The platform uses FastAPI, Pydantic, local JWT validation, deterministic repositories and a layered security package. Security workflows are implemented through pinned Make targets, Python evidence generators, scanner wrappers, JSON manifests and Markdown reports.
The strongest technical pattern is evidence continuity: source scanner outputs flow into normalised findings, release gates, lifecycle records, consolidated evidence, integration export and final portfolio readiness.