Architecture diagrams drawn from the scan
Blueprint lays out regions, VPCs, subnets and the services inside them, using the same read-only scan that produces your findings. Export it for a design review and it matches what is running today.
- 1Draw from the scan
Blueprint reads 84 resources and lays out eu-west-1, prod-vpc and the public, private and data subnets from where each one runs.
- 2Spot the risk on the tiles
bastion in the public subnets carries a port 22 open flag. customer-exports in the data subnets carries a PII label.
- 3Export as SVG
checkout-blueprint.svg exports with 11 tiles and 5 boundaries, ready to drop into a design doc.
Your cloud changes daily, your diagram does not
Design reviews, onboarding and incident calls all run on a picture someone drew months ago.
Hand-drawn diagrams go stale
What usually happens: The diagram was right the week it was drawn. Six months later it's missing two services and a VPC peering.
How CloudLens resolves it: Blueprint redraws from each scan, so the diagram changes when the account does.
ResolvedReviews stall on basic facts
What usually happens: Half of a threat-model session goes to working out whether the queue really sits in a private subnet.
How CloudLens resolves it: Subnet and VPC boxes come from where resources actually live, so the review starts from what's deployed.
ResolvedRisk lives in another tool
What usually happens: The architecture doc shows clean boxes, and the exposure sits in a scanner export nobody attaches.
How CloudLens resolves it: Open ports, internet exposure and data classes are drawn on the tiles they belong to.
ResolvedPreparing a design review with Blueprint
Tom is planning to move payments out of the checkout service and needs an accurate starting diagram.
Lumora Retail is a fictional company. The people, names and numbers are sample data.
Starts from the front door
Switches to Blueprint
Notices the data tier
Exports PNG and SVG
Reopens it after the split
Start from a diagram of what's actually deployed
The diagram your team never has to redraw
Atlas draws from the same read-only scan that powers findings, so the diagram and the risk describe the same estate.
Scope a diagram by how requests arrive
- Public entry points listed
- Only tiles on the request path
- Internet-exposed markers
- 1Pick checkout.lumora-retail.example
The diagram keeps 5 of 11 tiles: Route 53, checkout-cdn, checkout-lb, checkout-api and orders-db. Everything else dims.
- 2Switch to api.lumora-retail.example
The request path changes to public-api, tickets-fn and support-tickets. A different front door leads to a different data store.
- 3Check images.lumora-retail.example
Requests pass through image-cdn to image-resizer, which reaches customer-exports. That hop belongs on the review's list of questions.
Regroup the estate around your question
- Apps by application tag
- Networks by VPC and subnet
- Services by AWS service
- 1Start from the Traffic lens
Tiles sort into front doors, what sits behind them, and data. checkout-cdn and checkout-lb are marked Internet-exposed.
- 2Regroup by app and type
The same tiles move into app: checkout, app: media and app: support, then into networking, compute, identity and data.
- 3Check Networks and Services
Networks separates prod-vpc public and private subnets from regional services with no VPC. Services lists one group per AWS service.
- Graph: relationships
- Blueprint: boundaries and tiles
- Lanes: internet to private to data
- 1Click a tile in Graph mode
checkout-api opens with its region, owner and hierarchy. It sits behind checkout-lb, runs as checkout-task-role and reaches orders-db.
- 2Switch to Blueprint
The tiles move into Edge, Compute and Identity & data boxes, closer to a hand-drawn architecture diagram.
- 3Switch to Lanes
The same tiles line up from Internet-facing through Private to Data, which is how most threat models read.
Diagrams you can put in a design doc
Service-level tiles
One tile per service with its type and name, at the density of a hand-made architecture diagram.
Real boundaries
Region, VPC and subnet boxes come from where resources actually live.
Risk on the picture
Open ports, internet exposure and data classes appear on the tiles they belong to.
PNG and SVG export
Put the current diagram in a design doc, a threat model or an audit pack.
About architecture diagrams
From the same read-only scan that builds the Security Graph. There is nothing to install and nothing to draw. The layout is computed from where resources live and how they connect.
The Traffic lens only treats entry points that route requests to workloads as front doors. Validation records and gateways without routes are left out.
Yes. Export the current view as PNG or SVG. The export reflects the lens and mode you have selected.
Get an accurate diagram of your own cloud
Connect a read-only AWS role or Azure service principal. We'll walk you through your bill, your security graph and the first things worth fixing.
