# Code Compliance Triage

*/Opportunities/Code_Compliance_Triage*

## Opportunity Overview

**Wedge**: The initial beachhead targets B2B healthtech and fintech startups required to maintain continuous SOC 2 and HIPAA compliance. These organizations experience acute pain balancing fast feature shipping with strict audit requirements and adopt tools quickly to unblock deployments. Expansion proceeds horizontally by adding GDPR and PCI-DSS frameworks, and vertically by automating the generation of audit-ready compliance reports directly from the codebase.
**Timing**: Large language models with expanded context windows process entire repository architectures and data flows simultaneously, moving compliance checks from brittle regex rules to contextual understanding of data lifecycle requirements.
**Why This I C P**: Mid-market B2B SaaS companies face existential mandates to maintain SOC 2 or HIPAA compliance to close enterprise deals, yet lack the massive, dedicated security engineering divisions found in Fortune 500 firms.
**Size Of Prize**: There are roughly 50,000 mid-market to enterprise software companies globally subject to strict regulatory frameworks. At an estimated annual spend of $40,000 per company on compliance auditing and manual engineering triage labor, the total addressable prize is approximately $2B.
**Gap Narrative**: Software engineering teams spend hours manually reviewing pull requests for regulatory compliance, often creating deployment bottlenecks or missing critical data-handling violations. Existing static analysis tools generate high volumes of false positives and lack the architectural context to distinguish a minor linter error from a severe HIPAA or SOC 2 violation.
**Defensibility**: Defensibility stems from deep workflow lock-in within the continuous integration pipeline and accumulating repository context. As the agent processes more pull requests, it builds a proprietary semantic map of the organization's specific architecture, internal policies, and historical exception patterns, making generic competitor replacements highly disruptive.
**Why This Thesis**: An autonomous agent operates directly within the pull request workflow, matching the exact shape of the problem: it reads the code diff, traces the data flow implications against specific regulatory frameworks, and writes remediating code blocks prior to merge.

## Opportunity Linked Thesis

**Thesis**: [Agent](/Theses/Agent)

## Opportunity Linked I C P

**Icp**: [Commercial Architecture Firm](/CompanyTypes/Commercial_Architecture_Firm)

## Opportunity Market Sizing

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**S A M**: ~15k-20k US and Canadian mid-to-large commercial architecture firms = ~$300M-500M SAM
**S O M**: ~$15M-30M realistic 3-year capture via direct sales to ENR top 500 design firms
**T A M**: ~100k global commercial architecture and design firms x ~$15k-25k/yr equivalent software and labor spend = ~$1.5B-2.5B TAM
**Growth Rate**: ~10-15%/yr, driven by accelerating local climate mandate updates, shifting zoning laws, and the rising cost of post-submittal design rework
**Paid Comparable Spend**: ~$150-300/hr for specialized third-party building code consultants and ~$20k-40k/yr in unbillable manual research hours per mid-sized project team

## Opportunity Incumbents

- [SonarQube Platform](/Products/SonarQube_Platform) — Tool
- [Synopsys Black Duck](/Products/Synopsys_Black_Duck) — Tool
- [Semgrep Open Source](/Products/Semgrep_Open_Source) — Open-Source
- [Manual Peer Review](/Products/Manual_Peer_Review) — DIY
- [External Security Auditors](/Products/External_Security_Auditors) — Service
- [Compliance Spreadsheet Trackers](/Products/Compliance_Spreadsheet_Trackers) — Spreadsheet
- [Snyk Code Compliance](/Products/Snyk_Code_Compliance) — Tool

## Opportunity Win Conditions

**Kill Thresholds**:
- False positive rate > 20% after 45 days in pilot
- D30 active usage drops < 40% among onboarded architects
- CAC > $10k on a $15k ACV target
- Database update latency > 7 days for new municipal code releases
**Leading Metrics**:
- Time-to-first-compliance-flag
- False positive violation rate
- Auto-resolution rate for standard zoning checks
- Weekly active users per onboarded firm
- Volume of unbillable research hours saved per project
**What Proves Right**: Architecture and design firms upload project plans and the platform correctly flags zoning and climate mandate violations within minutes. Mid-market firms purchase $15k annual subscriptions to replace expensive third-party building code consultants and reduce unbillable hours. User cohorts show over 90% logo retention at month 12 as project managers mandate the triage step before municipal submittals.
**What Proves Wrong**: Project teams revert to manual spreadsheet trackers because the system generates unmanageable volumes of false positives regarding local building codes. Architecture firms refuse recurring SaaS contracts, preferring to bill manual compliance research hourly to their end clients. The operational cost of parsing fragmented, constantly changing local municipal PDFs breaks unit economics.

