Security & Architecture guide

For: CTOs and Chief AI Officers

Magneto Mentor is built to sit safely alongside your secure AI environment. This guide explains how the platform protects your data by default, and the added controls available to enterprise teams who need governance, isolation and administration at scale.

In short

  • Magneto Mentor is an AI upskilling tool. People build AI personas (role-based AI custom instructions), task prompts and workflows here. They do not run AI tasks on your documents or systems. We are the build layer but not the execution layer.
  • Every plan is secure by design: no file uploads, data minimisation, and all AI processing brokered server-side.
  • AI features are powered by a single named provider, Anthropic, under commercial API terms that prohibit training on your inputs.
  • Enterprise plans add a control layer: single sign-on, single-tenant isolation, data residency in your region, full audit trails, retention and legal-hold controls, and cost governance.
  • Two tiers: Standard plans give you the secure base. Enterprise plans add the governance and administration a regulated organisation needs.

What is Magneto Mentor?

Magneto Mentor is an AI communication upskilling tool. It teaches the structured thinking people need to work well with AI at work: writing clear prompts, building AI workflows, and getting consistent output from AI tools. It is designed to work alongside your secure AI environment.

It draws on more than 20 years of enterprise communication and corporate training experience at Magneto Communications, where we help enterprise teams improve their business writing, board paper writing, influential communication and presentation skills.

How it works

The workflow is simple and stays within your security boundary.

Step What happens
User action Builds a structured persona, task prompt or workflow inside Magneto Mentor by answering guided questions.
Data in Magneto Mentor Templates, formatting guides, and the user's own answers and prompt scaffolds.
AI processing The user's structured prompt and answers are sent server-side to Anthropic's commercial API for processing. The response is returned to the user inside Magneto Mentor.
What leaves our platform The structured prompt and the user's answers to in-app questions. Nothing else. All AI task execution happens in your secure environment.
What stays in the platform Account metadata (organisation, username, email), saved workflow builds, and usage logs.

Secure by design (standard on every plan)

This applies to every Magneto Mentor plan, standard and enterprise.

 

Data minimisation

We keep what leaves the platform to the minimum the AI needs to respond.

 

What is sent to the AI provider (Anthropic):

  • The person’s answers to in-app questions (text and selections).
  • The tool data needed to build the prompt (templates, structure and tone scaffolds).

 

What is never sent:

  • Emails and passwords.
  • Organisation documents or uploaded files. The platform does not accept file uploads.
  • Account metadata such as organisation name or user identifiers tied to prompt content.

 

What we hold inside Magneto Mentor:

  • Account metadata: organisation, username, email. These let people save and share workflows.
  • Saved prompts and workflow builds created by the user.
  • Anonymous usage data for platform performance.

 

Server-side AI only

Every AI call is brokered by our backend. There are no direct client-to-API calls, so credentials, routing and content filters stay under our control. People cannot bypass these controls by calling AI services directly through the app.

 

AI provider governance

Magneto Mentor uses Anthropic (Claude) as its sole AI provider, through Anthropic’s commercial API. Key points for your AI governance review:

 

AI transaction logging

Every AI call is logged with user, organisation, token count, duration and status. Prompt content is not logged. Rate limits apply at user, organisation and endpoint level to prevent misuse.

 

Standard authentication and hosting

On standard plans, people sign in with a username and password, verified by email. The application backend, frontend and database are hosted with Railway in Singapore. Enterprise plans replace both, as set out below.


 

The enterprise control layer

Enterprise plans add governance, isolation and administration for organisations with formal security, compliance and procurement requirements.

Identity and access

  • Single sign-on and auto-provisioning (SSO / SCIM). People sign in with your existing identity provider. New joiners get access automatically. Leavers lose it the moment they go.
  • Multi-factor authentication (MFA). Require a second check at login, so a stolen password is not enough to get in.
  • Role-based access (RBAC). Each person gets only what their role needs.
  • Teams and user management. Group people the way your business works, and add, change or remove access quickly.

 

Data isolation and residency

  • Dedicated single-tenant instance. Your data sits in its own isolated instance, not shared with other customers.
  • Data residency in your region. Your instance is hosted in the region you choose. (On standard plans, hosting is with Railway in Singapore.)
  • Monitoring and uptime. Your instance is monitored around the clock and backed by an uptime SLA.

 

Compliance and oversight

We minimise what is stored. For what is stored, enterprise plans give compliance and legal teams the controls they expect.

  • Platform audit trail. A locked, searchable record of who did what and when: role changes, members added or removed, content created or edited, and logins. This is separate from the AI transaction logging above.
  • Data-retention controls. Set how long data is kept, then purge it on schedule, so you meet retention obligations without manual effort.
  • Legal hold and export (eDiscovery / DLP). Give compliance and legal teams direct, programmatic access for exports and legal holds.

 

Cost and usage governance

  • Spend quotas. Set spend limits at three levels: the whole instance, each team and each person.
  • Usage dashboards. See exactly how teams and people use the tool.
  • Usage alerts. Get told when usage spikes or key actions happen.


These sit alongside the standard rate limits described above. Rate limits protect against misuse; spend quotas control cost.

 

Administration and deployment

  • Instance configuration. Control settings per instance: enabled features, tools, branding theme and support contact.
  • Custom content. Every tool is fully templated to your business, roles and industry. Its questions, steps and output are configured as data, so tools can be tailored to your organisation.
  • Custom branding. Your logo, your brand colours for each of the tools, your domain.
  • Client-side deployment. For organisations that need on-premises or private cloud deployment, Magneto Mentor can run inside your own infrastructure.

 

AI governance alignment (summary for your review)

A single reference for your third-party AI assessment.

  • AI sovereignty. One named provider (Anthropic), under commercial API terms that prohibit training on customer inputs.
  • Data minimisation. Only the structured prompt content needed for a response is transmitted. Documents, files and credentials never leave the platform. No file uploads.
  • Data residency. Standard plans host with Railway in Singapore. Enterprise plans host in your chosen region on a dedicated single-tenant instance.
  • Authentication. Standard: username and password with email verification. Enterprise: SSO / SCIM with MFA.
  • Authorisation. Role-based access, teams and user management on enterprise plans.
  • Logging and audit. AI transaction logging on every plan (user, organisation, tokens, duration, status; no prompt content). Full platform audit trail on enterprise plans.
  • Retention and legal hold. Configurable retention, scheduled purge, and legal-hold export on enterprise plans.
  • Security practices. OWASP ZAP (DAST) and Semgrep (SAST) scanning in CI, PII-free logging by design, rate limiting and account lockout, and Redis-backed token versioning so logout invalidates all tokens.
  • Shadow AI risk. Magneto Mentor channels AI use through a governed, logged and rate-limited pipeline, replacing unmanaged personal accounts with an auditable path.
  • Policy support. The tool reinforces your AI usage policies by building structured-prompting habits into daily work.

Talk to us

For enterprise deployment, single-tenant hosting or a security review, contact us.