What Is a Point of Interaction?
A Point of Interaction (POI) is the place where the physical world meets the digital – a smart kiosk, ATM, automated LockerSHOP, drive-through, merchant terminal or community hub. The boundary itself. The slice of the network where citizens, merchants, agents and devices actually do something with real consequence – prove identity, move money, exchange data, give consent, receive a service.
Post-digital, everything else commoditises. Cloud is a tap. Models are commoditising. Compute is rented by the second. What does not commoditise is the seamless fusion of physical and digital at the moment of action. onePOI.online owns that boundary – and turns it from a single-purpose device into a governed substrate for Identity, Payment, Data Exchange and Governance.
Where legacy devices serve a single function for a single owner, a governed POI Appliance serves multiple tenants simultaneously – like an airport terminal serving multiple airlines – with cryptographic isolation between each, and a Constitutional OS enforcing every transaction. Financial-grade peripherals, edge compute, storage and network appliances take on whatever form factor the citizen needs.
The platform closes the Governance Gap between written policy and the operational reality of agentic commerce – bridging physical and digital with every touchpoint a governed, auditable, sovereign act.
The POI family spans twelve physical form factors: remote teller/ATM, drive-through, branch and civic assist, phygital POS, identity onboarding, transit hub, healthcare dispensary, hospitality concierge, universal accessibility terminal, CommunityHUB/3PL, and mobile incident service units. One shared constitutional substrate; many physical shapes to meet citizens where they already live, work, and engage.
Engineered for Institutional Margins.
Adopted for Human Sovereignty.
Every capability across the Salient Innovation Set delivers an immediate, symmetrical return: radical margin recovery for the enterprise tenant, paired with frictionless dignity and absolute cryptographic safety for the citizen.
How the Tenant Expands Margins
Transforming operating models from defensive cost centres into agile, shared revenue engines through multi-tenant pooling and mathematical compliance.
-
CapEx Pooling & No Single-Tenant Hardware
POI Appliances run white-label on co-funded premises. Reach 50 commercial catchments without funding 50 proprietary branch builds.
-
Zero Interchange & Flat-Fee Clearing
Instant Account-to-Account rails (SEPA Instant / PayShap) bypass 1.5–3.5% card scheme tolls with predictable, flat sub-cent clearing fees.
-
Compliance by Construction
Agreement DAGs enforce statutory mandates at wire speed; non-compliant states cannot execute, eliminating retrospective audit penalties.
-
Accelerated Partner Onboarding
Pre-verified BIAN and ArchiMate capability components compress multi-firm integration cycles from quarters to days.
Why the Customer Loves Using It
Delivering sovereign dignity and verifiable security where users never surrender control over their identity, consent, or funds.
-
Nothing Stored to Steal
Credentials remain in the user's oneWallet. A breach of a merchant's server reveals zero identity records, protecting citizens completely.
-
One Pattern, Everywhere
The same intuitive tap-and-confirm interaction works seamlessly at a high-street kiosk, transit hub, EV charger, or smartphone.
-
Delegated Authority, Never Escalated
Autonomous AI agents carry single-use, bounded warrants; an agent checking information cannot escalate its authority to transfer money.
-
Payments That Do Not Fail
When a payment network degrades, the transaction reroutes with authentication preserved – zero declines, zero repeated entries.
Scale Without Consolidation: A Sovereign Shared Infrastructure Model
Shared infrastructure is useful only when shared authority is unnecessary. The onePOI.online framework pools physical premises, high-assurance silicon, and secure logistics across urban, peri-urban, and rural service catchments – while preserving the absolute legal, data, and regulatory sovereignty of every participating credit institution, merchant, and public agency.
Pool What Is Expensive
Physical real estate, power, fibre connectivity, tamper-resistant enclosures, cash recycling modules, and high-assurance compute are shared as common utilities across multiple commercial and civic tenants.
Preserve What Is Sovereign
No shared database, no pooled customer records, and no blended liability. Each tenant maintains its own cryptographic roots, active Agreement DAGs, audit trails, and regulated decision-making rights.
