Resources · Scorecard

A scored snapshot of AI-assisted delivery risk — without touching the repo.

Answer how your team actually ships with Copilot, Cursor, or Claude Code. Export a one-pager. Client code stays in your environment.

The checklist is only useful if someone scores it

Most teams have a policy sentence and a green CI badge. They do not have a shared view of which Copilot/Cursor/Claude Code controls are in place, partial, or missing. The scorecard is the interactive version of Maxiom’s AI Code Risk Checklist — a snapshot you can print before the next questionnaire, not a scanner report and not an audit.

Who this is for

  • VP Engineering and staff leads who rolled out Copilot, Cursor, or Claude Code and need a honest pass tonight.
  • Security and compliance partners who want a shared list before they write “human in the loop” on a questionnaire.
  • Teams facing a date — fundraise, SOC 2, customer review — who are not ready to open a repository yet.

What you get

  • A scored snapshot across security, architecture, compliance, and code quality — the same pillars as the PDF checklist.
  • A printable one-pager (save as PDF from the browser) with banded results, not a vanity percentage.
  • A clear next step: keep going internally, or request a point-in-time AI code audit with a named engineer.

Frequently asked questions

What is the AI Code Risk Scorecard?

A short questionnaire for engineering leads overseeing Copilot, Cursor, or Claude Code. You answer security, architecture, compliance, and quality questions about how the team actually ships. You get a scored snapshot you can print or save as PDF — not a repo scan.

Do I need to upload source code?

No. Client code stays in your environment. The scorecard never asks for a repository, a paste of production source, or a prompt dump. If you need a named engineer to inspect the tree, that is an AI code audit.

How is this different from the PDF checklist?

The AI Code Risk Checklist PDF is the same control list in downloadable form. The scorecard is the interactive version: you mark each control in place, partial, or missing, and leave with a banded snapshot instead of a blank list.

Who should fill this out?

VP Engineering, staff/principal engineers, and compliance partners who can answer how Copilot, Cursor, or Claude Code is actually used — not a marketing pass. Fifteen honest minutes beats a polished guess.

Is a high score a clean bill of health?

No. A stronger band means more of the expected controls exist. It is not an audit, not a pentest, and not evidence for a buyer. Questionnaires still want a named engineer, a severity-ranked finding, and a dated artifact.

Why do you ask for a work email?

Same gate as the checklist PDF. We send the resource context to the address you give and keep a record of who used the tool. We do not use it to upload your code — there is nothing to upload.

Can I export or email the result?

Yes. After signup you can print or save a one-pager (your browser’s print-to-PDF). Copy is local to the browser. If you want the snapshot as an engineering artifact a buyer will accept, request an AI code audit.

What if we only use one assistant?

Pick Copilot, Cursor, Claude Code, or a mix. The control questions are the same; the tool name is for the snapshot header so the artifact matches how you actually ship.

How does this relate to Copilot and Cursor audits?

Use the scorecard tonight. If the band is mixed or weak, or a date is on the calendar, the paid path is the Copilot & Cursor code audit — a point-in-time senior review with written findings.

Launch

Launch the scorecard

Sign in with a work email, then run the tool in this page. Client code stays in your environment.

Work email to continue

Unlock AI Code Risk Scorecard

Same gate as the AI Code Risk Checklist. Unlock once per browser session to use or export. Client code stays in your environment — this tool never asks for a repository.

  • Questionnaire only — no source upload
  • Print or save a one-pager from the browser
  • Unlocks the other Resources tools in this session

Work email unlocks the tool for this browser session. No repo upload.

Need a named engineer, not a worksheet?

A 30-minute scoping call is the usual next step when the snapshot is not enough.

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days