phanes · infrastructure map

Your infrastructure, as a living map.

Servers, services, databases, queues, domains, external APIs — whatever your stack is made of. Define your own resource types, nest them by environment or team, and get one interactive graph that Claude can read and update over MCP. Spot the public cache bind before someone else does.

Start freeSee pricing14-day free trial · no card required
phanes — prod board1 risk flagged
loading board…

an actual Phanes board — drag to pan · redis bound to 0.0.0.0:6379 is already flagged

How it works

A diagram you draw once goes stale in a week. Phanes is built to stay true to what is actually running.

01

Define your types

Your stack, your vocabulary. Create the resource and connection types you actually use — service, database, queue, cache, cluster, whatever — each with its own icon and colour. Then map nodes and nest them by environment or team.

02

Keep it alive

Connect Claude over MCP. Ask it to scan a host, pull cloud inventory, or read your VPN policy — it writes what it finds straight onto the board, defining new types as needed. No stale diagrams.

03

Catch what's off

Risks and drift surface automatically, whatever your types are: public binds, dead routes, orphaned resources, over-privileged credentials, down services.

mcp integration

Claude keeps the map honest.

Add the Phanes connector and approve it once in your browser — no API keys to manage. From then on, ask Claude to document any part of your stack — it reads your type catalog, defines new resource types when it hits something new, and writes nodes and edges straight onto the board, with every change attributed to the import that made it.

  • ·Server scans over SSH: processes, listening ports, systemd units
  • ·Cloud & VPN inventory: instances, security groups, roles, ACLs
  • ·Anything else: describe it in words and Claude maps it with the right types
zsh — claude
$ claude mcp add --transport http phanes https://api.phanes.dev/mcp
 authorized in browser · workspace: acme
> "Scan prod-web-1 and update the map."
 3 processes discovered · 1 new edge
 risk: postgres bound to 0.0.0.0:5432

A risk engine that reads the graph.

No rule packs to configure, and the rules don't care what your types are called. Phanes derives findings from the structure itself — public binds, dead routes, orphaned resources, and credential grants already on your map.

Public bind

high

redis binds 0.0.0.0:6379 · firewall allows 6379 ← 0.0.0.0/0

A resource listening on all interfaces with the port open to the world — reachable from the public internet, no auth in between.

Dead route

medium

api-gateway → checkout:8081 (nothing listening)

The connection is still on the map, but its target is dead or gone. The route is configured and no one is answering — requests quietly fail.

Over-privileged credential

high

deploy-token grants full admin (*:*)

A single token holding admin over everything. One leak and the blast radius is your whole environment.

timeline — prod board
  • Mon 09:41import · mcp:server-scanflagged
    redis.ports 127.0.0.1:6379 0.0.0.0:6379
  • Mon 09:41import · mcp:server-scanflagged
    edge added internet → redis (OPEN :6379)
  • Fri 18:02jane@acme.dev
    api.depends_on postgres, redis postgres, redis, kafka
  • Fri 11:26import · mcp:genericflagged
    deploy-token.grants read-only full admin (*:*)

drift timeline

Know what changed since Friday — and whether a human or an import did it.

Every change to the map is recorded with field-level diffs and an author: a teammate editing by hand, or an import that discovered drift on a real server. When something breaks, the timeline is the first place to look — not your memory.

One map, whole team.

Infrastructure knowledge shouldn't live in one person's head. Workspaces keep the map shared, current, and access-controlled.

Roles

Owners manage billing and members; editors change the map; viewers trace and read. Nobody deletes prod by accident.

Email invites

Invite by email, teammates land in the workspace with the right role. No shared passwords, no exported PNGs.

Boards per workspace

One board per environment, per product, per client — as many as you need. All under one workspace, one bill.

Pricing that fits on a sticky note.

One dollar. No tiers to decode, no "contact sales".

Personal

For your homelab and side projects

$1/month
  • 1 member
  • Unlimited boards & nodes
  • MCP / Claude integration included
  • Risk engine & drift timeline
  • Imports: AWS, Tailscale, server scans
Start free

14-day free trial · no card required

Team

for teams

For teams who share infrastructure

$1/member/month
  • Everything in Personal
  • Email invites & roles (owner / editor / viewer)
  • Shared boards across the workspace
  • Unlimited members
Start free

14-day free trial · no card required

Questions, answered.

Is my data safe?

Your map lives in your workspace and is only visible to members you invite. Imports run with credentials you control — Phanes stores the topology (hosts, processes, ports, edges), not your secrets. You can delete a board or your account at any time.

Do I have to use predefined resource types?

No — that's the point. Every workspace starts with a set of generic defaults (service, database, queue, cache, load balancer, domain, external API, and so on), and you edit the catalog freely: add your own types with their own icons and colours, rename or remove ones you don't use. A node's type is just a reference to your catalog, so you can model any stack.

What does the MCP integration do?

Phanes is a remote MCP server you connect over OAuth — add the connector with "claude mcp add --transport http phanes https://api.phanes.dev/mcp", then sign in and approve access in your browser once. No API keys to manage. Claude can then read your board and catalog and write to both: scan a server over SSH, pull cloud inventory, define a new resource type, and update nodes and edges accordingly. Every change it makes is attributed to the import in the timeline.

Can I import from AWS, Tailscale, or my own tools?

Yes. Built-in importers bring in AWS (instances, security groups, IAM roles) and Tailscale (devices, mesh links, ACLs); server scans over SSH discover processes and listening ports. Beyond those, Claude can record anything you describe using your own types, so you're not limited to a fixed list of vendors.

What happens when the trial ends?

Your boards switch to read-only — nothing is deleted. You can still view and trace the map; subscribe to keep editing and importing.

Do you support on-prem / self-hosting?

Not yet. Phanes is currently cloud-hosted only. If on-prem matters for your team, tell us at support@phanes.dev — it helps us prioritize.

Put your infrastructure on the map.

Fourteen days free, a dollar a month after. The public database bind isn't going to find itself.