๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
Design Review Workbench ยท free with an account

Get a security review of your RFC before it ships

Paste an RFC, design doc, or architecture write-up and get severity-ranked security findings โ€” each with a rationale, a recommendation, and framework references โ€” that you triage on a kanban board, challenge with a rebuttal for an AI-adjudicated verdict, and pin to an annotation canvas. Export findings, coverage, and a signed-off PDF when you're done. Free with any signed-in PlayCISO account.

What it gives you

Severity-ranked findings

Paste an RFC, design doc, or architecture write-up and get findings ranked critical, high, medium or low, each with a rationale, a concrete recommendation, and CWE / OWASP ASVS / control references where they apply.

Accept, dispute, or challenge

Triage every finding on a kanban of Open, Accepted, Disputed and Deferred, or challenge one with a rebuttal and get an AI-adjudicated verdict that can uphold, downgrade, or retract it.

ASVS coverage & checklist library

A live OWASP ASVS coverage read (met / partial / gap), plus a swappable checklist library โ€” ASVS L1โ€“L3, OWASP SAMM, NIST SSDF, PCI DSS 4.0, SOC 2, or CIS Controls v8 โ€” for a manual reviewer pass.

Annotate on a canvas

Pin findings as colour-coded sticky notes onto a built-in drawing canvas to sketch the architecture and mark up trust boundaries as you review.

Import prior work

Pull a Threat Model or Architecture Studio JSON export straight in as review context, or load one of six example design docs โ€” fintech, healthcare, AI platform, e-commerce, SaaS, government โ€” to try the workbench first.

Export everywhere

PNG/SVG of the annotated canvas, JSON of findings and canvas, CSV, SARIF for CI and dashboards, Markdown issues formatted for Jira/GitHub, and a printable PDF sign-off sheet with reviewer and approver lines.

How it works

  1. 1Paste the RFC, design doc, or architecture write-up โ€” or load one of six example docs spanning fintech, healthcare, AI, e-commerce, SaaS and government.
  2. 2Pick a severity scoring method (OWASP Risk, CVSS, or Qualitative) and which control frameworks to check against, then run the review.
  3. 3Triage each finding on the kanban โ€” accept it, dispute it, defer it, or challenge it with a rebuttal for an AI-adjudicated verdict.
  4. 4Pin key findings to the canvas, work through the reviewer / ASVS checklist, then export the findings and a signed-off PDF.

Honest about what this is

  • An AI first pass that reasons over the document you paste and surfaces real classes of risk โ€” auth, data exposure, crypto, logging โ€” each with a rationale and a fix.
  • A structured way to triage, dispute, and sign off on a design review, with a record of what was accepted, disputed, or deferred and why.
  • โœ• Not a code scanner or a live test of your systems โ€” it reviews the document you give it, not your actual infrastructure.
  • โœ• The AI verdict on a challenge is a second opinion, not a guarantee โ€” a human reviewer still signs off.

FAQ

What does the Design Review Workbench actually check?

Paste an RFC, design doc, or architecture write-up and it returns severity-ranked findings โ€” critical, high, medium, or low โ€” each with a category, a rationale, and a concrete recommendation, plus CWE, OWASP ASVS, and control references where they apply, and an overall ASVS coverage read.

What does "challenge back" mean?

For any finding, write a rebuttal explaining why it is wrong, already mitigated, or lower risk than scored. An AI reviewer adjudicates the rebuttal and returns a verdict โ€” upholding, downgrading, or retracting the finding โ€” with its reasoning, and updates the finding accordingly.

Is it free?

Yes โ€” the workbench works with any signed-in PlayCISO account, free included. There is no paywall on the tool itself; a paid plan mainly helps if you want higher usage limits or the other security-architect studios too.

What can I export?

PNG or SVG of the annotated canvas, JSON of the findings and canvas together, a CSV of findings, SARIF for CI pipelines and dashboards, findings as Markdown issues formatted for Jira or GitHub, and a printable PDF sign-off sheet with reviewer and approver lines.

Can I bring in a threat model or existing diagram?

Yes โ€” import a JSON export from the Threat Model or Architecture Studio tools to seed the review with that context, or start from one of the built-in example design docs and adapt it.

Design Review Workbench ยท PlayCISO