Engagements start with an agreed proposal. This website does not collect payments.

IX / DECISIONS BEFORE INVESTMENT

First, clarity.
Then, build.

Decide what to build, fix and verify before investing. Architecture, data, risk and strategy review with Ixequi Luna.

01 / WHAT YOU TAKE AWAY

A supported decision.
An actionable path.

01

System map

Actors, data, integrations and trust boundaries.

02

Risk register

Findings with evidence, impact, priority and proposed owner.

03

Architecture decisions

Options, constraints, costs and decisions requiring validation.

04

Roadmap

Execution order, acceptance criteria and next milestones.

What is included and where it ends

The proposal defines one system, one priority process, available materials and necessary interviews. The diagnostic includes review and recommendations; it excludes implementation, intrusive production testing, compliance certification and guaranteed business outcomes. Clinical or regulatory validation requires a specialized scope.

PUBLIC TOOLS / SYNTHETIC SECURITY EXPERIMENTS

MIT · Python · CI

telemetry-leak-lab

What can survive log and trace redaction, and how to check without losing useful signals.

Explore case and demo ↗
MIT · Python · CI

tenant-fence

A business question made testable: can one organization read another’s records?

Explore case and demo ↗

02 / BEFORE WE TALK

Organize what you know.
See what is missing.

12 questions to prepare a review agenda. Explicit rules run in your browser. This does not inspect your repository or replace the professional diagnostic.

Do not enter credentials, patient information or business secrets. Nothing is sent automatically.

How your answers are interpreted

IX method v1. This is not a validated maturity or risk scale. All data is self-reported; no probabilities, savings or return on investment are calculated. Even if you report everything as documented, it still requires verification against real evidence.

  • Is there a measurable business outcome? — weight 2
  • Is someone accountable for the decision? — weight 3
  • Are the process and its boundaries documented? — weight 2
  • Are data sources and flows known? — weight 2
  • Is data use authorized and accountable? — weight 3
  • Are there quality criteria and representative examples? — weight 2
  • Are access and roles bounded? — weight 3
  • Do integrations define contracts and error handling? — weight 2
  • Are critical flows tested before release? — weight 3
  • Has recovery or rollback been tested? — weight 3
  • Are failures detected and assigned to an owner? — weight 2
  • Are operating costs and limits known? — weight 1

03 / HOW WE START

See engineering cases ↗