## Opportunity Build Profile

**Hardest Part**: Mapping abstract, subjective regulatory text into deterministic checks across highly customized infrastructure-as-code repositories without triggering paralyzing false-positive alerts.
**Min Viable Scope**: Support only Terraform configurations mapped strictly to SOC 2 Type II requirements for B2B SaaS. Completely exclude custom application source code, runtime environments, GCP, Azure, and other regulatory frameworks like HIPAA.
**Cold Start Problem**: The system needs exposure to private enterprise codebases to learn how edge-case violations and false positives look in the wild. Break this by releasing a local-only CLI scanner to build developer trust and gather anonymized telemetry before requesting direct repository access.
**Time To First Value**: Under 15 minutes (time to authorize a GitHub App and complete the first repository scan)
**Data Moat Available**: true
**Technical Difficulty**: High

## Neighborhood

### Where the gap lives

- [Solar Photovoltaic Installers](/Occupations/Solar_Photovoltaic_Installers) — latent gap · Occupations
- [Installation](/Skills/Installation) — latent gap · Skills

### Incumbent in

- [SonarQube Code Quality](/Products/SonarQube_Code_Quality) — incumbent in · Products
- [Compliance Spreadsheet Trackers](/Products/Compliance_Spreadsheet_Trackers) — incumbent in · Products
- [External Security Auditors](/Products/External_Security_Auditors) — incumbent in · Products
- [Manual Peer Review](/Products/Manual_Peer_Review) — incumbent in · Products
- [Semgrep Open Source](/Products/Semgrep_Open_Source) — incumbent in · Products
- [Snyk Code Compliance](/Products/Snyk_Code_Compliance) — incumbent in · Products
- [Synopsys Black Duck](/Products/Synopsys_Black_Duck) — incumbent in · Products

### Applies thesis

- [Commercial Architecture Firm](/CompanyTypes/Commercial_Architecture_Firm) — applies thesis · CompanyTypes

### Embodies

- [Agent](/Theses/Agent) — embodies · Theses

### Similar Opportunities

- [Automated Compliance Gate](/Opportunities/Automated_Compliance_Gate) — similar · Opportunities
- [Compliance Reporting Automation](/Opportunities/Compliance_Reporting_Automation) — similar · Opportunities
- [Audit Request Fulfillment](/Opportunities/Audit_Request_Fulfillment) — similar · Opportunities
- [Compliance as a Service](/Opportunities/Compliance_as_a_Service) — similar · Opportunities
- [AI Release Auditing For DevOps](/Opportunities/AI_Release_Auditing_For_DevOps) — similar · Opportunities
- [Release Compliance API](/Opportunities/Release_Compliance_API) — similar · Opportunities
- [Compliance Drift Monitor](/Opportunities/Compliance_Drift_Monitor) — similar · Opportunities
- [Compliance Assessment Agent](/Opportunities/Compliance_Assessment_Agent) — similar · Opportunities
- [Continuous Audit Compliance](/Opportunities/Continuous_Audit_Compliance) — similar · Opportunities
- [Compliance Audit Agent](/Opportunities/Compliance_Audit_Agent) — similar · Opportunities
- [Continuous Audit Defense](/Opportunities/Continuous_Audit_Defense) — similar · Opportunities
- [Automated Compliance Reporting Generation](/Opportunities/Automated_Compliance_Reporting_Generation) — similar · Opportunities
- [Automated Evidence Collection](/Opportunities/Automated_Evidence_Collection) — similar · Opportunities
- [Continuous Evidence Gateway](/Opportunities/Continuous_Evidence_Gateway) — similar · Opportunities
- [Continuous Audit Defense](/Occupations/Management_Occupations/Opportunities/Continuous_Audit_Defense) — similar · Opportunities
- [Compliance Audit Defender](/Opportunities/Compliance_Audit_Defender) — similar · Opportunities
- [Continuous Audit Compiler](/Opportunities/Continuous_Audit_Compiler) — similar · Opportunities
- [Continuous Vendor Auditing](/Opportunities/Continuous_Vendor_Auditing) — similar · Opportunities
- [Assurance Node](/Opportunities/Assurance_Node) — similar · Opportunities
- [Compliance Reporting Engine](/Opportunities/Compliance_Reporting_Engine) — similar · Opportunities
