Prompts
Security Architecture Review Prompts

Security Architecture Review Prompts
Prompt playbooks for reviewing authentication flows, authorization models, secrets management, zero-trust boundaries, and network segmentation in system designs. Useful for security engineers and architects because security reviews at design time catch threats that are invisible in code review alone.
Authentication Flow Review Prompt Template
For security architects reviewing login, token exchange, and session creation flows. Produces a structured threat analysis with misconfiguration risks, missing controls, and protocol violations. Includes eval checks for OWASP ASVS coverage and flow completeness.
Authorization Model Audit Prompt for System Designs
For architects evaluating RBAC, ABAC, or ReBAC implementations in design documents. Produces a permission boundary analysis, privilege escalation paths, and policy gap report. Includes harness checks for role explosion and cross-tenant access risks.
Secrets Management Architecture Review Prompt
For platform engineers reviewing how secrets are stored, rotated, accessed, and audited across services. Produces a secrets lifecycle assessment with injection points and vault integration gaps. Includes eval criteria for secret sprawl detection.
Zero-Trust Boundary Validation Prompt
For architects validating that every service-to-service call, user request, and data access enforces authentication and authorization without implicit trust. Produces a trust-boundary map with violations. Includes harness checks for lateral movement paths.
Network Segmentation Analysis Prompt for Architects
For infrastructure architects reviewing VPC, subnet, security group, and firewall designs. Produces a segmentation audit identifying overly permissive rules, missing isolation, and blast-radius risks. Includes eval checks against least-privilege network access.
OAuth 2.0 and OpenID Connect Flow Security Review Prompt
For security engineers reviewing authorization code, PKCE, client credentials, and implicit flows. Produces a grant-type-specific threat list covering redirect validation, token leakage, and scope over-provisioning. Includes harness checks for RFC compliance.
Service-to-Service Authentication Architecture Prompt
For platform architects evaluating mTLS, SPIFFE, JWT, or API-key-based service auth designs. Produces a comparison of credential rotation, revocation, and identity propagation approaches. Includes eval criteria for credential lifetime and blast-radius analysis.
Identity Provider Integration Security Prompt
For architects integrating external IdPs via SAML, OIDC, or LDAP. Produces a federation trust analysis covering assertion validation, session mapping, and logout consistency. Includes harness checks for token replay and IdP compromise impact.
Session Management Security Review Prompt
For security architects reviewing session creation, storage, timeout, refresh, and termination designs. Produces a session lifecycle threat analysis covering fixation, hijacking, and cross-device risks. Includes eval checks for cookie attributes and token binding.
Encryption Architecture Review Prompt
For architects reviewing encryption-at-rest, encryption-in-transit, and key management designs across data stores and services. Produces a cryptographic inventory with algorithm, key length, and rotation gaps. Includes harness checks for TLS version and cipher suite compliance.
Threat Modeling Architecture Prompt Template
For security architects generating structured threat models from system design documents. Produces a STRIDE or attack-tree analysis with prioritized threats, existing controls, and missing mitigations. Includes eval checks for threat coverage completeness and control mapping.
Data Flow Diagram Security Review Prompt
For architects reviewing DFDs to identify trust boundaries, data stores, and external entities missing security controls. Produces a boundary-violation report with data classification mismatches. Includes harness checks for PII and secrets crossing trust zones.
Defense-in-Depth Architecture Review Prompt
For architects evaluating whether security controls are layered across network, host, application, and data tiers. Produces a control-gap matrix showing single points of security failure. Includes eval criteria for compensating control identification.
Security Non-Functional Requirements Extraction Prompt
For architects extracting testable security NFRs from design documents, compliance standards, and threat models. Produces a prioritized NFR list with measurable acceptance criteria. Includes harness checks for requirement traceability to controls.
Architecture Risk Assessment Prompt Template
For technical decision makers generating structured risk assessments from architecture proposals. Produces a risk register with likelihood, impact, mitigating controls, and residual risk ratings. Includes eval checks for risk scoring consistency and control coverage.
Security Decision Record Generation Prompt
For architects documenting security design decisions with context, options considered, trade-offs, and rationale. Produces a structured security ADR suitable for audit and future review. Includes harness checks for decision traceability and assumption documentation.
Cloud Security Architecture Review Prompt
For cloud architects reviewing IAM, network, encryption, logging, and compliance controls across AWS, Azure, or GCP designs. Produces a cloud-specific control gap analysis mapped to the shared responsibility model. Includes eval checks for provider-specific misconfigurations.
Kubernetes Security Architecture Review Prompt
For platform security engineers reviewing pod security, network policies, RBAC, secrets handling, and admission control in cluster designs. Produces a cluster security posture report with prioritized hardening steps. Includes harness checks for container escape and privilege escalation paths.
API Gateway Security Architecture Review Prompt
For architects reviewing authentication, authorization, rate limiting, request validation, and threat protection at the API gateway layer. Produces a gateway control assessment covering OWASP API top-10 risks. Includes eval checks for bypass and direct-backend access paths.
CI/CD Pipeline Security Architecture Review Prompt
For DevSecOps engineers reviewing pipeline authentication, secret handling, artifact integrity, and deployment gates. Produces a supply-chain risk assessment from commit to production. Includes harness checks for unsigned artifacts and credential exposure in logs.
Audit Logging Architecture Design Prompt
For architects designing tamper-proof audit trails covering authentication, authorization, data access, and configuration changes. Produces an audit coverage matrix with retention, integrity, and SIEM integration requirements. Includes eval checks for non-repudiation and log injection risks.
Incident Response Plan Architecture Review Prompt
For security architects reviewing detection, containment, eradication, and recovery capabilities in system designs. Produces a gap analysis against incident response requirements with architectural blockers. Includes harness checks for forensic readiness and isolation capabilities.
Supply Chain Security Architecture Review Prompt
For architects evaluating dependency risk, artifact provenance, build integrity, and vendor access in system designs. Produces a supply chain threat analysis covering dependency confusion, compromised packages, and insider build risks. Includes eval checks for SBOM completeness.
Data Residency and Sovereignty Architecture Prompt
For architects designing systems that must comply with data localization, cross-border transfer, and jurisdictional access requirements. Produces a data-flow sovereignty map with compliance violations. Includes harness checks for data classification and geographic control placement.
Least Privilege Architecture Audit Prompt
For architects systematically reviewing whether every component, service account, and user operates with minimum necessary permissions. Produces a privilege-inflation report with over-provisioned roles and unused permissions. Includes eval checks for blast-radius reduction opportunities.
Partnered with leading AI, data, and software stack.
How We Work
Custom AI workflows for your Business
One-fit-all AI don't work for modern businesses. At Inferensys, we aim to understand your business & custom requirements; which we use to define most efficient agentic workflows, the data, and the tools for your business.
01
Review the use case
We understand the task, the users, and where AI can actually help.
Read more02
Pick the right approach
We define what needs search, automation, or product integration.
Read more03
Build the first useful version
We implement the part that proves the value first.
Read more04
Improve from there
We add the checks and visibility needed to keep it useful.
Read moreThe first call is a practical review of your use case and the right next step.
Talk to Us