Move Intelligence to the Edge
Sensory capture, computer vision, and local AI inference execute at the physical point of interaction – yet authority remains strictly bounded by deterministic deontic policy (F > O > P).
Seven Ranked Foundational Innovations
Ranked strictly by how foundational they are to the sovereign ecosystem – where each capability is a mathematical consequence of the layer beneath it.
The Foundational Authority & Execution Hierarchy
Authority in Agreement
Agreement authorises role; role carries zero ambient power.
Insurability by Design
Unlawful execution unavailable; loss is bounded for underwriters.
Agent Liability
On-behalf-of delegation tokens signed by human principals.
Counter Resilience
Pre-execution adjudication in power cuts & network partitions.
Many Tenants, 1 Node
Shared capex with isolated TEE hardware enclaves.
Flat Clearing Fee
Direct A2A bank rails replacing credit card interchange tax.
Sovereign Wallet
oneWallet mints micro-claims and active delegation envelopes.
Authority Lives in the Agreement
Authority lives in the agreement, not in the identity. Every other system treats “who you are” as carrying permission. onePOI treats the bilateral agreement as the only source of authority: role granted → agreement authorises role → agreement decides case → cryptographic record proves execution.
Tenant: Compliance leaves the transaction path entirely – authority check is the transaction.
Customer: Nobody acts on you without a verifiable agreement mandate you can see.
Unlawful Execution is Unavailable
Unlawful execution is a state the platform cannot enter. Not detected late, not remediated, not subject to regulatory fines – unavailable. The commercial reality is insurability. Pre-execution adjudication by construction creates the bounded-loss conditions underwriters require.
Tenant: High-stakes agentic workflows become formally underwriteable.
Customer: Your rights cannot be breached by model hallucination or runtime glitch.
Constitutional Delegation & Agent Liability
Autonomous AI models act without ambient privileges. Agents carry signed On-Behalf-Of (OBO) delegation tokens minted by legal principals, with single-action expiry and pre-ruling GateKeeper verification.
Tenant: Zero ambient exposure; full legal attribution for every automated action.
Customer: Agents can never exceed their explicit, delegated brief.
Lawful Execution at the Counter
Pre-execution adjudication runs locally on the POI appliance hardware at the physical edge. The platform settles and validates transactions during power cuts and broadband partitions without cloud backhaul.
Tenant: Unbroken business continuity at the physical point of interaction.
Customer: Essential civic and retail services function even in network blackouts.
Many Tenants, One Appliance
Multiple competing banks, retailers, healthcare providers, and civic authorities run on a single physical POI node. Hardware-isolated TEE enclaves eliminate cross-contamination and slash hardware deployment capex.
Tenant: Radically lower capital expenditure through shared, sovereign infrastructure.
Customer: Single consolidated physical touchpoint for all essential services.
Flat Clearing & Sovereign Wallet
Mathematical certainty allows direct A2A / SEPA Instant clearing at a predictable flat target clearing fee (near-term target state architecture, Q4 2026 / 2027 roadmap). oneWallet serves as the cryptographic root of authority projecting micro-claims.
Tenant: Replaces 1.5–3.5% interchange drag; zero toxic credential storage liability.
Customer: Direct instant settlement with complete cryptographic data sovereignty.
Replay as a Product, Not a Log
Re-run any decision exactly as it was made, against the precise version of the rule in force at that exact millisecond, transforming regulatory audits into deterministic verifications.
Switcher+ & Entitlement Continuity
Entitlements and historical trust credit travel seamlessly with the citizen under citizen-held agreements, regardless of backend service provider switches.
Institutional Standards Crosswalk
Direct canonical mapping onto BIAN (Banking Industry Architecture Network) Service Domains and ArchiMate layers, enabling frictionless enterprise adoption.
How the Lead Architects View the Moat
We asked top FSI architects, frontier AI safety leads, and forward-deployed engineers to dissect the platform. Here is the big deal from their respective vantage points.
Tier 1 FSI Enterprise Architect
"Transforms our operational risk posture by replacing passive auditing with active, hardware-level policy enforcement. By segregating edge applications in secure enclaves and compiling compliance rules into digital contracts, we guarantee transaction compliance at the point of action. This structural mitigation helps justify reduced regulatory capital requirements."
