> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Architecture

> How Docusnap365 is built, what runs in your network, and where your data lives.

Docusnap365 is a cloud application. It is operated by Docusnap GmbH in
**Microsoft Azure, West Europe**. Exactly one component runs in your network:
the Docusnap Enterprise Gateway.

## Components

| Component | Role |
| - | - |
| **Web interface** | Operated in the browser. No installation. |
| **Backend** | Processes requests from the web interface and the results the gateways send. |
| **Your database** | Every tenant has its own database. Data belonging to different tenants is strictly separated. |
| **Transfer storage** | Receives scan results from the gateway until the backend has processed them. Temporary. Strictly separated per tenant. |
| **Storage** | Holds files ready for download: exports, documents, AI assistant attachments. Strictly separated per tenant. |
| **Vault** | Stores scan credentials encrypted. See [Security](/docs/en/getting-started/security). |
| **Gateway** | Windows service in your network. Executes scan jobs. |

## The gateway

The gateway is the connection between your network and Docusnap365. It
consists of a **Windows service** that does the work and a **configuration
app** for registration and setup. It runs on a server or a VM and connects
**outbound** to Docusnap365 over HTTPS. There are no inbound connections from
the internet; only **port 443** is required outbound.

A gateway belongs to exactly one tenant. Any number of gateways can be
registered per subscription — for separate sites or networks.

**Jobs.** The gateway fetches its scan jobs from Docusnap365. A job set to run
immediately starts right away; a scheduled job is executed by the gateway
itself on its schedule — even without a browser open. It receives the
credentials for a scan from the vault only for the duration of the run.

**Results.** Every scan module writes its results to encrypted files. Once a
job finishes, the gateway uploads them to the transfer storage; the backend
processes them into your database.

**Updates.** The gateway updates its scan modules itself, without a
reinstall. New modules and fixes arrive without your intervention.

## Data flow

1. The gateway scans and uploads the results to the transfer storage.
2. The backend processes the results and writes them to your database.
3. The web interface reads from your database and writes changes back.
4. Exports and generated documents live in storage and are ready for
   download.

## AI assistant

The AI assistant uses language models **operated in Europe**. Processing is
covered by a data processing agreement. Your questions and the data read to
answer them are not processed outside Europe. Details:
[Permissions and Data](/docs/en/assistant/permissions-and-data).

## Next steps

[Security](/docs/en/getting-started/security) describes how credentials,
transmission and your data are protected. To start scanning:
[Scanning Your Network](/docs/en/getting-started/inventory).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.