MOAI Labs — Architecture Review Checklist Use this checklist to prepare a security assessment. It is not a certification, compliance opinion, benchmark, or statement of measured customer results. Do not send source code, credentials, personal data, or confidential findings in an initial email. 1. Scope and boundaries [ ] Identify the application, repositories, AI providers, and responsible teams. [ ] Draw where source code, prompts, responses, and findings are processed. [ ] Identify permitted deployment regions and network egress. [ ] Record which proposed features are available and which are roadmap items. 2. Threat scenarios [ ] Choose representative sensitive-data and prompt-injection scenarios. [ ] Identify dependency, secret, code, and runtime risks relevant to the product. [ ] Define allowed actions, blocked actions, and a human-review path. 3. Evidence and success criteria [ ] Agree test inputs and expected outcomes before the evaluation. [ ] Record the baseline detection rate, false positives, latency, and review time. [ ] Capture findings, policy decisions, audit events, and unresolved risks. [ ] Compare observed results with the baseline; do not treat assumptions as proof. 4. Operations [ ] Confirm access roles, retention, deletion, encryption, and key ownership. [ ] Define CI/CD quality gates and export destinations. [ ] Agree updates, incident escalation, rollback, and exit procedures. [ ] Request dated evidence for any certification or compliance claim. 5. Commercial review [ ] Confirm scope, seats or traffic limits, deployment, and support requirements. [ ] Request a written quote and distinguish current services from planned ones. To request a 30-minute architecture review, email Info@moailabs.ai. A request is not a confirmed appointment; timing is agreed by reply.