> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/plans-billing/architecture.md).

# Architecture

How the AIsuru platform is built: the components, the infrastructure and the technical choices that guarantee security and reliability.

How the AIsuru platform is built: the components, the infrastructure and the technical choices that guarantee security and reliability.

The architecture of AIsuru follows a modular approach that clearly separates responsibilities between independent subsystems. This separation is what allows the platform to scale, isolate failures and adapt to the different delivery models (SaaS, PaaS, Private Cloud, on-premise).

***

**The five functional blocks**

| Component       | Role                                                                                                                     |
| --------------- | ------------------------------------------------------------------------------------------------------------------------ |
| **Frontend**    | the interfaces (dashboard, chat widget, mobile app, VR app) from which users manage and interact with the Agents         |
| **Backend**     | stores user, tenant, consumption and asset data; handles authentication and authorization                                |
| **Engine**      | the heart of the platform: runs the conversational dialogue, hosts the proprietary NLP engine and the data of all Agents |
| **MCP Gateway** | the component through which Agents connect to external tools and systems (databases, CRMs, automation services)          |
| **Billing**     | tracks credits, consumption and invoicing (only for the public SaaS plan)                                                |

Communication between the backend and the engine takes place over an encrypted channel.

***

**How an Agent "thinks"**

An AIsuru Agent is not a simple wrapper around a generic language model. Memori's proprietary NLP system analyzes each question with semantic understanding techniques developed in-house, and first of all tries to answer with the explicit knowledge provided by the Agent's creator.

Only when this knowledge is not sufficient — and only if the Agent is configured to do so — does the platform query an external generative artificial intelligence model, providing it with the relevant context retrieved from the knowledge base. **Explicit knowledge always takes precedence over generation**: this is the property that distinguishes AIsuru from a generic chatbot builder based on a single language model, and that guarantees the Agent's creator substantial control over the answers given to their users.

The NLP engine is trained and managed in-house by Memori for each of the natively supported languages (Italian, English, French): the language of an Agent is defined by its creator at creation and cannot be changed later by third parties. Conversations can nevertheless take place in many more languages thanks to a translation service that operates at the edges of each dialogue turn, leaving unchanged the language in which the Agent was trained.

***

**Isolation and multi-tenancy**

The platform is designed to handle each customer's ("tenant") data in an isolated manner:

* each tenant can see only its own Agents, users and configurations;
* each tenant can be customized with its own branding, domain and operational limits;
* data does not transit between different tenants.

***

**Integrations with external systems**

Through the MCP Gateway, an Agent can connect to external tools — corporate databases, CRMs, automation platforms — to retrieve information or perform concrete actions (sending a message, updating a system, filling in a form). The connected external systems always remain under the full control of the customer: the platform acts as a technical intermediary for executing the requested operation, not as the owner of the data that transits through it.

All communications to external servers take place over an encrypted connection (HTTPS/TLS).

***

**Security and continuity**

* Segregation of data between different customers (multi-tenant isolation).
* Encrypted communications between all components of the platform.
* Regular backups and disaster recovery procedures.
* Continuous monitoring of service availability, with dedicated alert channels for the technical team.
* Development cycle with over 2,000 automated tests run before each production release, plus manual quality checks.

For details on application security testing activities, see \[Penetration test summary].

***

**Delivery models**

AIsuru is available in different modes, with an increasing level of isolation and control — the detail is on the \[Delivery models] page:

* **Public Cloud / SaaS** — the public platform on aisuru.com, with free registration and a credit system;
* **Public Cloud / PaaS** — a branded environment on a dedicated domain, with advanced management of users, API keys and consumption;
* **Private Cloud** — infrastructure with greater isolation, suited to companies with stricter data protection requirements;
* **On-premise** — the platform deployed entirely within the customer's infrastructure, for maximum control over data.

For the processing and geographic location of data, see \[EU data residency] and \[Where is my data hosted?].

***

### Deployment and updates

Platform updates are released through automated **CI/CD pipelines**. For most components a **blue-green deployment** strategy is adopted, which guarantees service continuity during releases. The staging environment is kept aligned with production for complete testing before deployment.

{% hint style="warning" %}
For the PaaS, Private Cloud and On-Premise models, architectures with greater isolation are available. Contact the technical team for the details specific to your scenario.
{% endhint %}
