Product

The architecture review board, generated.

From requirements capture to immutable approval and beyond, IronArchitects runs the entire compliant-design lifecycle: AI does the heavy lifting, your governance stays in control, and the evidence writes itself.

Capture

Start from intent, not a blank canvas.

A design package captures the use case, the data classes involved (PHI, cardholder data, PII), residency, RTO/RPO, SLA, and threat profile. Templates and predefined input fields pre-fill requirements, policies, and team assignments so intake is consistent across the org.

  • Bring existing material: documents, PowerPoint, Visio, draw.io, and Mermaid all feed the run, or import requirements straight from a Jira epic and export them back when they change.
  • A curated technology catalog defines what's approved, candidate, and forbidden, with vendor contracts and in-use counts.
  • Your knowledge base (standards, prior designs, vendor docs) grounds every generation via retrieval.
  • Discovery agents inventory your real environment (cloud estates, APIs, databases, CMDB assets, org structure, file stores) so designs integrate with what exists. Metadata only, never data values.
  • Every package gets a human-readable Design ID (like ACME-0042) for referencing across reviews and audits.
Use caseMember claims portal, external-facingCaptured
DataPHI + PII · US residencyClassified
ResilienceRTO 15m · RPO 5m · 99.9% SLASet
FrameworksHIPAA + SOC 2 + org security standardApplied
Catalog42 approved technologies · 3 vendor contractsEnforced
Generate

Describe it. Get a whole design.

The AI engine assembles components, data flows, technology choices, and deployment topology from your approved catalog, constrained to your controls. Four specialist AI reviewers then critique and deliberate, and a remediation loop closes gaps automatically before you ever see the design.

  • Design alternatives with trade-offs scored on cost, compliance, and complexity.
  • Live grounding: real CVE data, live cloud pricing, and your knowledge base.
  • Refine conversationally, with every version kept and architect overrides locked against re-runs.
C4 L1System contextRendered
C4 L2Containers with trust zonesRendered
C4 L3ComponentsRendered
C4 L4Deployment · multi-AZRendered
DFDPHI flows crossing DMZ boundary2 flagged
Diagram

Every level drawn. Nothing drawn by hand.

All four C4 levels (context, container, component, deployment) plus data-flow diagrams render automatically from the architecture spec. Trust zones are classified per component, data flows carry their data-class labels, and boundary-crossing flows are flagged as compliance risks.

  • Interactive canvas with pan and zoom; edit in the built-in draw.io editor.
  • Lossless round-trip: export to draw.io, edit, re-import, and the structure survives.
  • An org-wide diagram standard keeps shapes, zone colors, and fonts consistent, with semantic colors fixed (red = gap, green = encrypted).
  • Versioned, optionally locked on approval, and exportable to PDF, PNG, and Lucidchart.
Analyze

Scored on every axis that matters.

One design run produces the analysis a review board would take weeks to assemble.

Control coverage

Every applicable control evaluated against machine-checkable assertions, severity-ordered, with pass, fail, remediable gap, and residual risk called out per control.

Well-Architected scoring

Deterministic, citable scores against the AWS, Azure, and GCP pillars, with per-pillar drill-down showing exactly which decision earns or loses points.

Threat modeling

STRIDE threat trees tied to your actual data flows and trust boundaries, plus VERIS threat-vector classification derived from your industry and data sensitivity.

Live-priced cost card

Per-service SKU breakdown with monthly and annual TCO, per-data-class attribution for chargeback, and your negotiated vendor discounts applied automatically.

ROI value model

Quantified value delivered per design (speed to market, efficiency, compliance cost avoidance, risk reduction), rolled up across the portfolio for executives.

Narrative & ADRs

A generated design narrative that reads like an architect's pitch, and Architecture Decision Records auto-captured from every major choice, versioned with the design.

Govern

Approval that would survive a deposition.

Structured review workflow with real gates: a package cannot be approved while it has open gaps without accepted exceptions, failed controls without risk treatments, or blocked AI verdicts. Sign-offs are unanimous, segregated, and immutable.

  • Draft → In Review → Changes Requested → Approved → Superseded, with all reviewers required to approve.
  • Segregation of duties: risk acceptance and flagged overrides need a different principal than the final approver.
  • An org-wide exceptions register tracks deferred gaps, accepted risks, and waived controls with owners and expiry dates.
  • Approved versions are locked; edits create a linked revision while the approved baseline stays intact for auditors.
Gate0 open gaps · 0 unaccepted risksReady
Review3 of 3 reviewers approvedUnanimous
SoDRisk accepted by a different principalEnforced
RecordApproval hash-chained · tamper-evidentImmutable
v2Revision opened · baseline preservedLinked
PDF Word draw.io Lucidchart Mermaid Terraform Bicep Pulumi
Deliver

The audit binder, generated.

Every design exports a complete deliverable set: the System Security Plan, data-flow diagrams with trust boundaries, the STRIDE threat model, an SBOM, the control traceability matrix, a deployment runbook, and parameterized infrastructure-as-code (Terraform, Bicep, or Pulumi) for the approved design.

  • PDF for immutability, Word for customization, draw.io and Mermaid for living diagrams.
  • Infrastructure-as-code output turns the approved design into a deployment starting point, not shelfware.
  • Every deliverable is backed by the immutable approval record it was generated from.
Operate

"Approved" stays true, or you hear about it.

Approval isn't the finish line. When a control pack is updated, a policy tightens, or a technology falls off the approved list, IronArchitects re-evaluates your approved portfolio and surfaces exactly which designs drifted and why.

  • A portfolio view of all approved and superseded designs with drift status and expiring exceptions.
  • Bulk re-evaluation when a framework version changes, so nothing silently rots.
  • Revise, archive, and supersede with full lineage; archived designs stay searchable for regulatory record-keeping.
  • Email notifications with per-org and per-user policies keep reviewers and owners in the loop.
ISO 27001Pack upgraded to 2026 revision4 designs stale
ACME-0018Re-evaluated · 2 new control failuresNeeds revision
ACME-0023Re-evaluated · still compliantClean
ExceptionStream-processing waiver expires in 14 daysOwner notified
Portfolio31 approved · 4 drifted · 1 expiring exceptionVisible
Built for teams

Governance-grade collaboration.

Teams & fine-grained roles

Packages belong to teams. Sixteen-plus granular permissions compose into custom roles, with defaults for Architect, Compliance Officer, Privacy Officer, and Enterprise Architect.

Versioned documents

A built-in rich editor for narratives, requirements, and policies, with immutable version history, comparisons, and who-changed-what tracking.

Architecture chat

Ask an approved or in-progress design questions and get grounded, cited answers. Available on the Enterprise tier, with abuse monitoring built in.

Notification policies

Email on review requests, approvals, design completion, and membership changes, governed by a three-tier platform, org, and user policy with one-click unsubscribe.

Legal hold & retention

Freeze records under legal hold, enforce retention policies, and keep compliance attestations locked. Regulated record-keeping is first-class, not an afterthought.

API keys & webhooks

Scoped API keys for CI/CD, a public REST API with Swagger docs, and HMAC-signed webhooks on run completion, approval, and incident events.

Run your first design through the whole lifecycle.

Capture the intent, watch the AI engine design and review it, and export the audit binder. Free for 30 days.