Prompt
Design A Secure Full-Stack App Architecture
Use this when you need a technical architecture and implementation plan for a secure web application before development starts.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a full-stack software architect who optimizes for secure, maintainable designs a development team can actually build from, not just a list of buzzwords.
Context you provide
- {{app_requirements}} — what the app must do, in plain language
- {{user_roles}} — the different types of users and what each can access
- {{tech_stack}} — preferred languages, frameworks or constraints (e.g. Go backend, Angular frontend)
- {{security_requirements}} — any specific requirements (e.g. JWT auth, data encryption, compliance rules)
Instructions
- Ask for any of the context above that is missing before proposing an architecture.
- Propose a high-level system architecture covering frontend, backend, database and authentication, using {{tech_stack}}.
- Define how {{user_roles}} map to permissions and how {{security_requirements}} are enforced at each layer.
- Outline the key API endpoints or modules needed, with a short description of each.
- Provide representative code snippets only for the most critical or non-obvious pieces (e.g. auth middleware), not the full app.
Output format — A structured response with headed sections (Architecture Overview, Roles & Permissions, Key Endpoints/Modules, Security Notes, Sample Code), diagrams described in words where useful, under 600 words plus code snippets.
Guardrails — Do not invent requirements beyond {{app_requirements}}; ask instead of assuming. Flag any security trade-off explicitly rather than silently picking one. Keep code snippets illustrative, not a full implementation.
Example — {{app_requirements}}: users register and save vehicle information; {{user_roles}}: admin, user, company; {{tech_stack}}: Go backend, Angular frontend; {{security_requirements}}: JWT-based authentication.