Alliance OS Proposal

This is an enterprise architectural proposal.
Kindly open this on a desktop browser for the optimal experience.

Software Proposal — Alliance Insurance

Your insurance
OS, completely
reimagined.

Alliance OS by Sayaintel is not a policy system upgrade. It is the insurance operating layer your business will run on — every portal, every transaction, every workflow, every employee, every channel partner, every customer — from a single, unified, low-code-configurable platform.

15m → 90s
Workflow Reduction
100%
Portals Delivered
99%
APIs ≤ 3s
≤6h
Disaster Recovery
Prepared For
Alliance Insurance
Delivered By
Sayaintel Corporation
Alliance OS Platform © 2025
6
Portals included in scope
Staff Workbench (Back Office)
Direct Customer Portal
Intermediaries & Broker Portal
Affinity Partner Minisite
Aggregator Minisite
Mobile App (iOS & Android)
Platform
Alliance OS — Next-Gen Core
Proposed Go-Live
Phase 1 — Q4 2026
≤10m
Scheduled deployment
downtime
≤15m
Recovery Point
Objective (RPO)
80%
APIs respond
within 1 second
3-Tier
Platform, Tenant
& Product isolation
AES-256
All PII & sensitive
data encrypted
01

A complete insurance
operating system.
Not a software tool.

Alliance OS is a AI-native, event-driven bespoke infrastructure serving insurers across Asia with policy volumes in the tens of millions. Alliance will receive a fully configured instance — not a fresh codebase — with

Command-Driven Operations (Omnibar)
One platform, data/logic isolation per tenant, unlimited products. Life, GI, Health, Micro-products all under one roof — each independently configurable.
Object-Centric Canvas Workspaces
Build and modify insurance products, underwriting rules, pricing formulas, workflows, and UI layouts — all from a visual interface. No code deployments needed for business changes.
Exception-Based Processing (AI Maker)
The AI is the Maker. The Human is the Exception Handler. AI ingests PDFs, extracts 40+ fields, and cross-references policies. Humans simply review highlighted fields and click Approve.
Modern Event-Driven Architecture
AES-256 PII encryption, SSO/SAML/OAuth2/JWT auth, WAF, rate limiting, circuit breakers, audit logging, and role-based data isolation — fully out of box.
Policy Administration
Core
Full lifecycle — quotation, proposal, issuance, endorsement, renewal, cancellation. Configurable per product with on-screen rules, rate tables, and coverage structures.
Claims Management
Core
Claim registration, reserve management, settlement workflows, authority levels, recovery tracking, and legal management — all configurable without code.
Reinsurance
Core
Treaty and facultative configuration — quota share, XOL, surplus. Outward and inward treaty definitions, risk accumulation limits, RI cession automation.
Finance & Billing
Finance
Premium billing, collections, GL integration, bank reconciliation, commission settlements, refunds, offsets, and accounting rule engine — all configurable.
Sales Channels & Commission
Channel
Agency, broker, bancassurance, affinity channel hierarchy. Sales authority control, commission structure, overriding rates, performance tracking.
Data Services & Reporting
Analytics
Built-in data pipeline, Vector-DB powered enquiries, report management, dashboard configuration, Google Analytics pre-integrated, BI tool ready.
Customer & CRM
Customer
360° customer view, AMLO/blacklist checking, individual and corporate profiles, compliance screening, customer 360 via NoSQL data layer.
AI Services Layer
AI
Pluggable AI service layer pre-integrated into the platform kernel. Ready to connect 3rd party AI/Big Data services without custom integration work.
02

Six portals. Every
user type. One platform.

6

Alliance will receive six fully functional, role-controlled user portals — not templates, not mockups. Each portal is product-aware, data-isolated by role and hierarchy, and shares the same underlying API layer. Changes made by your back-office staff reflect immediately across every portal without a new deployment.

