What you will create
6 practical deliverables move this work from an idea into an editable operating system.
- Threat and trust-boundary map
- Data classification and privacy review
- Authorization test matrix
- Accessibility and device plan
- API and database checks
- Release evidence register
Guided modules
- 01
Threat model
Map assets, actors, entry points, trust boundaries, abuse, and mitigations.
- 02
Data protection
Classify data, minimize collection, set retention, deletion, encryption, and sharing.
- 03
Authorization
Test roles, workspaces, ownership, endpoints, storage, and administrative actions.
- 04
Experience quality
Cover normal, empty, loading, error, offline, responsive, keyboard, and assistive states.
- 05
System verification
Test API validation, rate limits, secrets, database controls, backup, and restore.
- 06
Release decision
Rank findings, assign owners, define blockers, and capture acceptance evidence.
Evidence-based review
Use these checks to find missing decisions and weak evidence before implementation or release.
- Authentication is not treated as authorization.
- Every exposed action has a server-side permission check.
- Sensitive data has a retention and deletion path.
- Known relevant failures block the affected release.
Practice before using real project information.
A pre-launch review of a subscription web application with user uploads, AI processing, and organization workspaces.
