Loading security overview...
Initializing...
Intelligent Cloud Architecture Platform
Google sign-in and sign-up are coming soon. Please use email and password for now.
Don't have an account? Sign Up
Platform management and statistics
Need help? support@cloudlensai.cloud (Reply within 2-5 business days)
Usage metrics and insights
View and download your past assessments
Loading your history...
Select a cloud provider to begin your architecture assessment
Manage your CloudLens display and account session.
Signed in as Signed-in user
Review recommended fixes before making any AWS change.
Loading remediation plans...
Choose an action for your AWS architecture
Evaluate your architecture against Well-Architected pillars
1-3 Credits Works with a diagram, a text description, or a live accountUpload a diagram to estimate monthly AWS infrastructure costs with detailed assumptions
2 Credits β¨ NEW No AWS expertise needed β see your bill before you buildUpload a diagram and generate Terraform or CloudFormation code with optional compliance scoring
10-12 Credits β¨ ENHANCEDSimulate Graviton modernization, WAF protection, and custom architecture trade-offs with live TCO & pillar deltas
Free Sandbox β¨ SIMULATOR Zero risk β test cost & resilience before writing codeSecurely connect your AWS account for automated assessment
Free PREVIEW Read-only access β we never store your credentialsSelect a framework to scan your AWS environment against
Live account status is shown on each card. Only standards marked Active are ready to scan.
AWS-managed foundational checks across commonly used AWS services
Industry-standard security baseline with 53 security recommendations
Payment Card Industry Data Security Standard for payment processors
Latest CIS benchmark with enhanced security controls and updated recommendations
Protecting Controlled Unclassified Information in nonfederal systems
Security and Privacy Controls for Information Systems and Organizations
These frameworks will be available in future updates
Health Insurance Portability and Accountability Act for healthcare data
Trust Service Criteria for service organizations
International information security management standard
Federal information systems security controls
EU General Data Protection Regulation compliance
Enable live compliance scanning and security monitoring
Connect your AWS account to enable:
We believe in complete transparency. Here's exactly what happens in your AWS account:
Creates: An IAM role named CloudLensAssessmentRole
Purpose: Allows CloudLens to read (not modify) your AWS resources for assessments
Security: Uses External ID validation to prevent unauthorized access
Permissions: Read-only access to:
βΉοΈ No Write Access: CloudLens cannot create, modify, or delete any resources in your account
Creates: Configuration recorder and delivery channel
Purpose: Track resource configuration changes over time
Data Storage: Creates an S3 bucket in your account to store configuration snapshots
Cost: ~$2/month (billed by AWS based on configuration items)
βΉοΈ You can disable this by unchecking the AWS Config option below
Enables: AWS Security Hub in your account
Purpose: Centralized security findings and compliance checks
Standards: Automatically subscribes to:
Optional Standards: You can enable these below:
Cost: ~$1.20/month for findings collection + $0.0010 per check per standard
β±οΈ Initial Setup: Security Hub takes 20-30 minutes to analyze your account after enabling
Creates: A Lambda function named
CloudLens-Service-Manager
Purpose: Automatically enables selected services during CloudFormation deployment
Runtime: Python 3.13
Execution: Runs once during stack creation, then remains for management
Cost: Free tier eligible (minimal invocations)
βΉοΈ This Lambda function ensures services are properly configured based on your selections
| AWS Config | ~$2.00/month | (Optional - can disable) |
| Security Hub - Findings | ~$1.20/month | (Optional - can disable) |
| Security Hub - Checks | ~$0.10-$0.30/month | (Per standard enabled) |
| Lambda Function | $0.00 | (Free tier eligible) |
| IAM Role | $0.00 | (No charge) |
| Total Monthly Cost | ~$3.20-$3.50 | Billed by AWS |
π‘ CloudLens Charges: Assessments cost credits (5 credits per scan), not billed by AWS
CloudLens can ONLY read data, never modify or delete
Unique external ID prevents unauthorized role assumption
All AWS data remains in your account - we only read assessment results
Delete the CloudFormation stack to instantly revoke all access
All API calls are logged in your CloudTrail for full audit trail
We don't store access keys - using IAM role assumption is safer
CloudLens uses a credit-based system. We do NOT add charges to your AWS account.