01
Insurer Staff Workbench
Internal Operations Portal
The command center for your internal teams. Every policy, claim, customer record, financial transaction, and configuration is accessible with role-based precision. Underwriters, claims handlers, finance, compliance, and ops all operate from a single, purpose-built interface.
Full policy lifecycle management — quote to renewal
Claims processing, reserve setting, settlement approval
Finance operations — billing, collection, GL posting
Reinsurance cession management and treaty tracking
RBAC — every button, every field, every tab controlled by role
Audit trail on every critical action — immutable log
Bulk operations with file management and monitoring
Embedded report builder and dashboard access
02
Direct Customer Portal
B2C Self-Service
A branded, self-service portal for individual and corporate policyholders. Customers can purchase, manage their policies, file claims, make payments, and download documents — entirely without calling your staff.
Online quotation with real-time premium calculation
Policy purchase, payment and digital policy delivery
Self-service endorsements and renewals
Claim filing and status tracking
Digital document vault — e-policies, receipts, schedules
Secure login — SSO, 2FA, social login options
Customer 360 view — all policies and history in one place
03
Intermediaries Portal
Agents, Brokers & Bancassurance
A full-featured portal for your agency, brokerage, and bancassurance channels. Channel users operate within their hierarchy and sales authority — they can only see and transact what they are authorized to. Commission tracking and client management built in.
Quote, bind and issue policies on behalf of customers
Hierarchy-based data visibility — each agent sees only their book
Sales authority control per channel category and qualification
Commission statement access and settlement tracking
Client portfolio management and renewal pipeline
Mobile app access (iOS & Android via React Native)
Document generation — proposals, policy schedules
04
Affinity Partner Minisite
White-Label Partner Storefronts
A configurable, brandable minisite for each affinity partner — banks, telcos, retailers, associations. Partners get their own insurance experience without technical overhead. Each minisite is independently configured on-screen with product selection, pricing rules, and UI layout.
Fully branded per affinity partner — logo, colors, domain
Product selection scoped per partner relationship
Simplified purchase flow tailored to partner's customer base
Group/employee scheme enrollment support
Partner admin access for their own reporting
On-screen configuration — no code change per partner
05
Aggregator Minisite
Price Comparison Connectivity
Ready-to-connect interface for insurance price comparison platforms and aggregators. Alliance OS's API layer exposes comparison-ready endpoints that aggregators consume — your products appear on third-party platforms without custom integrations from your side.
Aggregator-friendly API layer — partner-specific parameter converters
Real-time premium calculation exposure to aggregators
Bind and issue via aggregator platform with policy delivered direct
Product and pricing scoped per aggregator relationship
Integration log visibility — every aggregator call tracked
06
Mobile Application
iOS & Android — React Native
A native mobile application built on React Native for both iOS and Android. Designed primarily for intermediary field agents — enabling them to quote, bind, and manage their clients' policies on the go. The same data layer, same rules, same permissions — mobile-first.
Quote and bind insurance on the go — full product access
Client portfolio and renewal management on mobile
Digital document access — policy schedules, receipts
Push notifications for policy events and renewals
Biometric and PIN authentication — 2FA enabled
Works for both agents and direct customers depending on config
03

Built on layers that
were designed to never fail.

Alliance OS runs on a tiered microservices architecture deployed on AWS (or your preferred cloud). Every layer is independently scalable, fully observable, and production-hardened across multiple live insurance deployments.

Users
Individual Customer Corporate Policyholder Field Agent / Broker Affinity Member Aggregator Platform Insurer Staff API Partners
Security Layer — AWS WAF + Firewall + CloudFront
Gateway
AWS API Gateway / GraphQL — Real-time Endpoints Authentication — NextAuth / SSO / OAuth2 / JWT Rate Limiting + Circuit Breaker Nginx Web Layer
Authorization Check — RBAC by User Type per API
Services
Policy Services Claim Services Reinsurance Services Finance Services Product Services Customer & Sales Channel Services AI Services Alert Services Output Services Async Task Processor File Services (S3)
All services run on Alliance OS Kernel — Platform, Tenant, Product isolation
Data
MySQL (AWS RDS) Postgres (Read Replica) S3 Data Lake (Parquet/JSON) S3 Object Storage Configuration Center (Nacos) Service Registry (Nacos)
Observability Stack — fully instrumented
DevOps
Prometheus + Grafana (Metrics) SkyWalking APM (Traces) ELK Stack (Application Logs) Loki + Grafana (Log Aggregation) AWS CodePipeline CI/CD CloudWatch + Alerts Google Analytics (Pre-integrated)
External integrations via standard protocols
External
General Ledger SMS / Email / Social Payment Gateways AMLO / Blacklist 3rd Party AI Document Management Data Lake / BI Tools
2,894
Total APIs
AES-256
PII Encryption
TLSv1.3
Data in Transit
R/W Split
DB Architecture
Multi-AZ
AWS Availability
04