Frontier AI Lead Architect
"Solves the unconstrained agent problem. AI models cannot run amok because their Action Space is bounded at the runtime gate by the neuro-symbolic Guardian. If the payload doesn't fit the active Agreement DAG, the transaction receives a Structural VETO."
Forward Deployed Engineer
"Predictability is the killer feature. We compile policy to eBPF bytecode verified by Actuator DAGs on eBPF kernel filters. Secure secrets never sit in memory; Threshold Cryptography (MPC) makes key extraction physically impossible."
The Phygital Fabric – Appliance to Platform
Financial-grade peripherals, devices, edge compute, storage and network appliances – many form factors, one constitutionally governed substrate. Virtualises hardware resources into isolated TEE Hardware-Isolated Enclaves using TEE-backed security boundaries and DToP signing keys, allowing Anchors, Deployers, and Tenants to operate simultaneously with financial-grade isolation and six-nines availability.
Three Tiers. One Substrate.
The platform separates ownership from operation from tenancy – a layered trust model that lets multiple parties share the same physical infrastructure without sharing risk, liability or data.
- Anchors own and provision the physical infrastructure – the appliances, network fabric and edge compute. They set the constitutional rails everything else runs on.
- Deployers operate brands, merchant networks or service channels on top of Anchor infrastructure – with full independence and cryptographic isolation from every other Deployer on the same hardware.
- Tenants plug services into a Deployer's channel – a bank embedding into a retailer's terminal, or a government scheme riding a telco's kiosk network – without any infrastructure investment of their own.
The result: infrastructure unit economics that no single-tenant model can match, with governance that no multi-cloud architecture can enforce. Every layer is contractually and cryptographically bounded – the Constitutional OS makes cross-tier liability unambiguous before a transaction ever fires.
Three-tier model: Anchors provision infrastructure, Deployers operate channels, Tenants embed services – all on one constitutionally governed substrate with financial-grade isolation.
The Symphony of Systems
Six governed system layers performing on one non-negotiable foundation. In practice, this loop executes when a citizen uses their phone's EUDI wallet to securely unlock a click-and-collect parcel at a 3PL locker, or when a merchant deploys a new loyalty application across legacy terminals instantly – completely bypassing the typical 9-month PCI recertification window.
The Symphony of Systems (SoE, SoA, SoO, SoR, SoI, TRS-MS). Orchestrates human-assisted and digital journeys across physical touchpoints while keeping authority institutionally sovereign.
Local AI acceleration, seL4 microkernel enclaves, and TEE silicon. Workloads are placed dynamically across the device, edge node, and cloud based on latency, confidentiality, and jurisdiction.
Bitemporal verification, verifiable cryptographic lineage, and purpose-bound value settlement. Shares governed data products, never unrestricted raw copies.
System of Engagement
The phygital front door. Omni-channel POI Appliances and universal hubs connecting citizens to governed services.
System of Agreement
Agreement DAGs as machine-executable digital contracts. Every LAHE captured and substantiated across all channels.
System of Orchestration
Governed execution – policy authored in SoA, enacted by agents across services with Constitutional OS constraints at every step.
System of Record
Immutable, ISO 20022-aligned ledger. Every agreement, act, and outcome stored as a sovereign-grade MVEB.
System of Intelligence
The intelligence and learning layer. SBOM, MBOM, DBOM, HBOM – AI models, data products, and hardware governed, registered, and traded through the xBOM Marketplace with Governance-as-a-Service embedded throughout.
Trust, Risk & Security Management System
The bedrock foundation the five layers perform on. Governs cryptographic key management, hardware-isolated memory apartments, and platform-wide emergency halts.
Platform Architecture & Verification
Explore the platform-wide integration layers, physical silicon enclaves, and the formal mathematical proofs validating the onePOI.online substrate.
The Unified Front Door for Digital and Physical Interaction
onePOI.online is a unified platform that connects physical locations – like smart kiosks, local LockerSHOPs, ATMs, and community hubs – with secure digital services. It ensures that everyone, from tech-savvy individuals using mobile wallets to elderly citizens who prefer physical interactions, can access identity verification, payments, and public services safely and easily. All operations are governed automatically, so systems are reliable, protect user privacy, and verify compliance before actions execute. Note: while the system guarantees execution of the law exactly as written, it does not judge whether the law itself is good – that remains a human responsibility.
