This describes properties of the architecture: what is separated from what, what is encrypted, what a given component is able to read, and what the system cannot do even if someone asked it to. Those are the parts worth trusting, and the parts that are checkable.
It does not describe deployed resources — no infrastructure identifiers, no internal endpoints, no data-store or queue names, no configuration keys. Publishing those would map an attack surface without making a single claim here more credible. If a detail would help an attacker more than it would help you evaluate us, it is not on this page.
Every claim below is a property of how the system is built, not a policy we promise to follow. The distinction matters: a policy can be changed in an afternoon.