This page is machine-translated from French. Read the French original.

Architecture

WivenLLM consists of three cooperating services and interchangeable components connected to the main service. This page describes the system without going into the code details.


The three services

┌──────────────┐      ┌──────────────────────────┐      ┌────────────────────────┐
│  Interface   │─────▶│         Serveur          │─────▶│  Service d'extraction  │
│  (navigateur │◀─────│  API · orchestration IA  │◀─────│  texte des fichiers    │
│   ou appli)  │      │  base · sécurité         │      │  et des URL            │
└──────────────┘      └───────────┬──────────────┘      └────────────────────────┘
                                  │
              ┌───────────────────┼───────────────────┐
              ▼                   ▼                   ▼
        ┌───────────┐      ┌────────────┐      ┌─────────────┐
        │  Modèles  │      │ Embeddings │      │    Base     │
        │    LLM    │      │            │      │ vectorielle │
        └───────────┘      └────────────┘      └─────────────┘

Interface

The application you use: workspaces, conversations, documents, administration screens. It runs in a browser, or in the desktop application that includes it. It only communicates with the server.

Server

The heart of the product. It contains:

  • L''API consumed by the interface, web widget, mobile application, browser extension and third-party integrations; ;
  • L''authentication and the roles; ;
  • L''AI orchestration : supplier selection, vector search, context construction, agent execution; ;
  • there database (spaces, conversations, users, settings); ;
  • THE background treatments : indexing, memory retrieval, Second Brain consolidation, scheduled tasks.

Extraction service

A service dedicated to one thing only: transforming a file or URL into usable text. PDF, Word, spreadsheets, presentations, emails, ebooks, images (character recognition), audio and video (transcription), web pages, code repositories, enterprise wikis.

Separating it from the server has a practical benefit: a large document or a poorly formatted PDF cannot slow down or cause your conversations to drop.


Interchangeable bricks

Three families of components are chosen by the administrator and can be replaced without affecting the rest:

Brick Role By default
Language Model (LLM) Write the answers, manage the agents To be chosen during onboarding — local model possible
Embeddings engine Translates the text into comparable vectors Integrated engine, running locally
Vector base Stores vectors and retrieves nearby passages Integrated local database, stored on disk

Two additional optional families are included: the image and video generation, and the Speech synthesis/recognition.

→ Supported providers


The journey of a document

  1. Deposit. You drag a file into a workspace, or you provide a URL.
  2. Extraction. The extraction service identifies the format, extracts the text and metadata (title, source, date, author when they exist).
  3. Available. The extracted text is saved as an available document. It is not yet searchable.
  4. Cutting. When added to a space, the text is cut into fragments of configurable size, with an overlap between fragments to avoid breaking overhanging sentences.
  5. Vectorization. Each fragment is transformed into a vector by the embeddings engine.
  6. Indexing. Vectors are written in the vector basis, in a namespace specific to the workspace.

The document can then be searched. The same document can be added to several workspaces: it is only retrieved once, but indexed in each one.


The path of a question

  1. Sending. You write a question in a conversation.
  2. Orders. If the message begins with a command (/reset, /image, /video, /note, (or a command you have defined), it is processed before everything else.
  3. Agent mode. If the message begins with @agent, the hand passes to the agent and the sequence becomes that of the agents.
  4. Research. Your question is vectorized and then compared to fragments of the space. The closest ones are retained, within the limits of the number of results and the configured similarity threshold.
  5. Context construction. The server assembles: the space system prompt, the pinned documents, the recovered fragments, your memories and relevant elements from Second Brain, then the last messages of the conversation.
  6. Generation. The whole thing is sent to the model, which responds in a continuous stream — the text is displayed as it is produced.
  7. Restitution. The response is recorded in the history along with its sources, displayed below the message.

Where is the data stored?

Everything produced by an installation lives in a single storage directory :

  • the application's database; ;
  • the extracted documents; ;
  • vector indices, when the vector basis is local; ;
  • downloaded models, when you run models locally; ;
  • the files produced by the agents.

Saving an installation therefore means saving this directory and the configuration file. Moving it to another machine moves the entire instance.

→ Security and confidentiality


What comes out of the network, and when

Situation Network output
Local model, native embeddings, local vector database None
External model provider The messages and context are sent to this provider.
Hosted vector database The vectors and metadata are sent to this hosting provider.
Web research agent skills« The query is sent to the chosen search engine.
Importing a URL or a repository Request to the requested address
Downloading a local model Once, during the download

The screen Réglages → Confidentialité reflects this state for your instance.


Governance, compliance and business integration

The services described above define where the processing takes place. Three additional layers are added, and these are what make the difference in operation.

Governance roles

Three role levels: administrator, unit manager, user. Authentication is via the existing corporate directory, using single sign-on. Each role opens a distinct area of access to workspaces, documents, and settings.

nLPD Processing Register

The processing register is exportable, and the event log is annotated and time-stamped. The solutions are designed for compliance with the nLPD (French Data Protection Act); compliance also depends on the purposes and the client's register, and Wiven provides support in this area rather than guaranteeing it on their behalf.

Agent's perimeter

An agent only works within their assigned scope: the workspaces, documents, and skills explicitly granted to them. The client decides what falls outside this scope, and each departure is logged. The table above shows, situation by situation, what this entails at the network level.

Business connectors

The integration is done with the tools already in place, without replacing them: Abacus, bexio, SAP Business One, Odoo, WINBIZ, Teams, M-Files.

→ WivenLLM security · Integrations