Application Intelligence  ·  AI-Native · AWS Bedrock

Your Application Estate,
Decoded by AI.

Aufsite CodeLens is a single-tenant AI platform that ingests your source code, documentation, and database schemas — then delivers structured analyses and living documentation entirely within your own AWS account.

100%
In Your AWS Account
0
Free-Form Prompts
Single
Tenant Per Engagement
Full
Audit Trail

What Is CodeLens?

AI That Understands Your Application

Complex, long-lived application estates — layers of undocumented business logic, aging back-office systems, missing architecture records — are notoriously difficult to document, modernize, or hand off. CodeLens changes that.

It reads your actual source code, not just comments. It parses code, config, database schemas, and supporting documentation into a deterministic structural index, then runs your LLM of choice on AWS Bedrock over that index to produce structured analyses and Word/PDF deliverables — ready for your team on day one.

Because it runs entirely inside your AWS account, your code never crosses a trust boundary. CodeLens is read-only toward your application — it observes, indexes, and narrates; it never modifies your systems.

☁️
Deployed in Your AWS Account

ECS Fargate + DynamoDB + Bedrock — single CloudFormation stack, installed in minutes

🔍
Structural Code Intelligence

Parses any stack — source code, schemas, config, and documentation — not just search, actual comprehension

📄
Deliverables, Not Just Answers

Generates downloadable Word, PDF, and Markdown documents — client-ready, audit-logged

🔒
No Free-Form Prompting

Users select parameterized analyses — no data leakage, no hallucination from open-ended input


How It Works

From Source Code to Living Documentation

A five-stage pipeline — entirely inside your AWS account — that turns raw application assets into structured, citable, downloadable intelligence.

Input
🗂️
S3 Drop Zone
source/ docs/ db/
Drop your assets here
Ingest
Parse
⚙️
Structural Index
Any Stack · Schemas
Config · Docs
Retrieve
AI Core
🤖
Bedrock + KB
LLM of Choice via Bedrock
RAG + Keyword Search
Analyze
Engines
📊
Analyses & Q&A
Parameterized
Citation-Bound
Generate
Output
📑
Deliverables
Word · PDF · Markdown
Audit-Logged Downloads
🔒 All processing stays inside your VPC 📖 Read-only — never modifies your systems 🛡️ All ingested content isolated in <untrusted_data> guards Full demo mode available with bundled sample corpus

Platform Capabilities

Everything an Engagement Needs to Deliver

🔍

Deep Code Analysis

Structural parsing across any technology stack — source code, service interfaces, schemas, and config files. Builds a deterministic inventory of components, endpoints, dependencies, and traceability links.

🤖

Your LLM of Choice — In Your Account

Model inference runs via AWS Bedrock in the customer's own account. Choose the model that fits your requirements. Your source code and documentation never leave your AWS boundary — ever.

📚

Bedrock Knowledge Base

Optional Bedrock Knowledge Base with OpenSearch Serverless for semantic retrieval — merged with exact-identifier keyword search for precision and recall across large codebases.

📋

Selectable Parameterized Analyses

Users choose from a curated catalog of analyses — architecture overviews, data flow diagrams, gap assessments, traceability reports. No open-ended prompting; no hallucination risk.

💬

Scoped Q&A with Citations

A guarded Q&A interface lets users ask natural language questions about the application — but only with read-only tools and citation-bound answers. The AI guard runs before every model call.

📄

Client-Ready Deliverables

Every analysis can be exported as a Word document, PDF, or Markdown file. Deliverables are registered in an audit log, available for download, and branded to match your engagement.

☁️

Single CloudFormation Stack

The entire production environment — ALB, ECS Fargate cluster, DynamoDB tables, Bedrock KB — deploys from a single CloudFormation template. Full rollback journal if anything goes wrong.

🖱️

Double-Click Installer

A browser-based install wizard handles AWS provisioning, updates, and rollbacks — no CLI expertise required. Deploy, update, or tear down with a point-and-click ops console.

👤

Flexible User Management

Supports SSO for enterprise identity providers or built-in local accounts with scrypt hashing, admin bootstrap, forced first-login change, role-based access (admin/member), lockout, and full audit trail.


Who It's For

Built for Complex Application Estates

CodeLens is designed for organizations where understanding the application is the hard part — before modernization, migration, or handoff can even begin.

01
🏦

Financial Services & Insurance

Large-scale legacy back-office systems with years of layered changes, missing documentation, and compliance obligations. CodeLens produces the audit-ready architecture record your team needs.

02
🔄

Application Modernization Programs

Before you refactor or re-platform, you need to understand what you have. CodeLens accelerates discovery by producing a living knowledge base from your actual source — not interviews and tribal knowledge.

03
🤝

System Integrators & Consultancies

Deploy one CodeLens instance per client engagement. Speed up onboarding, reduce dependency on client SMEs, and deliver structured documentation as a standard deliverable — at every project close.

04
📋

GRC & Compliance Teams

Map application behavior to regulatory requirements. CodeLens traces data flows, identifies control points, and generates gap reports — all citation-bound to the actual source code.


Security & Trust

Evidence-First. Read-Only. Yours.

Every design decision in CodeLens reflects a single principle: the AI should assist your team, never act autonomously, and never take a risk with your customer's data.

The security model isn't a checkbox — it's the architecture. From the way ingested code is handled to how every deliverable download is logged, trust is built into each layer.

Read-Only Toward Customer Systems CodeLens reads from S3; it never writes to, modifies, or executes against your application environment.
Untrusted-Data Isolation All ingested source code and documentation reaches the model inside <untrusted_data> delimiters — the AI narrates; it never executes or trusts customer content as instruction.
AI Guard Before Every Model Call The Q&A guard runs BEFORE any model call in the scoped interface — no prompt injection, no boundary escape.
No Free-Form Prompting Surface Users select from a parameterized action catalog. There is no open prompt box — eliminating the primary vector for prompt injection and data leakage.
Full Audit Trail Every deliverable download, user action, and admin event is written to an immutable DynamoDB audit log. Local JSON fallback ensures no silent gaps.
Scrypt Password Hashing + Lockout Local accounts use scrypt — not bcrypt, not MD5. Admin bootstrap forces a first-login password change, and repeated failures trigger automatic lockout.

Our Approach

The 3Ds: Live in Your Account in Weeks

Aufsite's proven engagement methodology — scoped, fast, and built to hand off cleanly.

01
Discover

We review your application estate, identify the source assets to ingest, map the documentation gaps you need to close, and scope the deliverables for your engagement.

02
Design

We configure the analysis catalog for your domain — which engines to enable, which deliverable templates to use, how branding and user roles are set up for your team.

03
Deploy

We provision CodeLens into your AWS account via CloudFormation, load your source corpus, validate the knowledge base, and hand off a running platform with your team trained on day one.


Get Started

Ready to See CodeLens in Action?

We'll walk you through a live demo on a sample corpus — no AWS account needed for the first look. If it fits, we'll scope a deployment in your environment the same week.

Prefer a call? Reach us at 732.234.1020