Solution architecture and data flow for enterprise security reviews.
CloudFix — Core Architecture
How CloudFix connects to your AWS environment, what it reads, and how approved fixes are executed — without any third-party ITSM integration.
Figure 1 — CloudFix core architecture. Data flows left (CloudFix platform) ↔ right (customer AWS account). No application data is accessed; only infrastructure metadata.
CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary — customer must approve before fixes execute
CloudFix + ITSM Integration
How CloudFix integrates with service desk and ITSM platforms via webhooks and the CloudFix REST API.
Figure 2 — CloudFix + ITSM integration. CloudFix raises a webhook to your service desk when a recommendation is ready. The service desk routes approval through its own workflow, then calls the CloudFix API to signal approval. CloudFix then triggers execution via AWS Systems Manager.
Service desk / ITSM platform
CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary
No customer AWS data passes through the service desk platform. Webhook payloads contain only CloudFix recommendation metadata: AWS resource IDs, estimated savings amounts, service type, and approval status. No S3 contents, database records, application data, or credentials are ever included.
Need the diagrams in another format?
Request a Visio, draw.io, or high-resolution PNG version for your security review pack.