Deployment that respects
your business hours.

Alliance OS operates a one-click CI/CD deployment pipeline via GitHub Actions and AWS CodePipeline. Every change — Next.js frontend, Node.js services, database migrations, and UI updates — is containerized via Docker and deployed automatically to our Kubernetes (AWS EKS) clusters with all unit test cases executed. Thanks to EKS rolling deployments, our target for both hotfixes and major releases is zero downtime. Kubernetes seamlessly drains traffic from old pods and routes it to new ones.

The platform uses a structured branching model (Master → Release → Develop → Feature) that mirrors four live environments: Prod, UAT, Test, and Enhance/Local. Configuration management follows the same flow, ensuring configuration releases are always tracked alongside code.

Zero-downtime hotfix deployments — critical fixes deployed to production without taking down the system
One-click pipeline — all changes built, tested, and deployed automatically via GitHub Actions
On-screen data patch management — production data corrections go through a submit → approve → execute workflow with full audit
On-screen release management — configurations packaged and released through a managed approval workflow, not ad-hoc
Rollback capability — every production deployment has a tested rollback path executed if verification fails
Multi-environment parity — what is tested in UAT is exactly what is deployed to production. No environment drift.
Web Layer
React Tailwind CSS v4 shadcn/ui Next.js (App Router) React Native / PWA
Service Layer
Node.js TypeScript Prisma / Drizzle ORM Zod tRPC / GraphQL Kafka Docker AWS EKS (Kubernetes) AWS API Gateway
Data Layer
PostgreSQL 16 Redis (Upstash) OpenSearch DynamoDB AWS S3
DevOps & Testing
GitHub Actions AWS CodePipeline Turborepo Jest / Vitest Cypress Playwright ESLint / Prettier Cursor / Copilot
Monitoring
Prometheus Grafana Datadog AWS CloudWatch Sentry CloudWatch Kibana
≤10 min
Deployment Downtime
Kubernetes rolling updates ensure no traffic is dropped. 100% of deployments run without interruption.
0 min
Hotfix & Ad-hoc Downtime
Emergency fixes and ad-hoc deployments are deployed without any downtime using rolling deployment and session persistence.
100%
Containerized Infrastructure
Every service runs in isolated Docker containers orchestrated by AWS EKS, guaranteeing parity between local, test, and production.
05

From kick-off to go-live
a clear, committed plan.

Each phase is structured with defined deliverables, acceptance milestones, and dedicated environments. Configuration work happens in parallel with infrastructure setup — no waiting around.

Months 1–2
Discovery & Foundation
Business requirements & product mapping
Infrastructure provisioning on AWS
Alliance OS base instance setup
Data migration strategy & staging DB design
Integration architecture sign-off
Team onboarding & access provisioning
Months 3–5
Product & Channel Configuration
Insurance product setup on-screen
Underwriting rules & rate tables
Sales channel & commission structure
Metadata and UI configurator setup
Reinsurance treaty configuration
Finance & GL configuration
Months 6–8
Portal Build & Integrations
All 6 portals configured and deployed to UAT
Mobile app build & testing
3rd party integrations (payment, SMS, GL)
API partner enablement
Claims & finance workflow testing
Performance & security testing (JMeter, VA/PT)
Months 9–10
UAT & Data Migration
User acceptance testing with Alliance teams
Data migration dry run from legacy system
Defect resolution and regression testing
Training — all user roles and portals
Disaster recovery drill and sign-off
Go-live readiness checklist completion
Month 11+
Go-Live & Stabilization
Phased go-live (start with 1–2 products)
Hypercare support — Sayaintel team on standby
Full production monitoring activated
Remaining products and portals rollout
Post go-live SLA support begins
Handover to steady-state support model
06

We don't hand over and
disappear. We stay.

