Archplorer automatically discovers your applications, their dependencies, their owners and their deployment environments — directly from your code, your pipelines and your cloud. No file to maintain by hand.
Read-only agents · Deployed in your infrastructure · No inbound access to your systems
And it was already wrong the day it was drawn. Classic developer portals just move the problem: instead of an outdated diagram, you get hundreds of catalogue files that nobody maintains any more.
A critical CVE is published for a widely used library. Nobody knows which applications embed it, in which versions, or who maintains them.
The service goes down. The team that wrote it has been reorganised twice since. The documentation points to a disabled e-mail address.
A new architect has to mentally rebuild the whole system from scattered conversations and Git repositories.
Archplorer is built on a strict Hub & Spoke architecture. Agents run on your side and push their results to the Hub. The Hub never initiates any call to your systems.
A command-line tool, installed in your CI or on a runner of your choice. It reads your repositories, your dependency manifests, your pipelines and your cloud resources. Read-only.
Applications, executables, repositories, libraries, environments, teams and domains are linked in a queryable graph. Every new scan brings the map up to date.
No link is ever created automatically. Uncertain matches land in a review queue, with a confidence score and a justification. You accept or reject them.
Graph, catalogue, dependency matrix, review queue. No outbound connection to your infrastructure.
Every relationship is projected into a graph. Questions that used to take a meeting now take a second.
Every application that depends on this one, directly or indirectly, with its depth. Before you deploy, not after.
How does application A reach application B? The exact path, hop by hop, with the type of each dependency.
Circular dependencies between applications, surfaced automatically.
Who uses this library, in which version, and with what vulnerability status.
12 applications · 17 dependencies · 4 topics · 1 cycle
Every library in every application is inventoried, versioned, and continuously checked against public vulnerability databases.
NuGet · npm · Maven · PyPI · Go — from your real manifests, not from a declaration.
For every package, in every application, in every deployed version.
Trace a library up to the application, then to the team responsible for it.
All your applications, filterable by business domain, owning team, criticality and lifecycle stage. A governance score flags orphaned or incomplete applications.
For every application: its repositories, its executables, its inbound and outbound dependencies, its deployment environments, its team and its domain. Plus the list of applications it would impact if it went down.
For dependencies no manifest declares — an HTTP call, a message queue, a shared database — Archplorer explores the repository and proposes the links it finds.
The agent walks the file tree, opens the relevant files and follows leads, instead of applying a fixed list of regular expressions.
Every proposal arrives in a review queue with its confidence score, its justification and the source file behind it. A contributor accepts or rejects it. No edge is ever created automatically.
Every link keeps a record of its origin: exact match, approximate match, model inference, or manual entry.
Model-assisted analysis is optional and disabled by default. The heuristic analysers work entirely offline. The model endpoint is one you configure yourself.
Archplorer is designed to keep its exposure surface minimal and verifiable.
The Hub never initiates a connection to your infrastructure. It needs no inbound port opened, no service account on your side, no network access to your systems.
Agents transmit names, versions, URLs and relationships. Source code never leaves your agents to reach the Hub.
Agents write nothing, modify nothing, trigger nothing in your systems.
Language-model analysis is disabled by default. When enabled, the endpoint is the one you configure — including a gateway hosted in your own environment.
No changes needed in your repositories. No file to add.
On the cloud: App Service, Azure Functions, AKS, Container Instances, Lambda, ECS, EC2, Cloud Run, Cloud Functions, GKE and Compute Engine.
A pre-populated demo environment, no sign-up required. Click an application, trace its dependencies, measure its blast radius.
Pricing on request.
One organisation, a narrow scope.
Multiple business domains, multiple teams.
Regulatory constraints or a specific scope.
Archplorer is under active construction. Our partner programme will open soon: it will give a small number of organisations early access and a direct line to the team to help shape the product with us. If your system landscape is complex and poorly documented, that's exactly the context that interests us.
Thirty minutes. We'll show you the product on a system landscape comparable to yours, and answer your integration and security questions.