This was part of the eco-system we created, where the organization did not have any format Security Review Board process for new feature or tools. With the increasing democratization of AI usage throughout the org, I found a huge gap in maintaining a security first approach while development. Now devs need to create a PR using a cookie cutter template where they add all details about the work they are proposing to do. We created a shared knowledge base using SOC2 audits, customer privacy policies, internal privacy policies and known secure coding and development best practices. The LLM reviews the plan based on this knowledge base and then similar to PR review bot, presents a summary and review comments. Once all comments are addressed, a human in the loop approves the PR. This project helped formalize an industry standard best practice and made it entirely streamlined