About This Architecture
Regulated-data architecture showing a web tier in a public subnet and an app tier plus database in private subnets, with a clearly drawn dashed trust boundary around the cardholder-data/PII zone; a firewall/WAF and TLS termination sit at the boundary crossing, the database is labeled encrypted at rest (AES-256), and explicit legends mark which components are in PCI DSS/HIPAA scope versus out of scope as regulated data enters and a tokenized payload exits to an external processor.