Orithos is built on a modern stack: Next.js on Vercel, FastAPI on Railway, ARQ workers with Redis, and PostgreSQL for storage.
The user creates a scan via the dashboard or API. The API enqueues a job in Redis. The ARQ worker picks up the job, executes probes against the agent endpoint, sends responses to the LLM evaluator, persists findings to PostgreSQL, and updates the scan status. The frontend polls the API for real-time progress.
Proxy-to-backend requests are authenticated using an internal API key shared between the Next.js frontend and FastAPI backend. This key is set via the INTERNAL_API_KEY environment variable and validated on every proxied request. User API keys are never exposed to the frontend.