THE SHORT ANSWER
The frontend is what the user interacts with. The backend applies server-side logic. A database keeps structured persistent information, storage holds files or other objects, APIs connect capabilities, authentication establishes identity, hosting runs and delivers the system, and analytics records selected behavior for learning.
Use a simple system map
| Layer | Plain-English role | Product question |
|---|---|---|
| Frontend | What the user sees and operates | Which journeys and states appear? |
| Backend | Logic executed away from the user's device | Which rules must be trusted and coordinated? |
| Database | Persistent structured information | Which records and relationships must survive? |
| Storage | Files and larger objects | Which documents or media must be retained? |
| API | An interface between systems | Which external or internal capabilities connect? |
| Authentication | Evidence of identity | Who is making the request? |
| Hosting | Infrastructure that runs and delivers the product | Where and how is it available? |
| Analytics | Selected behavioral and operational signals | How will the team learn and detect problems? |
Follow one request through the stack
A user submits a booking in the frontend. The backend validates the request, checks identity and availability, writes a record to the database, calls an email API and returns a result. Hosting makes those components reachable. Monitoring records whether the operation succeeded.
The names of tools can change while these responsibilities remain recognizable.
Evidence & context: MDN Web Docs · MDN Web Docs
Choose a stack from constraints
- Product journeys and data
- Team capability and support
- Security and privacy consequences
- Integration requirements
- Reliability and performance needs
- Expected change and scale
- Portability, vendor dependence and cost
- Monitoring, backup and recovery
A popular framework is not a requirement. Prefer a system the team can operate safely and change deliberately.
Ask for a diagram you can explain
A useful architecture diagram names components, data flows, trust boundaries and outside services. Ask where sensitive data enters, which component enforces permissions, how failure is surfaced and how a deployment is reversed.
Deepen the core layers through databases, APIs and authentication and permissions.
Evidence & context: NIST
Sources & further reading
- How the web works
MDN Web Docs. Standards-oriented learning material on clients, servers, DNS, HTTP and browser rendering. It is a simplified conceptual introduction rather than a complete architecture guide.
- Introduction to web APIs
MDN Web Docs. Standards-oriented introduction to interfaces that expose capabilities. Product APIs vary in transport, authentication, limits and guarantees.
- PostgreSQL tutorial: SQL language and relational concepts
PostgreSQL Global Development Group. Official relational-database documentation covering tables, rows, queries and joins. The module uses the durable concepts without prescribing PostgreSQL or teaching SQL.
- Secure Software Development Framework
NIST. Outcome-based secure-development guidance covering preparation, protection, secure production and vulnerability response. It is a framework, not a product-specific checklist.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