Implementation and working code are not included. Neither are source-code auditing, production deployment, data migration, penetration testing, legal or compliance certification, vendor procurement or third-party costs. Risk review is architecture-level screening only. Estimates are planning ranges, not a binding implementation quote.