FlowDex turns your entire codebase — code, infrastructure and configuration — into living documentation, end-to-end flows, change impact and security insight. For your developers, your product owners and the AI agents that write code with them.
300repositories documented in one enterprise landscape
4×feature output in pilot teams*
65%less engineering effort per feature*
€3.7Msaved yearly for a team of 80 engineers*
* Pilot results and model calculation: 80 engineers × 1.5 hours saved per week on documentation and research (€414,000) plus the 65% less effort on feature work seen in pilots (€3,318,900), at €75 per hour. Run your own numbers
The challenge teams face
AI accelerates development. It also breaks ownership.
AI assistants produce more code than ever, but understanding hasn't kept pace. Pull requests grow, context disappears and teams increasingly rely on assumptions instead of understanding.
“This PR is pretty big… but we're going to test it anyway.”Pull request review
“I think it works… but I don't know what else this relates to.”Refactoring
“Who actually built this code?”Incident review
“I actually don't dare to touch this part.”Legacy module
Build faster, understand less. Less self-written code means less ownership.
Features get duplicated or built incorrectly because nobody sees what already exists.
Pull requests are reviewed without full understanding of what they touch.
Changes go live with uncertainty about their impact.
Engineers don't fully trust the output of AI.
How do we keep control and trust in a world where AI writes code faster than we can understand it?
Speed without control = risk. The bottleneck has moved from building to understanding.
How FlowDex works
Take control of your codebase in five steps.
FlowDex makes complex software understandable, with full insight and control. The result is documentation that serves humans and AI alike — and stays current with every scan.
Documentation for humans and AI
Step 1 · Index
Indexes the entire codebase
FlowDex scans source code, infrastructure and configuration across all your repositories — including private packages — and builds a deterministic graph of entrypoints, calls, messages and data access.
.NET / C#TypeScriptInfrastructure as codePrivate packages
Step 2 · Document
Builds complete application documentation
It maps how requests flow through the system, how components interact and how business processes work — described both functionally and technically, per flow, per focus area and per application.
AI enriches the graph with summaries, focus areas, business rules, risks, dependencies and opportunities for reuse. Every claim links back to code evidence; what can't be proven is shown as a gap.
Evidence-backedBusiness rulesConfidence score
Step 4 · Detect change
Shows the impact of every change
New deployment or pull request? FlowDex immediately shows what changed, which flows are affected and what needs to be retested — integrated into your CI/CD pipeline.
FlowDex DIFFRetest adviceQuality gate
Step 5 · Deliver
Makes everything immediately usable
Developers, product owners and AI agents use the same knowledge through the FlowDex app, the API and the MCP server — including agent workflows that build features, fix issues and add tests.
Web appAPIMCP serverAgent workflows
Product tour
See what FlowDex actually shows you.
A look inside FlowDex with a fictional codebase: Contoso Travel, a booking platform with 14 projects, a TypeScript frontend, .NET services and Azure Service Bus. Every screen below uses demo data — yours is generated from your own code.
flowdex · contoso/travel-platform · main
Demo data
Projects contoso/travel-platform Booking API
Flow insight cockpit
What does Booking API do?
Booking API lets travellers search trips, book and pay, and manage their bookings. Confirmations and payment capture run asynchronously over Azure Service Bus; reservations with airlines and hotels go through the Partner Gateway.
6Focus areas
71Flows explained
48API routes
15Async side effects
94%Confidence
Booking & checkout
Create, change and cancel bookings, from checkout to confirmation.
18 flows12 API routesasync
Payments & refunds
Take payments, handle provider webhooks and refund cancellations.
11 flows6 API routesasync
Search & availability
Find trips, hotels and flights and check live availability.
14 flows9 API routesread-only
Pricing & vouchers
Calculate prices, apply vouchers and seasonal surcharges.
9 flows5 API routes
Customer accounts
Sign-up, profile, fellow travellers and marketing consent.
12 flows10 API routes
Partner integrations
Sync inventory and reservations with airline and hotel suppliers.
