# AI Launch Security Review Figures
Launch Review Scope
A launch review covers the architecture, data, models, retrieval, tools, authority, and evidence needed to make a release decision.
Matrix showing AI launch review coverage across architecture, data, model, retrieval, tool, authority, evidence, and launch stages.
Architecture and trust boundaries
Components, deployment, data paths, external systems, and trust transitions.
Data and privacy boundaries
Sensitive data, tenant boundaries, retention, provenance, and external sinks.
Model and prompt controls
Model choice, system instructions, guardrails, and policy boundaries.
Retrieval and RAG
Corpus access, provenance, ranking, prompt assembly, and tenant isolation.
Tools, agents, and MCP
Tool schemas, delegated actions, workflow transitions, and external effects.
Evidence and operations
Logging, incident visibility, remediation, retest, and decision records.
Architecture and trust boundaries
Components, deployment, data paths, external systems, and trust transitions.
- Map
- Included
- Test
- Partial
- Remediate
- Included
- Retest
- Optional
- Decision
- Advisory
Data and privacy boundaries
Sensitive data, tenant boundaries, retention, provenance, and external sinks.
- Map
- Included
- Test
- Partial
- Remediate
- Included
- Retest
- Optional
- Decision
- Advisory
Model and prompt controls
Model choice, system instructions, guardrails, and policy boundaries.
- Map
- Included
- Test
- Included
- Remediate
- Included
- Retest
- Optional
- Decision
- Advisory
Retrieval and RAG
Corpus access, provenance, ranking, prompt assembly, and tenant isolation.
- Map
- Included
- Test
- Included
- Remediate
- Included
- Retest
- Optional
- Decision
- Advisory
Tools, agents, and MCP
Tool schemas, delegated actions, workflow transitions, and external effects.
- Map
- Included
- Test
- Included
- Remediate
- Included
- Retest
- Optional
- Decision
- Advisory
Identity and authority
Users, agents, service identities, permissions, and approval gates.
- Map
- Included
- Test
- Partial
- Remediate
- Included
- Retest
- Optional
- Decision
- Advisory
Evidence and operations
Logging, incident visibility, remediation, retest, and decision records.
- Map
- Included
- Test
- Included
- Remediate
- Included
- Retest
- Optional
- Decision
- Advisory
Service states
Launch Review Engagement Lifecycle
The engagement moves from intake and mapping through validation, prioritized findings, remediation planning, and retest.
Governed AI launch review lifecycle from intake through mapping, validation, findings, remediation planning, retest, and launch decision.
- 1Scope and intakeDefine the system boundary, launch stage, evidence access, stakeholders, and decision timeline.
- 2Map the systemCapture architecture, data, retrieval, tools, authority, deployment, and trust boundaries.
- 3Validate critical exposureTest the highest-consequence hypotheses within the agreed service boundary.
- 4Prioritize findingsSeparate launch blockers, material risks, hardening actions, and unresolved evidence gaps.
- 5Plan remediationAssign owners, controls, expected evidence, and retest criteria.
- 6Retest when includedReplay the agreed conditions after change and update finding state.
- Ready with accepted conditions
- Conditional launch
- Launch blocker remains
- Evidence insufficient
Launch Review Deliverable Stack
The buyer receives traceable technical findings, launch blockers, remediation priorities, and decision-ready evidence.
Layered launch-review deliverable stack from source evidence through findings, remediation records, retest, technical reporting, and executive decision support.