THE SHORT ANSWER

The frontend is what the user interacts with. The backend applies server-side logic. A database keeps structured persistent information, storage holds files or other objects, APIs connect capabilities, authentication establishes identity, hosting runs and delivers the system, and analytics records selected behavior for learning.

Use a simple system map

Technology layers
LayerPlain-English roleProduct question
FrontendWhat the user sees and operatesWhich journeys and states appear?
BackendLogic executed away from the user's deviceWhich rules must be trusted and coordinated?
DatabasePersistent structured informationWhich records and relationships must survive?
StorageFiles and larger objectsWhich documents or media must be retained?
APIAn interface between systemsWhich external or internal capabilities connect?
AuthenticationEvidence of identityWho is making the request?
HostingInfrastructure that runs and delivers the productWhere and how is it available?
AnalyticsSelected behavioral and operational signalsHow will the team learn and detect problems?

Follow one request through the stack

A user submits a booking in the frontend. The backend validates the request, checks identity and availability, writes a record to the database, calls an email API and returns a result. Hosting makes those components reachable. Monitoring records whether the operation succeeded.

The names of tools can change while these responsibilities remain recognizable.

Evidence & context: MDN Web Docs · MDN Web Docs

Choose a stack from constraints

  • Product journeys and data
  • Team capability and support
  • Security and privacy consequences
  • Integration requirements
  • Reliability and performance needs
  • Expected change and scale
  • Portability, vendor dependence and cost
  • Monitoring, backup and recovery

A popular framework is not a requirement. Prefer a system the team can operate safely and change deliberately.

Ask for a diagram you can explain

A useful architecture diagram names components, data flows, trust boundaries and outside services. Ask where sensitive data enters, which component enforces permissions, how failure is surfaced and how a deployment is reversed.

Deepen the core layers through databases, APIs and authentication and permissions.

Evidence & context: NIST

Sources & further reading

  1. How the web works

    MDN Web Docs. Standards-oriented learning material on clients, servers, DNS, HTTP and browser rendering. It is a simplified conceptual introduction rather than a complete architecture guide.

  2. Introduction to web APIs

    MDN Web Docs. Standards-oriented introduction to interfaces that expose capabilities. Product APIs vary in transport, authentication, limits and guarantees.

  3. PostgreSQL tutorial: SQL language and relational concepts

    PostgreSQL Global Development Group. Official relational-database documentation covering tables, rows, queries and joins. The module uses the durable concepts without prescribing PostgreSQL or teaching SQL.

  4. Secure Software Development Framework

    NIST. Outcome-based secure-development guidance covering preparation, protection, secure production and vulnerability response. It is a framework, not a product-specific checklist.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