7 flows3 jobs2 gaps
Booking & checkout Book a trip
Flow detail
Book a trip
Entrypoint · POST /api/bookings94% confidenceasync follow-up work7 tests1 gap
What this flow does
A traveller confirms a trip in the checkout. Booking API validates the travellers and the price quote, reserves seats or rooms at the partner and stores the booking as Pending. It then publishes BookingCreated, so payment capture and the confirmation email happen asynchronously.
Business rules and functional conditions 12
PreconditionAt least one adult traveller is required.View code
PreconditionThe price quote must be less than 15 minutes old.View code
Guard / deviationIf the partner cannot reserve, the booking is rejected with 409 Conflict.View code
ResultThe booking is stored with status Pending.View code
Side effectBookingCreated triggers payment capture and a confirmation email.View code
Known gapNo timeout is configured for the partner reservation call.View code
Obsolete code still in use.LegacyPaymentClient is marked [Obsolete] but still runs in 2 flows: Retry a failed payment, Refund a cancellation.
Security & compliance
Know which business flows a vulnerability actually touches.
Most scanners hand you a list of CVEs. FlowDex tells you where they matter: which projects, which packages and which customer journeys use them — so you fix what's risky first.
Dependency and container CVEs, grouped per package version with the version that fixes them
Secrets in code and configuration files
License compliance: copyleft and commercial license risks
Misconfigurations in Dockerfiles and infrastructure as code
A complete SBOM of direct and transitive packages, ready to export
A quality gate for your pipeline, per branch and per project
Newtonsoft.Json 12.0.2
High · 7.5
CVE-2024-21907 · denial of service via deeply nested JSON. Fixed in 13.0.1.
Projects
Booking.Api nuget
Partner.Gateway nuget
Reporting.Jobs nuget
Flows that use it
Import partner feed Job
Book a trip POST
Payment webhook POST
Revenue report Job
3 projects · 9 flows · 2 focus areas — fixed with one upgrade. Demo data.
Grouped per upgrade
CVEs are grouped per installed package version, because that's how you fix them: one upgrade clears every advisory for that version.
Linked to your flows
See which entrypoints, jobs and message handlers use a vulnerable package — and which focus areas carry the business risk.
Fixed by your agent, safely
With /flowdex_fix_issues your AI agent fixes one finding at a time in an isolated branch, with checks before and after and a pull request as the result. How it works
FlowDex MCP for AI agents
Context is the new code. Give your agent the map.
AI assistants are great at writing code and bad at knowing your system. The FlowDex MCP server gives GitHub Copilot, Claude, Cursor and any MCP-compatible agent the understanding your best engineer has: existing flows, reusable components, impact and architecture.
Reuse before rebuild
The agent searches existing flows and components first, so it extends what you have instead of duplicating it.
Impact before edit
Before touching shared code it checks which flows, entrypoints and projects are affected.
Smallest safe test scope
After the change it gets the exact projects to build and the flows to retest.
Fewer tokens, better results
Precise answers from the graph instead of reading dozens of files: faster, cheaper and more consistent output.
flowdex · affectedBuild & test Booking.Api and Payments.Service (2 of 14 projects)
AIAgent · with FlowDex context
I'll extend the existing CancellationPolicy.GetFee() instead of adding a new service — it already handles the 48-hour rule, so the 14-day window belongs there.
Heads-up: RefundPolicy.CalculateFee duplicates this logic, so refunds would ignore the new fee. I'll route both through CancellationPolicy.
Changes: 2 files, 1 new test
Retest: Cancel a booking, Refund a cancellation, Change travel dates
Without FlowDex164k
With FlowDex MCP19k
Tokens used for this task · illustrative example
FlowDex agent workflows
From feature to tested pull request. Your AI agent, on rails.
FlowDex MCP doesn't just answer questions. It gives your AI agent fixed, repeatable workflows: understand the context, turn a feature into stories, write the tests first, build on what already exists, compare before and after, and open a pull request with the evidence attached. Your agent programs faster because it starts with the answer instead of the search.
