Diagrams

How the pieces fit together, drawn out.

One page per drawing, each with the plain-English read underneath it.

High-Level Architecture

The hub in your own cloud account, a read-only collector in every cloud it covers — including its own — and the single outbound connection that crosses the boundary.

View the diagram →

Scan Cycle

All nine steps of a scan, the exact API called in each cloud at each one, and why every one of them is a read.

View the diagram →

Permission Model

Side by side across AWS, Azure and Google Cloud: the identity used, the role granted, how long the credential lives — and write access nowhere.

View the diagram →

AWS Infrastructure

Every resource the AWS template creates — VPC, ECS Fargate, RDS, ElastiCache, CloudFront and the rest — and what each one is for.

View the diagram →

Azure Infrastructure

Every resource the Azure template creates — App Service, PostgreSQL Flexible Server, Redis Enterprise, Key Vault and the rest — and what each one is for.

View the diagram →

GCP Infrastructure

Every resource the GCP deployment creates — Cloud Run, Cloud SQL, Memorystore, Secret Manager and the rest — and what each one is for.

View the diagram →

More are on the way — identity flow, end to end. Need one sooner? Email support@cloud-vex.com.

Join the waitlist