AI.CleanCode

Solution Architecture

Local developer tooling connects over HTTPS/REST to an API and analysis services inside the customer perimeter. Findings and reviewed fixes return to the IDE, CI/CD, web console, or configured export path.

End-to-End Data Flow

Actual AI.CleanCode product architectureA developer uses VS Code and the local extension and LSP on the workstation. HTTPS REST requests cross into the customer perimeter, where the web console, API backend, six analysis types, optional local vLLM model, PostgreSQL, CI/CD, exports, and optional Git repositories operate.DEVELOPER WORKSTATIONCUSTOMER PERIMETER — VPC / ON-PREMDeveloperwrites and reviews codeIDEVS Code / CursorAI.CleanCode extensionLSP client + LSP serverlocal analysisJSON-RPCSource code stays on the workstationin Air-Gapped On-Prem mode.Web consoleAPI / Back-EndREST APIscan orchestrationHTTPS / RESTfindings + fixesANALYSIS ENGINESSASTlanguage-specific static analyzersSCA + SBOMOSV Scanner · CycloneDX 1.5Secrets scanningDAST · Fuzzing · Automated pentestvLLM model (optional, GPU)enabled only when a customer GPU is availablesecurity-tuned open-weights modelinside customer perimeter · no external APIPostgreSQLfindings · policies · settingsCI/CDGitHub Actions · GitLab CIsafecode-ci CLI · quality gateFinding exportsJira · DefectDojo · Slackwebhook · SARIF → SIEM / ASPMGit repositories (optional)clone for scan → remove after completionany retention must be explicitly agreedDashed elements are optional or require deployment-specific confirmation. The model requires a customer GPU.Six analysis types. Findings and suggested fixes return to the IDE and CI/PR workflow; developers approve fix diffs.

Optional model, inside your environment

The model is optional. When enabled, a security-tuned open-weights model is served by vLLM on your own GPU inside the customer environment. No code, prompt, or finding is sent to a third-party model provider. In Air-Gapped On-Prem deployments there is no outbound connection at all.

Component Breakdown

Developer Workstation
Where code is written

IDE: The supported VS Code extension displays findings, explanations, and suggested fixes.

Local extension and LSP: The LSP client and server both run on the workstation; only HTTPS/REST requests cross the perimeter boundary.

Platform
Inside the customer perimeter

Web console, API, and backend: Orchestrate scans, policy, CI quality gates, and export paths.

PostgreSQL: Stores findings, policies, and settings.

Analysis Engines
Six analysis types in one pipeline
Six analysis types are exposed through IDE and CI workflows: SAST; SCA with SBOM generation; secrets scanning; DAST; fuzzing; and automated pentest.
Delivery Paths
Results where teams work

Ready-made GitHub Actions and GitLab CI templates, the safecode-ci CLI, Jira, DefectDojo, Slack, webhooks, and SARIF export to SIEM or ASPM systems.

Repository scans: When configured, the backend clones the requested revision into an isolated scan workspace, runs the selected analysis, and deletes the working copy after the scan. Retention occurs only when the customer enables and defines a retention policy.

Deployment Options

Managed Pilot

MOAI-operated evaluation environment, available only for the guided pilot.

Single-Tenant Cloud

Dedicated production VPC. Planned availability: H1 2027.

Air-Gapped On-Prem

Available now inside customer infrastructure, with no external telemetry or model API.