Comprehensive security audit with two modes and two tiers. Planning mode reviews architecture for security gaps (STRIDE threat modeling, auth design, data classification, AI regulatory compliance). Audit mode scans code, infrastructure, dependencies, and secrets for vulnerabilities. Covers OWASP Top 10, ML/AI model security (serialization safety, provenance, poisoning), AI regulatory compliance (EU AI Act, biometric privacy, EU Data Act), web security headers, API boundary security, authentication and session management, CWE references, infrastructure hardening, confidential computing, and privacy-preserving computation. Each phase has Standard (free tools, always actiona…