1
Understand
The agent reads focus areas, flows and business rules from FlowDex instead of crawling dozens of files.
overview · flow_insight
2
Plan stories
A feature becomes sharp stories and technical tasks, with the questions nobody asked and the flows each story reuses.
focus_areas · impact
3
Tests first
Tests are written up front from the extracted business rules and the flows to retest. They fail — as they should.
quality_retest_advice
4
Build, reuse first
A mandatory reuse check runs before the first edit. The agent extends existing code and checks impact before touching anything shared.
find_elements · impact
5
Compare
The same checks run before and after the change: tests, coverage, complexity, findings and the quality gate, plus the flows affected.
affected · quality_gate
6
Pull request
One branch, one pull request, with the reuse decision, test results, gate evidence and retest list attached.
git · PR
Agent · FlowDex workflow runDemo data
> /flowdex_implement contoso/travel-platform "Split a payment between travellers"
Backlog updatedquality_coverage_filesPricingCalculator.cs left the coverage backlog
Pull request #1494 openedTests only, ready for review
Built-in guardrails
AI writes the code. FlowDex decides when it's done.
Every workflow runs the same fixed steps, every time. The AI only does the scoped edit; FlowDex owns the selection, the checks and the gate.
Reuse before new codeEvery answer states the reuse decision: extend what exists, or new code with evidence.
One change, one branch, one PREach fix runs in its own isolated worktree. Nothing is batched.
Green baseline firstChecks must pass before any AI edit, and again after it.
Evidence before a pull requestNo PR without passing checks and FlowDex gate evidence.
AI doesn't grade its own workThresholds, check results and gate outcomes are decided by FlowDex, not the model.
No secrets to AICredentials and private environment values never reach the model.
Fits how you already work
From feature request to pull request, with context at every step.
Features become sharp stories
Start a feature in Azure DevOps, Jira or your own tool. FlowDex asks the questions nobody thought of and creates stories and technical tasks that reuse existing flows.
Boards / Contoso Travel / Features
Feature
Split a payment between travellers
Let the lead booker split the total so every traveller pays their own share.
?
FlowDex asksShould each traveller get their own refund when the booking is cancelled?
?
FlowDex asksIf one share fails, do we hold the booking or cancel it after 24 hours?
User story
As a lead booker, I can split the total between travellers
Reuses: Capture paymentAffects 4 flows
Task
Extend PaymentIntent with payer shares · Payments.Service
Task
Reuse PaymentWebhookHandler for partial captures
Every pull request gets an impact check
FlowDex runs in your CI/CD pipeline. Reviewers see changed flows, affected entrypoints, what to retest and whether the quality gate passes — before anything goes live.
Some checks were not successful2 successful · 1 needs attention · 1 failing
Rescans are incremental. FlowDex compares every flow's evidence and only re-synthesizes flows that changed, so AI costs stay low.
Any Git provider
Connect GitHub, Azure DevOps, GitLab or Bitbucket, including private package feeds, branches and monorepos.
Your own AI model
Use OpenAI, Azure OpenAI, Anthropic, Google Gemini, Ollama or a custom LLM — whatever your security team approved.
Enterprise ready
Single sign-on, tenants and roles, audit trail and analytics, and self-hosted containers for full control.
From insight to results
One source of truth for everyone who shapes software.
1
Developers
Deliver and evolve software faster and with more certainty. Reviews get easier, impact is clear sooner and the risk of regression drops.
Onboard in days, not months.
2
Product owners
Sharpen the path from idea to execution. Features are defined faster, built more effectively and with less miscommunication between product and engineering.
Understand the product without reading code.
3
AI agents
Get the context that is normally scattered across code, flows and documentation. Output becomes more relevant, consistent and reliable.
Fewer tokens, better results.
4
Business
Lower failure costs and more predictable delivery. Teams go live faster without sacrificing control or reliability.
Knowledge stays when people leave.
Impact on delivery
From weeks to days, with fewer engineers.
AI-assisted teams without shared context spend their time on analysis, research and rework. With FlowDex, that time goes into shipping.
