1. Home
  2. Wonder Security & Trust

Wonder Security & Trust

Infrastructure & Architecture

Infrastructure & Architecture

Architecture OverviewPlatform ComponentsEnvironment & Tenant SeparationNetwork & Infrastructure SecurityData Residency
Architecture Overview
Platform Components
Environment & Tenant Separation
Network & Infrastructure Security
Data Residency

Architecture Overview

Imagine is a cloud-native learning platform built on managed infrastructure from AWS, Vercel, and MongoDB Atlas. The core backend and primary data infrastructure are hosted in Frankfurt, with the platform designed around managed cloud services rather than institution-hosted infrastructure.

Platform Components

Imagine uses established managed cloud services for each major layer of the platform, allowing infrastructure, storage, databases, and application services to be operated and scaled independently.

LayerPlatform
Web applicationVercel
Core application APIAWS ECS Fargate — Frankfurt
Primary application databaseMongoDB Atlas
Object and file storageAWS S3 — Frankfurt for verified private storage
Private content deliveryAWS CloudFront

Environment & Tenant Separation

Imagine is a multi-tenant SaaS platform designed to provide strong logical separation between institutions. Each institution has its own dedicated MongoDB database and institution-scoped file namespace, while the application runtime and supporting managed infrastructure are shared. Production and Staging run as separate application deployments, with logical separation within shared infrastructure components.

LayerProduction / StagingBetween Institutions
Application runtimeSeparate deploymentsShared application runtime
API servicesSeparate services and endpointsShared API service
MongoDB dataSeparate databasesSeparate database per institution
MongoDB infrastructureShared Atlas clusterShared Atlas cluster
S3 storageShared bucketsShared buckets with institution-specific namespaces
Redis / ValkeyShared managed instance with environment-level queue separationShared managed instance with tenant context in application jobs
Application credentialsSharedPrimarily shared application-level credentials

Network & Infrastructure Security

Imagine's backend operates within a dedicated AWS network environment, with public application traffic routed through an AWS Application Load Balancer and protected using HTTPS. Internal infrastructure is subject to network-level access restrictions, with additional network hardening currently in progress.

ControlConfiguration
NetworkDedicated AWS VPC
Public entry pointAWS Application Load Balancer
HTTPSTLS 1.2 and TLS 1.3
Internal Redis accessRestricted to the application VPC
Application-service exposureAdditional network hardening in progress
HTTP → HTTPS enforcementHardening in progress

Status: Hardening in progress

Data Residency

Imagine keeps its core backend, primary database, and private file storage in Frankfurt. Vercel application processing is restricted to European regions, while the residency of AI and other external subprocessors is documented separately as part of the subprocessor review.

ComponentProviderRegion
Core production backendAWSEU Central (Frankfurt)
Private file storageAWS S3EU Central (Frankfurt)
Application databaseMongoDB AtlasEU Central (Frankfurt)
Web application processingVercelFrankfurt, Dublin, and London
Privacy at WonderHow we process dataWonder Security & Trust|© 2026 Wonder. All rights reserved.