Generate and govern designs where your work already lives: point discovery agents at your cloud, APIs, databases, and CMDB, sync requirements with Jira, turn approved designs into Terraform, Bicep, or Pulumi, stream the audit trail to your SIEM, and wire it all into CI/CD through a scoped public API.
Available shipped today · Beta limited / bring-your-own-license · Roadmap planned
Read-only agents inventory what you actually run, so generated designs integrate with it. Metadata shapes only, never data values; every run is authorized and audit-logged. Portfolio plans and up.
Hand over a drawn design, not just a description.
The approved design becomes the starting point for what you actually deploy.
Everything the app can do, from your pipeline.
Authenticate and provision with the identity provider you already run.
Feed the tamper-evident audit trail into the tools your SOC already watches.
Nothing here for you to configure; these are the engines that power the platform, listed for transparency.
Pull requirements in, publish deliverables out, and keep the CMDB honest.
The public REST API (Medium plans and up) is the same gateway surface the app uses, authenticated with a scoped API key instead of a user session, so you can start design runs, re-evaluate against current controls, and pull auditor deliverables straight from CI/CD.
403.Retry-After on 429./api/docs, so you can explore every endpoint before writing a line of code.Subscribe a URL to design-run completion, approval, and incident events and receive a signed POST when they fire; verify with HMAC-SHA256 over the raw body.
Keys are issued, rotated, and revoked from Settings, independent of any user account, so a departure never breaks your pipeline.
Authentication, authorization, and tenant isolation run on a hardened identity layer, not a bolt-on.
Federate your identity provider over OAuth 2.0 / OIDC (Microsoft Entra ID, Okta, and any standards-compliant OIDC IdP), powered by Keycloak identity brokering.
16+ granular permissions compose custom roles for Compliance Officers, Privacy Officers, and Enterprise Architects, least privilege by construction and fully delegable.
Every request runs under its organization's context with PostgreSQL row-level security, so one tenant can never read another's data, enforced in the database.
Programmatic access uses organization-bound API keys with explicit scopes, issued, rotated, and revoked from Settings, independent of any user account.
Automated provisioning and deprovisioning over SCIM 2.0 (RFC 7643/7644), Users and Groups with group-to-role mapping, plus organization-enforced multi-factor authentication.
Security-relevant actions are written to a hash-chained, tamper-evident audit log, searchable and verifiable in-app and streamed to your SIEM (Splunk, Datadog, or syslog), with configurable session timeouts enforced org-wide.
The public API and webhooks already let you wire IronArchitects into almost anything. Tell us what's on your roadmap and we'll tell you what's on ours.