Charon — High-Level Architecture
Authors: Vergel Esteban & Robert Evans
Version: 1.0 | December 2025
1. Overview
Charon is a travel companion platform that connects passengers with drivers already commuting along the same corridor. Unlike traditional ride-hailing (which adds cars), Charon fills empty seats—reducing congestion, emissions, and commute costs.
2. System Components
2.1 Client Applications
| Mobile | React Native + Expo | Passenger & Driver apps (iOS/Android) |
| Web | React + Vite + TypeScript | Passenger booking, Driver publishing |
| Employer Portal | React (shared components) | Cohort management, mobility credits |
| Ops Dashboard | React + Admin SDK | Micro-stop curation, incident handling |
2.2 API Layer
| Component | Technology | Purpose |
| API Gateway | Cloudflare Workers / Hono | Edge routing, rate limiting, geo-routing |
| REST API | Hono (Workers) or Express (fallback) | Core business logic endpoints |
| WebSocket | Durable Objects / Pusher | Real-time trip tracking, chat |
2.3 Core Services
- Matching Engine — Corridor matching, time-band alignment, detour budget
- Trip Service — Trip CRUD, booking flow, state machine, backup assign
- Fare Engine — Flag-down, per-km/min, surge/peak, audit logs
- Micro-stop Service — Curb curation, capacity mgmt, auto-switch, safety scores
- Safety Service — SOS pipeline, KYC verify, BLE/QR verify, deviation detection
- Payments — Hold/capture, splits, refunds, credits
2.4 Data Layer
| Primary DB | PostgreSQL + PostGIS | Relational data, geo-queries, corridors |
| Cache | Redis / Upstash | Session, rate limits, hot data |
| Edge KV | Cloudflare KV | Config, micro-stop cache, feature flags |
| Blob Storage | R2 / S3 | KYC docs, receipts, audit exports |
| Analytics | ClickHouse / BigQuery | Dashboards, ML training data |
3. Data Model (Core Entities)
Passengers
- id, name, phone, kyc_status, cohorts[]
Drivers
- id, name, license, vehicle, route_id, seats, detour_budget
Corridors
- id, name, cells[], time_bands, ev_ready
MicroStops
- id, corridor, gps, capacity, safety_score, schedule
Trips
- id, driver, corridor, stops[], depart_time, state
Bookings
- id, trip_id, passenger_id, pickup, status, payment
Fares
- trip_id, flag_down, per_km, per_min, fixed_fee, total
Incidents
- id, trip_id, type, severity, outcome, resolved
4. Key Flows
4.1 Passenger Booking Flow
Select Corridor & Time Band
View Drivers & Fares
Get Assigned MicroStop & Slot
Walk to Pickup
Board & Confirm (BLE/QR)
Trip Started → Payment Captured
4.2 Driver Publish & Pickup Flow
Publish Route & Seats
Receive Pickup Suggestions
Accept Pickup (within detour budget)
Arrive & Verify Passenger
Complete Trip & Receive Payout
5. Infrastructure & Hosting
| Edge Compute | Cloudflare Workers | Global edge, low latency, auto-scaling |
| CDN/Static | Cloudflare Pages | Web app, fast deploys, preview branches |
| Primary DB | Neon (Postgres) | Serverless Postgres + PostGIS, branching |
| Realtime | Durable Objects + WebSocket | Stateful connections at edge |
| Cache | Upstash Redis | Serverless Redis, global replication |
| Blob | Cloudflare R2 | Zero-egress storage for docs/receipts |
| Auth | Clerk | Managed auth, number masking, mobile SDK |
| Payments | PayMongo / Stripe Connect | Local + global payment rails |
| Maps | Mapbox | Routing, ETA, corridor visualization |
| Monitoring | Sentry + Axiom | Error tracking, structured logs |
6. Security Architecture
Authentication & Authorization
- Gov't ID scan + selfie match (KYC)
- Proxy phone numbers (number masking)
- TLS 1.3 everywhere, encryption at rest
Trust & Safety
- BLE/QR "right car" handshake
- Route deviation & dwell detection
- Geofenced risk nudges
- Immutable audit logs
7. API Design
Core Events
- booking.created, booking.assigned
- driver.arrived, trip.started, trip.completed
- sos.triggered, microstop.switched
REST Endpoints
| GET | /corridors | List available corridors |
| GET | /corridors/:id/drivers | Drivers on a corridor |
| POST | /trips | Publish a driver route |
| POST | /bookings | Pre-book a seat |
| POST | /bookings/:id/confirm | BLE/QR handshake |
| GET | /microstops | List micro-stops |
| POST | /sos | Trigger emergency |
8. Technology Decision Matrix
| Runtime | Node + CF Workers | Ecosystem maturity, edge support |
| Framework | Hono | Edge-native, lightweight, typed |
| DB | Neon Postgres | PostGIS, branching, serverless |
| ORM | Drizzle | Edge-compatible, type-safe |
| Mobile | React Native (Expo) | Code sharing, ecosystem |
| Maps | Mapbox | Pricing, customization, offline |
| Auth | Clerk | DX, number masking, mobile SDK |
| Payments | PayMongo + Stripe | Local rails + global scale |
9. Non-Functional Requirements
| Latency | p95 < 200ms | Edge compute, regional DBs |
| Availability | 99.9% | Multi-region, graceful degradation |
| Scalability | 100k concurrent | Serverless, auto-scaling |
| Security | SOC 2 ready | Encryption, audit logs, KYC |
10. Roadmap
| MVP | Corridors, matching, booking, micro-stops | Weeks 1-4 |
| Safety | SOS, BLE/QR, deviation alerts, backup routing | Weeks 5-8 |
| Scale | Payments, cohorts, dashboards, EV corridors | Weeks 9-12 |
| Global | Multi-region, localization, compliance | Months 4-6 |
Last updated: December 29, 2025