{"api":{"name":"api.sb","description":"Business-as-Code surface for Startups.Studio","home":"https://api.sb","docs":"https://api.sb/docs","version":"1.0.0"},"$context":"https://api.sb/$context","$type":"FoundingHypothesis","$id":"https://api.sb/founding-hypotheses/fh%3Aw4-518210-compliance-filing%3Av1","links":{"self":"https://api.sb/v1/founding-hypotheses/fh%3Aw4-518210-compliance-filing%3Av1","canonical":"https://api.sb/founding-hypotheses/fh%3Aw4-518210-compliance-filing%3Av1","pool":"https://api.sb/v1/founding-hypotheses"},"foundingHypothesis":{"id":"fh:w4-518210-compliance-filing:v1","lens":"AIService","type":"founding-hypothesis","click":{"rubricScores":{"C8_lensFit":1,"C7_magicLensFit":1,"C4_competitorHonesty":1,"C6_crossSlotCoherence":1,"C1_customerSpecificity":1,"C2_problemFrictionRealism":1,"C9_killCriteriaAttestability":1,"C3_approachEngineCoverability":1,"C5_differentiationLoservilleEscape":1},"upperRightLoserville":true},"cellRef":{"id":"work-contexts.org.ai/w4-518210-compliance-filing","stableHash":"wcc:w4:518210:compliance-filing:v1"},"problem":{"slotStatement":"Compliance teams at hosting providers hand-assemble each regulatory filing by copy-pasting control evidence across SOC 2 reports, DPAs, subprocessor lists, and incident logs — every filing cycle reopens the same citation hunt, and a single unsourced claim to a regulator can trigger a follow-up inquiry."},"approach":{"oneSentence":"An AI filing service that drafts each regulatory submission clause-by-clause against a published control rubric, linking every assertion back to the source artifact (policy version, audit workpaper, ticket ID) so the filing lands with the regulator as a review-ready, traceable record a GC can defend line by line."},"customer":{"icpShape":"US-based cloud hosting and managed data-processing providers (NAICS 518210) at 200–2,000 employees preparing state/federal regulatory compliance filings (SOC 2, HIPAA attestations, state data-privacy registrations, CIRCIA incident reports), where the buyer is the VP of Compliance or General Counsel and the daily user is the Compliance Analyst or GRC Lead assembling the filing package.","beachheadShape":"EarlyAdopterJTBD: mid-size 518210 hosting providers filing their first multi-state data-privacy registration cycle under new 2024–2025 statutes without headcount to expand."},"archetype":"startup-archetypes.org.ai/AIService-MoneyOnDelivery","beachhead":"EarlyAdopterJTBD: mid-size 518210 hosting providers filing their first multi-state data-privacy registration cycle under new 2024–2025 statutes without headcount to expand.","competitors":{"substitutes":[{"name":"Vanta / Drata continuous-compliance platforms","category":"incumbent"},{"name":"OneTrust regulatory research + filing modules","category":"incumbent"},{"name":"Big-4 / specialty compliance consultants (KPMG, Schellman) drafting filings manually","category":"human alternative"},{"name":"ChatGPT Enterprise / Harvey used ad-hoc by the compliance analyst to draft filing narrative","category":"AI-native horizontal"},{"name":"Confluence + shared-drive templates maintained by the in-house GRC team","category":"status-quo"}]},"studioThesis":"T-AIS-PREM","killThreshold":{"K":8,"M":30,"N":7,"rubricItemSet":["C1_customerSpecificity","C2_problemFrictionRealism","C3_approachEngineCoverability","C4_competitorHonesty","C5_differentiationLoservilleEscape","C6_crossSlotCoherence","C7_magicLensFit","C8_lensFit","C9_killCriteriaAttestability"],"verdictPolicy":"all-load-bearing-pass-and-overall-ge-X","loadBearingItemSet":["C1_customerSpecificity","C2_problemFrictionRealism","C3_approachEngineCoverability","C4_competitorHonesty","C5_differentiationLoservilleEscape","C6_crossSlotCoherence"],"verdictPolicyVerbatim":"KILL unless every load-bearing rubric item passes per workbook AND overall pass-rate ≥ 7/9 (CASCADE.md §4 Stage 9 commit threshold)."},"lifecycleState":"Active","differentiation":{"twoByTwo":{"xAxis":"Per-clause source-artifact traceability (each sentence links to a versioned policy, workpaper, or ticket)","yAxis":"Depth of 518210 hosting-specific control coverage (subprocessors, multi-tenant isolation, cross-border data flows, CIRCIA incident timing)","winningQuadrant":"High traceability + deep 518210 coverage: filings arrive as review-ready packages where every hosting-control assertion is clause-linked to primary evidence a regulator or auditor can open in one click.","loservilleEscape":true,"loservilleQuadrant":"Low traceability + shallow hosting coverage: ChatGPT/Harvey ad-hoc drafting produces fluent filing narrative with no artifact links and generic SaaS controls — the GC cannot defend a single sentence to a regulator, and the analyst re-does the citation pass by hand."}},"unmetRequirements":[],"pricingArchitecture":"usage-meter"},"actions":{},"options":{},"relationships":{"runtimeUnit":"https://api.sb/v1/runtime-units?startupRef=startup%3Afh%3Aw4-518210-compliance-filing%3Av1","brand":"https://api.sb/v1/brands?startupId=startup%3Afh%3Aw4-518210-compliance-filing%3Av1","listing":"https://api.services/listings?foundingHypothesisRef=fh%3Aw4-518210-compliance-filing%3Av1","cell":"https://api.sb/v1/cells/work-contexts.org.ai/w4-518210-compliance-filing","thesis":"https://api.sb/v1/theses/T-AIS-PREM"},"meta":{"level":"L0","scopes":[]},"user":{"requestId":"a057b9b39e4eb86e","edgeLocation":"a057b9b39e4eb86e","geo":{"country":"US"},"ua":{"browser":"Claude"}},"references":{"total":0,"limit":25,"page":1,"links":{"self":"https://api.sb/v1/founding-hypotheses/fh%3Aw4-518210-compliance-filing%3Av1/references"},"items":[]}}