Blueprint a reference security architecture
Draw a system on an editable canvas โ or start from the blueprint wizard or a built-in reference architecture โ and get a live compliance coverage read against NIST 800-53, CIS v8, ISO 27001, PCI DSS or SOC 2, generated Architecture Decision Records, and exports including a Terraform scaffold. Free with any signed-in PlayCISO account.
What it gives you
Component canvas
Drag edge, gateway, compute, data and ops components onto a free-form board, wire them with labeled connections, resize and annotate โ a full diagramming canvas underneath, not a fixed template.
Blueprint wizard & reference architectures
Answer five questions and get a proposed diagram, or load one of the built-in editable references โ fintech payments, healthcare, AWS/Azure/GCP security foundations, zero trust, Kubernetes hardening and more โ then adapt it.
Live framework coverage
A coverage score against the frameworks you pick (NIST 800-53, CIS v8, ISO 27001, PCI DSS, SOC 2), broken down control-by-control with status, responsibility and confidence โ recomputed whenever you re-check it.
Generated ADRs
Ask for a decision record on any topic in the design and get a drafted ADR โ decision, rationale, consequences, alternatives โ that you can edit, re-status, or delete.
Exports that keep the work
PNG or SVG of the diagram, JSON of the canvas and findings, a CSV statement of applicability, ADRs as Markdown, a Terraform scaffold, and a printable PDF brief.
How it works
- 1Start blank, run the blueprint wizard (pattern, cloud, scale, data classification, compliance regimes), or load an editable reference architecture.
- 2Drag components onto the canvas by tier โ edge, gateway, compute, data, ops โ and connect them; everything stays editable.
- 3Re-check coverage to get a control-by-control read against your chosen frameworks, and add evidence notes per control.
- 4Draft ADRs for the decisions that matter, then export the diagram, control map, ADRs and a Terraform scaffold.
Honest about what this is
- A fast way to get a real diagram, a first compliance read, and drafted ADRs down โ then keep editing.
- Useful for design reviews, a starting statement of applicability, or scaffolding IaC for a new system.
- โ Not a certified audit and not a scan of a live environment โ nothing connects to your actual cloud account.
- โ The Terraform export is a scaffold with TODOs, not apply-ready infrastructure code.
FAQ
What does Architecture Studio actually produce?
A visual reference architecture on an editable canvas โ components (edge, gateway, compute, data, ops tiers) wired together with labeled connections โ plus a compliance coverage read against NIST 800-53, CIS v8, ISO 27001, PCI DSS or SOC 2, a set of Architecture Decision Records (ADRs), and export files you can keep.
What does the "coverage" score mean?
It is a control-by-control read of your diagram against the frameworks you pick: each control is marked met, partial, or gap, with a responsibility tag (customer / provider / shared) and a confidence rating. It is a starting assessment to challenge and annotate with evidence, not a certified audit.
Is the Terraform export production-ready?
No โ it is a deterministic scaffold, one resource block per component with secure-default hints as comments and required arguments left as TODOs. It saves you the blank page; you still fill in real values and review it before applying anything.
Do I need to design from scratch?
No. The blueprint wizard asks five questions (pattern, cloud, scale, data classification, compliance regimes) and an AI proposes a starting diagram, control map and ADRs โ or load one of the built-in editable reference architectures (fintech, healthcare, AWS/Azure/GCP security foundations, zero trust, Kubernetes hardening, and more) and adapt it.
Is it free?
Yes โ Architecture Studio works with any signed-in PlayCISO account, free included. There is no paywall on the tool itself; a paid plan is only useful if you want higher usage limits or work across the other studios as a team.