailed response structures and error handling
- Authentication - Clear security requirements and implementation guidance
JSON Request/Response Format
Modern data interchange with consistent JSON formatting:
- Camel case properties - JavaScript-friendly naming conventions
- Nested objects - Complex data structures as needed
- Array handling - Consistent list formatting and pagination
- Type safety - Clear data types and validation rules
Multi-tenant Aware Endpoints
Tenant context automatically handled in all API operations:
- Automatic tenant resolution - API key determines tenant context
- Data scoping - All operations automatically scoped to correct tenant
- Permission enforcement - Tenant-specific access controls applied
- Resource isolation - No cross-tenant data access possible
API Reference: The complete Stack9 Experience API provides 100+ endpoints across admin, content, marketing, email, AI, and analytics capabilities as documented in the comprehensive OpenAPI specification.
Data Management
Entity Versioning and Change Tracking
Comprehensive versioning provides complete audit trails for all data:
Version Management:
- Automatic versioning - Every entity update increments version number
- Version history - Complete timeline of all changes
- Point-in-time recovery - Restore any entity to previous state
- Change attribution - Track who made what changes when
Supported Entities:
- Email templates and snippets
- Marketing campaigns and emails
- Subscriber profiles and preferences
- Form configurations and submissions
- AI assistants and vector indexes
- All content and configuration data
Audit Trail Capabilities
Complete compliance support through comprehensive logging:
Audit Information:
- User attribution - Who made each change
- Timestamp tracking - When changes occurred with sub-second precision
- Change details - What specific fields were modified
- System context - API calls, user interfaces, or automated processes
Audit Use Cases:
- Audit evidence - Record-level versioning plus AWS CloudTrail provide the change history an audit requires. Note that GDPR-aligned data handling is implemented per engagement rather than enabled by default, and there is no purpose-built tooling today for privacy incident investigation, evidentiary reporting or chain-of-custody handling
- Security investigation - Track potential security issues or breaches
- Performance analysis - Understand how data changes affect system performance
- Quality assurance - Verify changes match intended modifications
Deleted Records and Data Recovery
Soft delete architecture enables data recovery and compliance:
Deletion Handling:
- Soft deletes - Records marked as deleted but not physically removed
- Recovery capabilities - Restore accidentally deleted data
- Compliance support - Meet data retention requirements while enabling recovery
- Cleanup processes - Automated hard deletion after retention periods
Recovery Features:
- Point-in-time recovery - Restore data as it existed at specific times
- Selective recovery - Restore individual records or bulk data sets
- Version restoration - Roll back to previous versions of existing records
- Cross-reference maintenance - Ensure data integrity during recovery operations
Data Lifecycle Management
Automated data governance ensures optimal storage and compliance:
Retention Policies:
- Configurable retention - Set data retention periods per entity type
- Automated cleanup - Remove data after retention periods expire
- Compliance alignment - Meet regulatory requirements for data retention
- Storage optimization - Balance compliance needs with storage costs
Data Archival:
- Long-term storage - Move old data to cost-effective archival storage
- Query capabilities - Search archived data when needed
- Restoration processes - Bring archived data back to active storage
- Compliance reporting - Generate reports on data lifecycle compliance
API Reference: Data management uses /entity/versions, /entity/versions/{version}, /entity/deleted-records, and administrative endpoints providing comprehensive versioning, audit, and recovery capabilities.
Why Choose Stack9 Platform Architecture?
Enterprise-Ready from Day One
Traditional platforms often struggle with enterprise requirements:
Basic Platform + Enterprise Bolt-ons = Complex, Fragile Architecture
Stack9 provides enterprise architecture natively:
Enterprise-Native Platform = Scalable, Secure, Compliant Foundation
Operational Excellence
- High availability - Redundant infrastructure with automatic failover
- Disaster recovery - Multi-region backup and recovery capabilities
- Performance monitoring - Real-time system health and performance metrics
- Automated scaling - Infrastructure adapts to load automatically
Security and Compliance
- Multi-layer security - Defense in depth with multiple security controls
- Data encryption - At rest and in transit encryption for all data
- Access controls - Fine-grained permissions and role-based access
- Certifications - April9 holds ISO 27001 (5+ years), with ISO 9001 in progress (targeted Q1 2027). SOC 2 is not held and is not being pursued. GDPR-aligned data handling is not a default platform setting, but can be implemented on web portals where an engagement requires it
- Engagement-level credentials - The Comcover engagement is delivered and operates under IRAP certification; the Surf Life Saving platform is PCI DSS-compliant for payment card handling. These apply to those engagements, not to Stack9 as a product certification
Developer Experience
- Comprehensive documentation - Complete API specs with examples
- SDK availability - Client libraries for popular programming languages
- Testing environments - Separate sandbox for development and testing
- Integration support - Technical assistance and best practice guidance
In Production
Comcover (Australian Government Department of Finance) runs Launchpad on this architecture: a single sign-on dashboard serving 168 separate Commonwealth entities from one platform, with role-based access scoping each entity to its own applications and data. It has been in production for over four years, integrates with Power BI reporting and MS Dynamics CRM, and is delivered and operated under IRAP certification.
Eagers Automotive runs a 450+ dealership site network on the same architecture, absorbing up to 20x Saturday transaction spikes through autoscaling — containers moving from 5 to 35 units and the database to 300% of baseline, with no manual intervention and no pre-provisioned peak capacity idling for the rest of the week.
Surf Life Saving Australia demonstrates the other transaction pattern: sustained queue-based processing, where a monthly payment cycle generates tens of thousands of queued messages and hours of continuous load, with autoscaling responding to queue depth throughout.
These are recurring production patterns rather than synthetic load tests. Note that they are commercial and government-portal workloads — they are not insurance-scheme claims volume benchmarks.
Data residency
All data stays inside Australian AWS regions: ap-southeast-2 (Sydney) for production, metadata, logs and AI processing, and ap-southeast-4 (Melbourne) for backups and disaster recovery replication. Support is delivered by a fully onshore Australian team.
Best Practices
Multi-tenant Management
- Plan tenant structure - Design tenant hierarchy for organizational needs
- Monitor resource usage - Track utilization and optimize accordingly
- Implement governance - Establish policies for tenant creation and management
- Test tenant isolation - Verify complete data separation regularly
API Integration
- Use API keys securely - Implement proper key management and rotation
- Handle errors gracefully - Implement retry logic and error handling
- Follow rate limits - Respect API limits to ensure consistent performance
- Version API usage - Plan for API evolution and version changes
Data Management
- Plan retention policies - Balance compliance requirements with storage costs
- Monitor audit logs - Regular review of system access and changes
- Test recovery procedures - Regularly validate backup and recovery processes
- Document data flows - Maintain clear documentation of data processing
Next Steps
Ready to leverage platform architecture? Explore:
- Getting Started Guide - Learn how to begin using Stack9 Experience
- API Reference - Dive into detailed API documentation
- Implementation guides for specific capabilities and use cases
Stack9 Platform Architecture provides the enterprise-grade foundation that enables scalable, secure, and compliant digital experiences - ensuring your marketing technology investment grows with your organization while maintaining operational excellence.