Skip to content

System Architecture v3.9 ​

Last updated: September 30, 2026

System Boundaries ​

AI4Love does not operate its own data center infrastructure. All hosting, storage, and credential management is delegated to SOC 2 Type II certified providers. The system is stateless — serverless functions process requests and release memory when complete.

What AI4Love Operates ​

  • Application logic (serverless functions on Vercel)
  • 7 core analysis agents (scheduled via Make.com) — six run nightly; the research-enrichment agent is activated per organization — plus Queue Cleanup and two resurrection workflows that support the agent pipeline on their own schedule — these are maintenance jobs, not additional analysis agents
  • Nightly publisher (planned — not yet in production) — a write-only sync job designed to run after the analysis agents complete, syncing people, activity, and insight records to each organization's own mirror file
  • MCP server for AI assistant access — 40 read-only tools for authenticated clients; it cannot create, modify or delete data
  • Dashboard UI (static SPA on Vercel)

What AI4Love Does Not Operate ​

  • Databases or data warehouses
  • Email or messaging infrastructure
  • Credential storage systems (delegated to Nango and Doppler)
  • AI model training or hosting

Data Flow ​

Source Systems                    Processing                      Output
─────────────                    ──────────                      ──────

┌──────────────┐
│ Blackbaud    │──READ──┐
│ RE NXT       │        │
└──────────────┘        │
                        ▼
┌──────────────┐    ┌──────────┐    ┌─────────────┐    ┌────────────┐
│ Mailchimp    │──READ──▶│ Airtable │◀───│ Make.com    │───▶│ Airtable   │
│              │    │ (People,  │    │ (7 Agents)  │    │ (Insights) │
└──────────────┘    │  Donors,  │    │ Nightly run │    └─────┬──────┘
                    │  Events,  │    └─────────────┘          │
┌──────────────┐    │  etc.)    │          ▲                  ▼
│ Environics   │──READ──▶│          │          │           ┌──────────┐
│ Analytics    │    └──────────┘          │           │ Dashboard│
└──────────────┘         │               │           │ (UI)     │
                         │         ┌─────┴─────┐     └──────────┘
                         │         │ Claude API │          │
                         │         │ (text gen  │          ▼
                         │         │  only)     │     ┌──────────┐
                         │         └───────────┘     │ MCP      │
                         │                           │ Server   │
                         └───────────────────────────│ (40 read-│
                                                     │  only    │
                                                     │  tools)  │
                                                     └──────────┘

The MCP server only reads. It has no path that writes to Airtable, Pinecone or any other store.

Flow Explained ​

  1. Source systems (Blackbaud, Mailchimp, Environics) are read-only inputs. AI4Love pulls data on manual trigger or scheduled sync. Nothing is written back.

  2. Airtable is the hub. All supporter records, donations, events, engagements, and participation live here. Airtable automations create Participation records from source data and stamp them for agent processing.

  3. Make.com runs the core analysis agents nightly. Agents 1-5 use the prefetch proxy pattern: Make.com pulls queued supporters, the backend pre-fetches each supporter's full timeline from Airtable, then sends everything to the Claude API in one call — and validates every returned insight against that same timeline data before anything is written (batch membership, pattern vocabulary, eligibility thresholds, claimed metrics). Agent 6 reads today's insights and sends them to Claude for cross-agent pattern detection, writing results server-side. Agent 7 embeds insights, queries Pinecone for sector research, and writes enrichment guidance — it is activated per organization and runs only where research enrichment is in use. All agents and campaign-generation calls are constrained by the Content Integrity Policy (v2026-09-09), fetched at runtime and prepended to the system prompt, which prohibits fabricating names, programs, outcomes, quotes, or statistics not present in the provided data, and prohibits inferring a personal reason behind a gift from its designation. Supporters flagged do-not-contact in the source system are excluded before any model call. Queue Cleanup and the two resurrection workflows run on their own schedule to support this pipeline — they don't generate new insight types themselves.

  4. Verification — After each insight is written, the /api/verify-insight endpoint compares AI-claimed metrics against actual Airtable data. Results are written back to the insight record. Cost per run is logged to the Engine Logs table.

  5. Dashboard reads from Airtable to display insights, metrics, and recommendations to staff. Campaign generation also calls Claude with the Content Integrity Policy enforced. Staff take action — the system does not.

  6. MCP Server provides supporter-data access to AI assistants (Claude, ChatGPT, and other MCP-compatible clients). All 40 authenticated tools are read-only by behavior: supporter/source-system records and AI4Love working records are not writable through MCP. Archived insights are filtered from query results. Unauthenticated requests receive an HTTP 401 sign-in challenge and no data. See MCP Access Model.

  7. Publisher (planned — not yet in production) — A write-only publisher job is designed to sync people, activity, and insight records — records only, no formulas or automations — to a file your organization owns in its own workspace (Google Sheets for most clients) after each nightly agent run. It is available to be provisioned per organization but has not shipped yet; until it does, a full export of the working base is available on request at any time. Once provisioned, your organization can revoke the write access at any time; the file itself, and everything already written to it, is unaffected by that revocation and survives cancellation permanently.


Connection Model ​

PlatformAuth MethodDirectionWhat Flows
Blackbaud RE NXTOAuth 2.0 (refresh token)Read onlyConstituents, gifts, actions, events
MailchimpAPI KeyRead onlyMembers, campaigns, activity
EnvironicsOAuth 2.0 (client credentials)Read onlyPostal-code-level PRIZM segments
Airtable (working base)Scoped Personal Access Token or provisioned service credential, per organization, held in AI4Love's own accountRead + WriteRequired bases and tables only; writes restricted to insight, enrichment, and campaign-workflow fields by application logic
Organization mirror (planned — Google Sheets or comparable)Service account, editor on one fileWrite only, once provisioned — not yet in productionPeople, activities, insights
Claude APIAPI KeySend + ReceiveAgent prompts sent, insight text received
PineconeAPI KeyRead + WriteResearch embeddings (KindMind) and organization knowledge (Vault). The MCP server only reads; writes come only from AI4Love's internal ingestion of curated research and organization documents

Infrastructure Providers ​

AI4Love delegates all hosting, storage, credential management, and model inference to independently audited providers. The canonical list of those providers, with the role, data touched, region, and certification for each, is published on the Sub-Processors page.

AI4Love Trust Center v3.9