Security Hub & Config are OPTIONAL. Uncheck them above to avoid any AWS charges.
The IAM role for read-only access has NO cost. AWS doesn't charge for IAM roles.
Our management Lambda runs ~once/month. Well within AWS free tier limits.
| CloudLens Platform | Credits only (not AWS) |
| IAM Role | $0.00 - Always Free |
| Lambda Function | $0.00 - Free Tier |
| Security Hub (if enabled) | ~$1.20/month |
| AWS Config (if enabled) | ~$2.00/month |
β Bottom Line: If you only enable the IAM role (minimum required), your AWS bill increases by exactly $0.00.
Securely connect your AWS account for automated assessments
Checking connection status...
Securely connect your Azure subscription to access Microsoft Defender for Cloud findings
Checking connection status...
Upload your architecture diagram to generate IaC
Drag & drop or click to upload (JPG, PNG, WebP)
or click to browse (.tf files or .zip archive)
Paste any Terraform HCL or CloudFormation template. CloudLens AI parses VPCs, subnets, instances, and databases, maps topology connections, performs automated security audits (encryption, public ingress, multi-AZ resilience), and injects compliance badges directly into Draw.io diagram nodes.
Or drag & drop a .tf, .yaml, or .json file
Describe your idea to generate a Draw.io XML diagram
Be precise! Example: "A highly available web app with an Application Load Balancer, Auto Scaling Group of EC2 instances in private subnets, and an RDS database."
View your previous architecture assessments
Loading history...
Choose how you want to assess your architecture
Upload an architecture diagram image for AI analysis.
Scan your connected AWS account for configuration issues.
Select a Well-Architected Pillar to scan (5 Credits)
Choose how you want to assess your Azure architecture
Upload an Azure architecture diagram for AI analysis.
Scan your connected Azure subscription using Azure Advisor recommendations.
Select a pillar to view Azure Advisor recommendations
Select a pillar to assess your architecture
Select a pillar to assess your architecture
Select a compliance framework and upload your architecture diagram
β οΈ Architecture Readiness Assessment - not a formal audit. Full compliance requires policy documentation and formal verification.
Upload your architecture diagram for analysis
or click to browse
Supports: JPEG, PNG, GIF, WebP (Max 10MB)
Loading security overview...
Loading security overview...
Upload an architecture diagram to estimate monthly AWS infrastructure costs
Drag & drop or click to upload your AWS architecture diagram (JPG, PNG, WebP)
Simulate modernizations, architectural trade-offs, and live cost/security impacts before writing code
Choose a starter architecture below (or bridge your custom code from the Bi-Directional Canvas). Live baseline cost and Well-Architected pillar scores load immediately.
Test Graviton ARM64 migration (-20% cost), Edge Shield with WAF, Aurora Serverless v2, or S3 Intelligent-Tiering with zero risk and 0 credits used.
Review annualized savings, carbon footprint cuts, and pillar score gains. Download the updated Draw.io diagram or synthesize Terraform code directly.
Migrate x86 compute & RDS to AWS Graviton (m6g/c6g) for 20% lower cost and higher performance.
Attach CloudFront CDN and AWS WAF with Managed OWASP Core Rules to protect endpoints.
Convert fixed RDS instance to auto-scaling Aurora Serverless with 6-way Multi-AZ replication.
Replace NAT Gateway data egress fees for S3/DynamoDB with free private Gateway Endpoints.
Apply automated lifecycle rules to move cold data to Glacier without retrieval fee penalties.
Upgrade single-AZ databases and compute instances to multi-AZ active/standby for 99.99% SLA.