Regulatory-Grade Omni-Channel Execution & Pooled-Infrastructure ROI
onePOI.online bridges compliance and commercial viability by serving as a multi-tenant pooled infrastructure. This pooled model distributes capital expenditure (CapEx) across multiple financial institutions (FSIs) and public sector operators, reducing individual deployment overhead by up to 80% while preserving absolute cryptographic tenant isolation. Built-in compliance with PSD3 open API directives, eIDAS 2.0 European Digital Identity Wallets, and DORA resilience frameworks guarantees high-assurance transaction lifecycle management, delivering forensic, fully attributable evidence trails that are impossible to hide. Downstream AI agents operate under a hard mathematical leash, executing actions strictly on-behalf-of (OBO) legal principals via rules flowcharts (which we call Agreement Directed Acyclic Graphs, or Agreement DAGs) within hardware execution bounds.
Compliance Frameworks
Native compliance logic alignment mapping to PSD3, eIDAS 2.0, and DORA resilience guidelines.
Commercial Pooled ROI
Shared physical infrastructure distribution model reducing CapEx overhead by up to 80%.
Architectural Integration (Symphony of Systems)
The onePOI.online platform operates as a unified phygital fabric for Identity, Payment, Data, and Governance by orchestrating flows across the six layers of the Symphony of Systems (SoS). When a user or agent initiates an action at a physical or digital terminal (System of Engagement, SoE), it triggers the active Agreement DAG (System of Agreement, SoA) to fetch its corresponding Policy Hash and deontic rules from the KnowledgeHUB (System of Intelligence, SoI). The execution is subsequently bound by constraints compiled into kernel-space by the Constitutional OS (System of Orchestration, SoO) and anchored upon the bedrock Trust, Risk & Security Management System (TRS-MS). Upon validation, the final act is committed to the Bitemporal Ledger (System of Record, SoR) as an immutable Minimum Viable Evidence Bundle (MVEB). This completes a closed-loop governance cycle where every touchpoint is a sovereign, lawful, and auditable act.
1. Engagement (SoE)
Captures intent at the phygital boundary (e.g., biometrics, cards, OBO tokens) and binds it to a secure local interaction session.
2. Agreement (SoA)
Maps intent to active digital contracts and legal rules represented as executable Agreement Directed Acyclic Graphs (ADAGs).
3. Orchestration (SoO)
Enforces policy bytecode directly in kernel space via eBPF filters and hardware enclaves, preventing non-compliant actions.
4. Record (SoR)
Commits transactions to an ISO 20022-compliant ledger, securing the output as an immutable evidence bundle (MVEB).
5. Intelligence (SoI)
Performs real-time trust decay calculations, continuous risk assessment, and evaluates policy updates using xBOM graphs.
6. Security (TRS-MS)
Enforces hardware-isolated memory enclaves, zero-trust cryptographic attestations, and systemic kill-switches.
Deep Technical Specifications (Enclaves, eBPF & Triadic Adjudication)
At the execution layer, onePOI.online guarantees security and low latency through a hardware-isolated confidential compute runtime, kernel-space packet filtering, and a three-tiered adjudication workflow.
1. Memory Isolation & Enclaves
Tenant application code is partitioned into hardware-encrypted RAM segments via Intel TDX (Trust Domain Extensions) and Arm CCA (Confidential Compute Architecture). This creates secure TEE Hardware-Isolated Enclaves where memory pages are completely invisible to host operating systems, hypervisors, and adjacent containers, eliminating side-channel leakage risk in multi-tenant environments.
2. Compile-to-eBPF Bytecode Flow
Agreement DAG policies are compiled directly into native kernel-space bytecode using LLVM/Clang. The compiled bytecode is injected as eBPF (Extended Berkeley Packet Filter) programmes into the Linux network interface. High-speed lookup tables in memory-mapped eBPF Maps verify compliance rules at the network boundary, ensuring all transactions obey platform invariants in < 5ms (target metric under near-term target architecture, Q4 2026 / 2027 roadmap).
