Solution architecture and data flow for enterprise security reviews.
CloudFix — Core Architecture
How CloudFix connects to your AWS environment, what it reads, and how approved fixes are executed — without any third-party ITSM integration.
Figure 1 — CloudFix core architecture. Data flows left (CloudFix platform) ↔ right (customer AWS account). No application data is accessed; only infrastructure metadata.
CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary — customer must approve before fixes execute
CloudFix + ITSM Integration
How CloudFix integrates with service desk platforms (ServiceNow, Jira Service Management, and similar tools) via webhooks and the CloudFix REST API.
Figure 2 — CloudFix + ITSM integration. CloudFix raises a webhook to your service desk when a recommendation is ready. The service desk routes approval through its own workflow, then calls the CloudFix API to signal approval. CloudFix then triggers execution via AWS Systems Manager.
Service desk platform (ServiceNow, Jira, etc.)
CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary
No customer AWS data passes through the service desk platform. Webhook payloads contain only CloudFix recommendation metadata: AWS resource IDs, estimated savings amounts, service type, and approval status. No S3 contents, database records, application data, or credentials are ever included.
Need the diagrams in another format?
Request a Visio, draw.io, or high-resolution PNG version for your security review pack.