Sayaintel operates a structured maintenance model covering open-source components, platform upgrades, testing, monitoring, and everything in between — so your team can focus on business, not systems.

01
Real-Time Monitoring Stack
Every component of the system is monitored 24/7 using a pre-integrated observability stack. Alerts fire before issues become outages.
Infrastructure Metrics Prometheus + Grafana
Application Performance SkyWalking APM
Log Aggregation ELK / Loki + Grafana
Integration Logs Built-in (full request/response)
User Analytics Google Analytics (pre-integrated)
02
Node.js & Security Governance
Sayaintel reviews open-source components monthly and monitors emergency notices from the community. Every upgrade goes through impact analysis, client notification, and tested deployment.
Postgres Minor Upgrade 6+ months after release
Postgres Major Upgrade 2+ years after release
Next.js / React Minor 6+ months after release
Node.js LTS Updates 2+ years after release
Emergency Security Patches Reviewed within 24h
03
Housekeeping & Archival Automation
The platform ships with pre-configured rules for automatic data housekeeping, archival, and purge. High-volume tables are managed transparently — performance stays consistent as data grows.
Integration Logs Archive after 1 year
Application Logs Rotate daily, archive 6 months
GL Accounting Entries Archive to log tables after 7 days
Job Execution History Archive after 6 months
All rules Configurable on-screen
04
Automated Testing Before Every Deployment
Every deployment cycle triggers the full automated testing framework — unit, API, UI, performance, and security — before anything reaches production. Defects are caught before users see them.
Unit Tests JUnit — auto-triggered on build
API Tests Postman collection — per deployment
UI Regression Cypress — automated browser tests
Performance Testing Playwright load & UI testing
Security Scanning SonarQube + 3rd party VA/PT
07

When things go wrong,
here is exactly what happens.

Every incident is classified by severity. Response times, escalation paths, and resolution commitments are pre-defined and agreed upon — not improvised under pressure. Alliance will always know who is on it and when it will be resolved.

Severity
Condition
Response
Resolution Target
S1
Full system outage or data integrity failure in production
≤ 30 min
≤ 4 hours
S2
Critical feature unavailable — policy issuance, payments, claims
≤ 2 hours
≤ 8 hours
S3
Non-critical feature degraded or workaround available
≤ 8 hours
≤ 3 days
S4
Minor issue, cosmetic, enhancement request
Next business day
Scheduled release
1
Detection — Automated Alerts Fire
Datadog, Sentry, and AWS CloudWatch continuously monitor all components. Alerts trigger automatically the moment thresholds are crossed — before users report anything.
2
Triage & Severity Classification
On-call engineer reviews alert within SLA window. Impact assessed, severity assigned, appropriate escalation path activated. Alliance Ops Team is notified immediately for S1/S2.
3
Active Remediation
Sayaintel engineering team engages. Logs analyzed via Datadog, traces reviewed via Sentry, integration logs reviewed for third-party failures. Hotfix prepared if needed.
4
Fix Deployed — Zero-Downtime
Hotfix deployed via CI/CD pipeline with no system downtime. Deployment goes through test verification before production. Rollback available within minutes if needed.
5
Post-Incident Review & Prevention
Root cause analysis documented and shared. Platform-level fix or monitoring rule added to prevent recurrence. Issue tracked in change management system with full transparency.
08

What no one else
can offer Alliance.

Every platform vendor will tell you they are configurable, scalable, and secure. What sets Alliance OS apart is not a feature list — it is a philosophy of reducing your dependency on developers, your cost of change, and your time to market. Here is what that means in practice.