3. DRAGON Triadic Adjudication
Every interaction is processed through a three-tiered evaluation pipeline:
- Syntactic Tier: Wire-speed format verification and schema sanity checks performed in eBPF/eBPF kernel space.
- Semantic Tier: Validates relationship paths, role attributes, and bitemporal constraints in the Policy Knowledge Graph (PKG).
- Pragmatic Tier: Verifies principal consent, intent signatures, and jurisdictional boundaries within TEE enclaves.
Mathematical Verification & Compliance Proofs
The correctness of our transaction lifecycle is mathematically proven. Every compliance rule and security check compiles into formal logic constraints, guaranteeing that policy violations are blocked at the runtime gate before execution.
Salient FinTech Innovation Set
The Sovereign Trust Engine at the Core
The overarching framework is the Salient Innovation Set. At its foundational core lies the Salient FinTech Innovation Set. Every phygital, civic, healthcare, retail, or agentic interaction ultimately resolves into a lawful value exchange, identity binding, cryptographic settlement, or fiduciary obligation; therefore, the FinTech innovation set (BIAN bare-metal execution, real-time A2A rails, SEPA Instant, Token Gantry, bitemporal ledgers) provides the non-negotiable trust engine that makes the entire sovereign ecosystem viable for all incoming Tenant Cohorts.
Rather than relying on closed proprietary payment networks with high toll extraction, the FinTech core executes bare-metal BIAN v14.0 Process Boundary Components, connects to direct account-to-account settlement rails, shreds plaintext credentials via Token Gantry, and preserves bitemporal evidence bundles that guarantee dispute-immune auditability.
BIAN v14.0 POS PBCs
Bare-metal Point-of-Sale Process Boundary Components. No proprietary POS middleware. No PCI-DSS scope creep.
Real-Time A2A Rails
PayShap and SEPA Instant Account-to-Account settlement. Target <500ms finality. Zero interchange toll.
Token Gantry Identity
Card PANs replaced by cryptographic commitment tokens. Zero plaintext PII retained at any POI node.
Bitemporal Ledgers
Every transaction recorded in transaction-time and valid-time. Satisfies statutory dispute and audit timelines natively.
Target State Architecture
Target State Metric Mandate (Q4 2026 / 2027 Roadmap)
All figures below are target metrics of the near-term target state architecture (Q4 2026 / 2027 roadmap). These are not current operational metrics. Performance targets will be parameterised and deployed exclusively by Tenant Cohorts in play.
| Architectural Dimension | Target Value (Target State Architecture) | Roadmap Milestone | Architecture Lever |
|---|---|---|---|
| A2A Direct Settlement Finality | <500ms | Q4 2026 Roadmap | PayShap & SEPA Instant Direct Bank Rails |
| Interchange Fee Drag per Transaction | Zero (Flat Target Clearing Fee) | Q4 2026 Roadmap | Non-card account-to-account payment architecture |
| Edge Policy Enforcement Latency | <45µs (PNAC Wire-Speed) | Q4 2026 Roadmap | eBPF / XDP Deontic Kernel Filters (DRAGON) |
| Plaintext PII / PAN Retained at POI | Zero Bytes | Q4 2026 Roadmap | Token Gantry Cryptographic Commitment Tokens |
| POI Node Availability | 99.999% | 2027 Roadmap | Isomorphic Stanzas (Offline-First Edge Execution) |
| Multi-Tenant Hardware Isolation | 100% Cryptographic Isolation | Q4 2026 Roadmap | TEE Hardware Apartments on Pooled POI Nodes |
| Bitemporal Audit Assembly (MVEB) | <200ms Automated Proof | Q4 2026 Roadmap | Transaction-Time / Valid-Time Hypergraph Ledger |
Ready to Find Your Place in the Phygital Network?
The Architectural Discovery Sprint is a low-risk, 4-week engagement for potential tenant anchors. For a fixed fee of €2,500*, we map your legacy hardware topology, define your domain-specific governance axioms, and deliver a containerised proof-of-concept.