CLEAR BY DESIGN

How this check works.

This is a self-assessment based on your reported answers. It does not inspect a repository, scan infrastructure, certify security, establish regulatory compliance, or prove load capacity.

How are answers counted?

For each of eight questions, Yes = 0, No = 1, and Not sure = 1. Missing answers are invalid. The total counts areas needing attention or verification; it is not a probability of failure or a weighted severity score. “No” is a reported gap; “Not sure” needs verification and is not a confirmed vulnerability.

Total Label What it means
0–1 Few gaps reported You reported few gaps in these eight areas. Verify the evidence behind your answers and keep it current as your system changes.
2–4 Several areas need attention You identified several gaps or unanswered questions. Start with the highest-priority items below and turn them into a practical review plan.
5–8 Broad review recommended Many important areas need attention or verification. A structured review can help establish what matters first and what work should follow.

Which items come first?

Any No or Not sure on secrets, environments, access, or backups gets a “Review this first” flag, even with a low total. Elevated items precede other items; within each group No precedes Not sure, then the editorial rank breaks ties. All flags appear in this order, and the first three are recommended starting points. This is editorial triage, not measured severity.

Topic / question ID Editorial rank Elevated attention
Secrets / secrets 2 Yes
Environments / environments 3 Yes
Access / access 1 Yes
Personal data / personal_data 5 No
Outages / observability 6 No
Handoffs / handoff 8 No
Backups / backups 4 Yes
Growth / load 7 No

What if I report no gaps?

Preserve supporting evidence, reassess after material changes, and schedule periodic permission, recovery, and load checks. A low total does not establish safety; a high total does not prove a particular failure. The checklist organizes discussion. Security, capacity, and regulatory conclusions require appropriate examination of the system and its context.

What do these terms mean?

  • Vibe coding: building software with substantial help from AI-generated code and natural-language instructions.
  • Access control: the rules that determine which people can see particular records or take particular actions.
  • Load testing: exercising a realistic workload in an authorized environment to observe limits, errors, speed, and cost. Three times peak demand is a starting scenario, not a capacity guarantee.
  • Architecture discovery: a scoped examination of a system and its important unknowns, resulting in a prioritized plan before implementation. It does not certify security or include remediation.

Quiz version: v1. Scoring version: v1. Read the eight evidence checklists or take the free risk check.

Take the free risk check