Get a security review of your RFC before it ships
Paste an RFC, design doc, or architecture write-up and get severity-ranked security findings โ each with a rationale, a recommendation, and framework references โ that you triage on a kanban board, challenge with a rebuttal for an AI-adjudicated verdict, and pin to an annotation canvas. Export findings, coverage, and a signed-off PDF when you're done. Free with any signed-in PlayCISO account.
What it gives you
Severity-ranked findings
Paste an RFC, design doc, or architecture write-up and get findings ranked critical, high, medium or low, each with a rationale, a concrete recommendation, and CWE / OWASP ASVS / control references where they apply.
Accept, dispute, or challenge
Triage every finding on a kanban of Open, Accepted, Disputed and Deferred, or challenge one with a rebuttal and get an AI-adjudicated verdict that can uphold, downgrade, or retract it.
ASVS coverage & checklist library
A live OWASP ASVS coverage read (met / partial / gap), plus a swappable checklist library โ ASVS L1โL3, OWASP SAMM, NIST SSDF, PCI DSS 4.0, SOC 2, or CIS Controls v8 โ for a manual reviewer pass.
Annotate on a canvas
Pin findings as colour-coded sticky notes onto a built-in drawing canvas to sketch the architecture and mark up trust boundaries as you review.
Import prior work
Pull a Threat Model or Architecture Studio JSON export straight in as review context, or load one of six example design docs โ fintech, healthcare, AI platform, e-commerce, SaaS, government โ to try the workbench first.
Export everywhere
PNG/SVG of the annotated canvas, JSON of findings and canvas, CSV, SARIF for CI and dashboards, Markdown issues formatted for Jira/GitHub, and a printable PDF sign-off sheet with reviewer and approver lines.
How it works
- 1Paste the RFC, design doc, or architecture write-up โ or load one of six example docs spanning fintech, healthcare, AI, e-commerce, SaaS and government.
- 2Pick a severity scoring method (OWASP Risk, CVSS, or Qualitative) and which control frameworks to check against, then run the review.
- 3Triage each finding on the kanban โ accept it, dispute it, defer it, or challenge it with a rebuttal for an AI-adjudicated verdict.
- 4Pin key findings to the canvas, work through the reviewer / ASVS checklist, then export the findings and a signed-off PDF.
Honest about what this is
- An AI first pass that reasons over the document you paste and surfaces real classes of risk โ auth, data exposure, crypto, logging โ each with a rationale and a fix.
- A structured way to triage, dispute, and sign off on a design review, with a record of what was accepted, disputed, or deferred and why.
- โ Not a code scanner or a live test of your systems โ it reviews the document you give it, not your actual infrastructure.
- โ The AI verdict on a challenge is a second opinion, not a guarantee โ a human reviewer still signs off.
FAQ
What does the Design Review Workbench actually check?
Paste an RFC, design doc, or architecture write-up and it returns severity-ranked findings โ critical, high, medium, or low โ each with a category, a rationale, and a concrete recommendation, plus CWE, OWASP ASVS, and control references where they apply, and an overall ASVS coverage read.
What does "challenge back" mean?
For any finding, write a rebuttal explaining why it is wrong, already mitigated, or lower risk than scored. An AI reviewer adjudicates the rebuttal and returns a verdict โ upholding, downgrading, or retracting the finding โ with its reasoning, and updates the finding accordingly.
Is it free?
Yes โ the workbench works with any signed-in PlayCISO account, free included. There is no paywall on the tool itself; a paid plan mainly helps if you want higher usage limits or the other security-architect studios too.
What can I export?
PNG or SVG of the annotated canvas, JSON of the findings and canvas together, a CSV of findings, SARIF for CI pipelines and dashboards, findings as Markdown issues formatted for Jira or GitHub, and a printable PDF sign-off sheet with reviewer and approver lines.
Can I bring in a threat model or existing diagram?
Yes โ import a JSON export from the Threat Model or Architecture Studio tools to seed the review with that context, or start from one of the built-in example design docs and adapt it.