Scorecard
AI Code Risk Scorecard
Engineering lead answers security, architecture, compliance, and quality questions about Copilot, Cursor, or Claude Code. Scored snapshot: no repo upload.
Launch the scorecardInsights · Resources
Score Copilot, Cursor, and Claude Code risk. Draft a one-page policy. Outline a Maxiom-style engagement. Map HIPAA minimum necessary. Check MCP exposure. Pick an engagement shape. Walk a BAA access path. Client code stays in your environment.
Seven tools
Each tool has its own indexable page (problem, who it is for, what you get, FAQ), then a work-email gate and the questionnaire. Nothing here asks you to paste production source.
Scorecard
Engineering lead answers security, architecture, compliance, and quality questions about Copilot, Cursor, or Claude Code. Scored snapshot: no repo upload.
Launch the scorecardPolicy
Short questionnaire: allowed languages, secrets, PR review, PHI, no production data in prompts. One-page Markdown for Confluence.
Launch the generatorScoping
Describe the problem, stack, regulatory context, and access constraints. Get the outline Maxiom uses: deliverables, NDA, read-only, named engineer.
Launch the builderHealthcare
Name a feature and the data it touches. Flag what must stay out of logs, prompts, analytics, and vendor subprocessors. One-pager, not an EHR.
Launch the mapperMCP
Engineering buyers score identity, least privilege, audit, data classes, and shadow AI on MCP / tool-servers. Banded snapshot. No config upload.
Launch the checklistBuying
Map the job to a shape Maxiom will actually sell: staff aug, fixed scope, retainer, MCP, or an honest no. Not a quote.
Launch the pickerHealthcare
Walk PHI, role, BAA status, and access type. Get a path: classify first, wait for BAA, or NDA-only. Not legal advice.
Launch the decision treeFree resource
The same security, architecture, compliance, and quality list as the scorecard, as a PDF for teams who want a printable pass before they score it.
Seven free, signup-gated tools: the AI Code Risk Scorecard, AI coding policy generator, engagement scope builder, HIPAA minimum-necessary mapper, MCP exposure checklist, engagement model picker, and BAA / vendor access decision tree, plus the original AI Code Risk Checklist PDF. Each tool has its own landing page.
No. Every tool is a questionnaire or generator that runs in the browser. Client code stays in your environment. We will not ask you to paste production source.
Same pattern as the checklist PDF. Enter work details once per browser session to use or export a tool. Submissions go to HubSpot. The same portal already used on this site. No second CRM.
No. The scorecard is a self-serve snapshot. An AI code audit is a named senior engineer, read-only access after NDA, and written findings in 5–10 business days.
Yes. The checklist remains on this page. The scorecard is the interactive version of the same security, architecture, compliance, and quality list.
No. It is a feature-level mapping aid, said once and quietly on that page. It is not an EHR. Dedicated HealthTech work is Maxiom Labs. Vendor access and whether a BAA must exist first is a different worksheet: the BAA / vendor access decision tree.
The gate captures work email. Copy and print (save as PDF) work immediately in the browser. Forwarding a generated file via HubSpot is a workflow Antonio can attach to the existing form. The tools do not invent a mail server.
Engineering, security, and healthcare product leads who need a one-pager tonight, not a slide about 500 projects. Senior judgment, named next step, no hype stats.
The scorecard and policy generator are built for teams shipping with Copilot, Cursor, or Claude Code. The paid, tool-led landing is Copilot & Cursor code audit.
If AI-assisted code is the worry, start with the scorecard. If you lack written rules, read how to write an AI coding policy engineers will follow and generate a one-pager. If diligence is copyleft, read Copilot does not check the license. If you are arguing staff aug versus a SKU, use the engagement model picker. If you are booking Maxiom, use the scope builder. If agents need internal systems, use the MCP checklist. If the feature might see PHI, use the mapper; if vendor access is the question, use the BAA tree. AI coaching and wearable products that may have left wellness: AI health and fitness app development.
Related services & resources