Security Baked In — Not Bolted On
AES-256 PII encryption, TLSv1.3 data in transit, BCrypt-11 passwords, WAF protection, anti-fraud URL encryption, data masking per role, immutable audit trail, SSO/SAML/OAuth2 — every one of these is in the platform by default, not added later.
API-First Platform — Every Feature Exposed
Every function in the system is accessible via API. GraphQL and REST APIs, categorized by user type, with dynamic parameter converters to create partner-friendly APIs for any integration without modifying core services. Build your ecosystem — aggregators, partners, IoT — on top.
Disaster Recovery With Real SLAs
RTO ≤6 hours, RPO ≤15 minutes. Not aspirational — documented in a full RACI matrix with step-by-step recovery procedures, parallel execution paths, and Sayaintel engineers assigned at each step. Tested before go-live. Drilled annually.
Multi-Tenant With Real Data Isolation
Alliance can run multiple business units, lines of business, and products — all under one Alliance OS instance — with complete data and logic isolation per tenant. No data leakage. No configuration bleed. Each tenant operates independently with shared infrastructure cost savings.
Handles 100M+ Record Tables Natively
The data service architecture separates hot and cold data, uses AWS S3 for big data scenarios, and employs read-write splitting with Postgres read replicas. Policy tables, transaction histories, and audit logs scale without re-architecture — ever.
Immutable Audit & Integrity
Triple-entry accounting principles applied to core data. Every policy mutation, every claim adjustment, and every financial transaction is logged cryptographically. Data isn't just saved; its integrity is mathematically guaranteed.
09

Every user. Every device.
Every workflow. Smooth.

Zero Latency — Next.js Edge APIs Respond in Milliseconds
By decoupling the frontend from the core engine using Next.js and a GraphQL API layer, UI interactions are instantaneous. Operations don't wait for monolithic database locks.
Dynamic Canvas — Different Flows Per Channel
The Object-Centric Canvas supports role-based dynamic layouts with distinct configurations for agent channels (B2B) and direct customers (B2C). No one sees more than they should, and no one is forced through screens that don't apply to them.
Everything Is Signable, Digital, and Delivered
e-Policy generation, email and SMS delivery, digital payment collection, and automated renewals — the entire customer journey runs digitally. No paper required. Integration with your preferred communication providers handled via the built-in communication configuration layer.
Compliance Built Into the Workflow
AMLO checks, compliance screening, blacklist verification, and regulatory declaration capture are embedded into the policy submission workflow — not a separate step, not a manual checklist. Compliance happens automatically as part of the process.
Native Mobile — Not a Responsive Web
The mobile app is built in React Native — a true native application for iOS and Android. It is not a responsive website wrapped in an app. Field agents get a purpose-built mobile experience that works at the speed they need in the field.
Policy Issuance — Typical Flow Time
< 90 sec
From quote to digital policy delivery (simple product)
Supported Login Methods
7
Username/PIN, LDAP, 2FA, Token, SSO, SAML 2.0, OAuth2 / JWT
Event Streams
Kafka
GraphQL, REST, WebSocket, Kafka Topics, S3 Data Lakes
API Response — 99th Percentile
≤ 5s
Even for complex batch operations — upload 1,000 collection records with matching
Serverless Async Task Types
Email, SMS, GL posting, recurring payment, commission settlement — all async, all monitored
Generated Output Documents
PDF, HTML, Excel
Policies, schedules, statements, reports — all configurable on-screen without development
10

Alliance deserves an
insurance OS built for 2030,
not 2009.

"Alliance OS is not a new system to learn. It is the infrastructure your business will grow on — with portals your staff will love, APIs your partners will integrate with, and a platform your IT team will never have to fight."

Proposal Prepared By Sayaintel Corporation
Platform Alliance OS © 2025
Prepared For Alliance Insurance
Portals in Scope 6 Portals
Modules Covered Policy, Claims, RI, Finance, Sales, Data, AI
Target Go-Live Phase 1 — Q4 2026
Deployment Model AWS Cloud — Multi-AZ
Status Open for Discussion