Wonder Security & Trust
AI & Subprocessors
AI & Subprocessors
AI & Processing Overview
Imagine uses external AI and processing services for selected platform capabilities. The information sent to each provider is limited to the data required for the relevant function.
| Processing area | Purpose |
|---|---|
| AI & language processing | Course assistance, content generation, document understanding, feedback and grading support |
| Retrieval | Indexing and retrieval over course learning materials |
| Speech processing | Transcription of course recordings |
| Code execution | Execution of programming-assignment code |
| Communications | Transactional email and institutional meeting integrations |
OpenAI
Imagine uses the OpenAI API for selected AI and retrieval capabilities. Course materials used for retrieval are isolated at the course level rather than combined into a shared institutional knowledge base.
| Control | Configuration |
|---|---|
| Model training / data sharing | Optional API input/output and model-improvement sharing disabled |
| Retrieval isolation | Separate Vector Stores at the course level |
| Indexed-file deletion | Corresponding OpenAI vector files are removed through the verified file-deletion flow |
| Data residency | Current OpenAI project configured as Global |
| Provider-side persistence | Hardening in progress to minimize unnecessary persistence and clean up temporary Batch files |
Status: Hardening in progress
Processing Providers
| Provider | Purpose | Data sent / integration |
|---|---|---|
| Google Vertex AI | Document understanding and AI processing | Learning/document content required for processing; current workload configured in us-central1 |
| Google Cloud Vision / Cloud Storage | Document processing infrastructure | Document content and processing files; direct Cloud Vision OCR path is deprecated |
| AssemblyAI | Transcription | Audio from course recordings; current integration uses the provider's default endpoint |
| Judge0 / RapidAPI | Programming assignment code execution | Source code and runtime inputs; student identity is not sent |
| AutoContent | Learning-media generation | Learning content, generation instructions and internal processing identifiers; student identity is not sent |
| Postmark | Transactional email | Recipient information and message content required for delivery |
| Zoom | Meetings and course recordings | Uses institution-specific Zoom credentials; recordings may be transferred to Imagine storage and transcription processing |
Subprocessor Register
Imagine uses the following infrastructure and processing providers depending on the features enabled by each institution.
| Provider | Purpose | Processing location / status |
|---|---|---|
| Amazon Web Services (AWS) | Application infrastructure, storage and processing | Core Imagine infrastructure: EU Central (Frankfurt) |
| Vercel | Web application hosting and processing | Frankfurt, Dublin and London |
| MongoDB Atlas | Application database | EU Central (Frankfurt) |
| OpenAI | AI processing and retrieval | Global; European data residency under review |
| Google Cloud / Vertex AI | AI and document processing | Current Vertex AI workload: us-central1 |
| AssemblyAI | Transcription | Current integration uses default provider endpoint |
| Postmark | Transactional email | Provider infrastructure includes United States processing |
| Zoom | Institutional meetings and recordings | Determined primarily by the institution's Zoom account configuration |
| Judge0 / RapidAPI | Code execution | Provider processing location under review |
| AutoContent | Learning-media generation | Provider based in Spain; processing chain includes third-party AI services |
Status: Subprocessor review in progress