1. Home
  2. Wonder Security & Trust

Wonder Security & Trust

Identity & Access

Identity & Access

Authentication & Account SecurityRoles, Permissions & Access ControlSession SecurityPrivileged Access & Secrets
Authentication & Account Security
Roles, Permissions & Access Control
Session Security
Privileged Access & Secrets

Authentication & Account Security

Imagine provides individual user accounts with password-based authentication and account protections against repeated failed login attempts.

ControlConfiguration
AuthenticationIndividual email and password credentials
Password protectionbcrypt password hashing
Account lockoutAccount locked for 4 hours after 5 failed login attempts
Session lifetime24 hours
Password resetTime-limited reset token valid for 15 minutes
Institutional SSOSAML 2.0 integration planned
Application MFANot currently implemented

Roles, Permissions & Access Control

Imagine uses role-based access control at both the institutional and course level. Access to academic information is determined by the user's institutional role, course enrollment, course role, and specific permissions where applicable.

Access layerConfiguration
Institutional rolesAdministrator, supervisor, creator and regular user
Course rolesStudent, lecturer, assistant, moderator and supervisor
Course accessControlled through active course enrollment and course role
Administrative accessInstitutional administration functions require elevated platform roles
Additional permissionsSpecific administrative capabilities can be granted through explicit permission flags
Institution dataSeparate MongoDB database per institution
File organizationInstitution-scoped storage namespaces

Session Security

Imagine uses signed JWTs for authenticated application sessions. Additional session and tenant-binding controls are being hardened before full institutional deployment.

ControlConfiguration
Authentication tokenSigned JWT
Token validity24 hours
LogoutClient session and locally stored authentication state are cleared
Server-side token revocationNot currently implemented
Browser session protectionMigration to server-managed protected cookies in progress
Identity-to-institution bindingAdditional server-side hardening in progress

Status: Hardening in progress

Privileged Access & Secrets

Administrative application capabilities are restricted to authorized institutional roles. Infrastructure and provider credentials are maintained server-side and are not exposed through the client application.

ControlConfiguration
Institution administrationRestricted through elevated institutional roles
Infrastructure credentialsMaintained in protected server-side environment configuration
Browser exposureSensitive backend and provider credentials are not exposed as public frontend variables
Source codeNo central AI provider credentials or private keys identified as hard-coded application secrets
Infrastructure administrative MFAMFA enforced for administrative access to AWS, MongoDB Atlas, and Vercel
Secrets managementAdditional centralization and access hardening in progress

Status: Hardening in progress

Privacy at WonderHow we process dataWonder Security & Trust|© 2026 Wonder. All rights reserved.