AI-assisted engineers without FlowDex
6 developers
5–6 features
per quarter
65%less engineering effort
4×output
AI-assisted engineers with FlowDex
2 developers
20–25 features
per quarter
Based on a FlowDex pilot team working on an existing enterprise codebase. Results depend on codebase and team. Calculate your savings
Self-hosted or SaaS · bring your own model
Your code. Your control.
FlowDex works within your existing security and governance frameworks — not around them.
Flexible deployment
Run FlowDex as SaaS, in your private cloud or fully self-hosted via containers. Same product, your choice of boundary.
Data stays protected
Code, context and data stay within your own infrastructure. Encrypted by default, with managed keys or your own.
Control over AI usage
Use your own approved models and AI providers. See exactly how many tokens every scan uses.
If context is the new code, that context must be under the same control.
Plans
Plans that scale with your organization.
Start with living documentation, add AI agents and change insight, or scale up with Enterprise and host FlowDex yourself.
Foundation
Living documentation and insight for your whole landscape.
FlowDex is a code intelligence platform for AI-driven software development. It indexes your source code, infrastructure and configuration and turns it into living documentation: end-to-end flows, focus areas, business rules, dependencies, and quality and security findings. Developers, product owners and AI agents use that knowledge through the FlowDex app, API and MCP server.
How is FlowDex different from GitHub Copilot, Cursor or Claude?
GitHub Copilot, Cursor and Claude are AI coding assistants: they write code. FlowDex is the context and control layer underneath. It tells them — and you — how the system actually works, what a change affects and what needs to be retested. FlowDex works with those assistants through MCP instead of replacing them.
Does our source code leave our infrastructure?
Not if you don't want it to. FlowDex runs as SaaS, in your private cloud or fully self-hosted in containers. Code, context and data can stay in your own infrastructure, encrypted by default, with the option to bring your own encryption key.
Which AI models does FlowDex use?
Your own. You bring an approved provider such as OpenAI, Azure OpenAI, Anthropic, Google Gemini, Ollama or a custom LLM. FlowDex only re-synthesizes flows that changed since the last scan, which keeps token usage low.
Which languages and platforms are supported?
FlowDex analyzes .NET (C#) and TypeScript/JavaScript codebases, including frontends and message-based architectures such as Azure Service Bus, MassTransit and NServiceBus. It connects to GitHub, Azure DevOps, GitLab and Bitbucket. More languages are on the roadmap.
What is the FlowDex MCP server?
MCP (Model Context Protocol) is the open standard AI agents use to call tools. The FlowDex MCP server gives agents tools such as focus_areas, flow_insight, find_elements, impact, affected and quality_retest_advice, so they reuse existing code, check impact before editing and pick the smallest safe test scope.
Can FlowDex build features and fix security issues with my AI agent?
Yes. FlowDex MCP gives AI agents fixed workflows. /flowdex_implement turns a feature into stories, writes tests first, checks reuse and impact before the first edit, builds the smallest slice and compares the result. /flowdex_fix_issues fixes security and quality findings, such as vulnerable packages or overly complex code, one at a time. /flowdex_test_coverage adds tests for the riskiest untested code. Every run uses an isolated branch, runs checks before and after the AI edit, and ends in a pull request with evidence.
How does FlowDex prevent AI hallucinations in its documentation?
FlowDex first builds a deterministic graph of your code: entrypoints, calls, messages and data access. AI only summarizes that evidence. Every claim links back to the code, and anything FlowDex cannot prove is shown as an explicit gap instead of being invented.
Which plans does FlowDex offer?
Three. Foundation gives you living documentation and security and quality insight. Co-Creation adds FlowDex MCP, agent workflows and FlowDex DIFF. Both plans are for organizations of up to 100 people. Enterprise adds the option to self-host FlowDex in your private cloud or in containers. Book a demo and we will put together a proposal that fits your organization.
Who builds FlowDex?
FlowDex is built by Brainstack, a Netherlands-based software engineering company specialised in cloud-native and AI solutions.
Ready to experience the impact?
See FlowDex in a live demo, or start a proof of concept on your own codebase. Code. Clarity. Control.