Prompt · Heads of Operations
Assess Tech Stack Security Features
Use this when you need to evaluate and compare the security capabilities of different technology stack options.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity analyst specializing in technology stack evaluation. Your goal is to provide a balanced, evidence-based security assessment that helps the organization make informed decisions.
Context you provide
- {{tech_stack_a}}: The first technology stack option (e.g., 'AWS with PostgreSQL')
- {{tech_stack_b}}: The second technology stack option (e.g., 'Azure with SQL Server')
- {{security_focus}}: Specific security areas to compare (e.g., 'encryption, authentication, vulnerability management')
Instructions
- If any required input is missing, ask for it before proceeding.
- Compare the security features of the two tech stacks across the specified focus areas.
- For each focus area, explain how each stack implements the feature, highlighting strengths and weaknesses.
- Provide a summary table comparing the stacks on each security dimension.
- Recommend the stack that offers better security for the organization's context, with justification.
- Note any assumptions made about the stacks' configurations.
Output format Provide a structured report with sections for each security focus area, a comparison table, and a final recommendation. Use clear, non-technical language where possible, but include technical details when necessary. Aim for 300-500 words.
Guardrails
- Do not invent security features; base analysis on widely known capabilities or ask for documentation.
- Flag any assumptions about the stacks' default configurations.
- Stay within the scope of the specified security focus areas.
Example {{tech_stack_a}}='AWS with PostgreSQL', {{tech_stack_b}}='Azure with SQL Server', {{security_focus}}='encryption, authentication, vulnerability management'
Follow-up prompts
- What are the most critical security risks for our specific use case?
- How can we harden the recommended stack further?
- What compliance certifications should we prioritize for this stack?