Data flow diagram
How data moves through MagOneAI — from user input to AI-generated output, with every storage layer and external service mapped
Overview
This page documents how data enters, moves through, is stored in, and exits the MagOneAI platform. Understanding these flows helps you assess data exposure, plan compliance, and make informed decisions about model selection and tool integrations.
Platform architecture
MagOneAI is a layered system where all data flows through a secure API layer. No external service connects directly to any internal data store.
Workflow execution flow
This is the primary data path — how user input travels through MagOneAI and becomes AI-generated output.
Data entering the platform
All data enters MagOneAI through authenticated API endpoints. There are no direct connections to internal stores from outside.
| Entry Point | Authentication | What Data |
|---|---|---|
| Studio / Hub UI | JWT session (HttpOnly cookies) | Workflow definitions, agent configs, chat messages, file uploads |
| REST API | JWT bearer token | Execution inputs, CRUD operations |
| Webhooks | API key + HMAC-SHA256 request signature; the key secret is encrypted at rest, never stored in plaintext | Freeform JSON payload to trigger workflows |
| Scheduled triggers | Internal (no external entry) | Pre-configured input for recurring workflows |
| OAuth callbacks | State token verification (CSRF protection) | Authorization codes from Google/Microsoft |
Data leaving the platform
Understanding what data exits your environment is critical for compliance. MagOneAI sends data externally only through two paths: LLM calls and MCP tool calls.
What goes to LLM providers
| Data Sent | Description |
|---|---|
| System prompt | Agent persona, role, and instructions |
| User input | The input data provided to the workflow or chat message |
| Conversation context | Previous activity outputs flowing through the workflow |
| Tool schemas | Definitions of available tools (function names, parameters) |
When using cloud LLM providers, all of the above data is sent to the provider's API. To keep everything within your environment, use privately hosted models via any OpenAI-compatible endpoint (vLLM, Ollama, LM Studio, TGI, etc.). MagOneAI treats private models identically to cloud models — no workflow changes needed.
What goes to tool APIs
| Tool | Data Sent Externally |
|---|---|
| Google Gmail | Email content, recipients, OAuth token |
| Google Calendar | Event details, attendees, OAuth token |
| Microsoft Outlook | Email content, recipients, OAuth token |
| Microsoft Calendar | Event details, attendees, OAuth token |
| Web Search | Search query text |
Tools that stay local
These MCP tools process data entirely within your environment:
| Tool | What It Does | External Calls |
|---|---|---|
| File Tools | Extract text from PDFs, Excel, CSV | None |
| Database / Vanna | Query your own databases with SQL or natural language | None (connects to your DB) |
| Filesystem | Read/write local files | None |
Secrets and credential management
MagOneAI separates sensitive credentials from application data. Credentials are never stored in the application database.
How credentials are resolved
When a workflow needs credentials (e.g., to call Google Calendar), MagOneAI uses a scoped fallback chain:
This allows flexible credential management:
- User-level: Individual team members connect their own Google/Microsoft accounts
- Project-level: Shared credentials for a team (e.g., a shared service account)
- Organization-level: Default credentials for the entire org
OAuth integration flow
When connecting to Google or Microsoft services, MagOneAI uses standard OAuth 2.0 with PKCE for security.
File processing flow
Files uploaded to MagOneAI are stored in private object storage and processed for use in workflows.
- Files are streamed in chunks to prevent memory issues
- Original files and extracted text are stored separately
- Access is controlled via time-limited signed URLs (no public access)
- Files are scoped to the project — only project members can access them
Human-in-the-loop flow
Workflows can pause for human approval or input, then resume automatically.
When a workflow is paused for human input, no compute resources are consumed. The workflow engine (Temporal) durably persists the state and resumes exactly where it left off — even if servers restart in the meantime.
Data protection summary
Sensitive data handling
| Data Type | How It's Protected |
|---|---|
| User passwords | Bcrypt hashed — never stored in plaintext |
| Session tokens | HttpOnly + Secure + SameSite cookies with short expiry |
| LLM API keys | Stored exclusively in encrypted Vault — never in application database |
| OAuth tokens | Stored exclusively in encrypted Vault — auto-refreshed on expiry |
| Tool credentials | Split storage: non-sensitive config in database, secrets in Vault |
| Webhook / API keys | Secret encrypted at rest (never plaintext); requests authenticated by HMAC-SHA256 signature |
| Uploaded files | Private object storage — access via time-limited signed URLs only |
Encryption
| Layer | Protection |
|---|---|
| In transit | TLS/HTTPS for all external and client-facing communication |
| At rest | AES-256 encryption in Secrets Vault; database and storage encryption configurable per deployment |
| Secrets | Vault seal mechanism with support for cloud KMS auto-unseal |
Access control
| Scope | Who Can Access |
|---|---|
| Organization | Members of that organization only |
| Project | Project members with appropriate role (Viewer, Operator, Builder, Admin) |
| Execution data | Project members only — isolated per project |
| User credentials | Only the user who created them |
| Org-level secrets | Organization Owners (and platform Superadmins) |
AI sovereignty
MagOneAI is designed for organizations that need complete control over their AI data:
- Private LLM support: Use any OpenAI-compatible model endpoint — your prompts and data never leave your network
- Self-hosted deployment: Run the entire platform on your infrastructure (Docker Compose or Kubernetes)
- Local tools: File processing, database queries, and filesystem access happen entirely within your environment
- No telemetry: MagOneAI does not phone home or send usage data externally
For maximum data sovereignty, deploy MagOneAI with privately hosted LLMs and use only local tools (File Tools, Database, Filesystem). In this configuration, zero data leaves your network boundary.