AccessLock — The ADA Title III / WCAG Accessibility Audit, Remediation & Litigation-Defense Engine
AI-native service business blueprint · Run date 2026-07-09 · Run #205 · Slug: ada-wcag-accessibility-litigation-defense-engine
Final Decision: Blueprint
A done-for-you digital accessibility service for litigation-exposed mid-market e-commerce, retail, financial-services, and healthcare organizations: manual expert audit (not an overlay widget) + engineer-executed code remediation + signed VPAT/Accessibility Conformance Report + continuous regression monitoring + a litigation-defense evidence file — sold as a fixed-fee outcome, delivered behind an internal AI scanning/classification/remediation-drafting engine with certified human accessibility-tester chokepoints. Positioned explicitly against the two failed incumbent models: self-serve overlay widgets (legally disfavored, FTC-sanctioned) and $150k+ hourly big-4 consultancies.
Executive Summary
Digital accessibility litigation has become an industrial-scale, repeat-defendant business for plaintiffs' firms, while the two products the market actually sells — self-serve overlay widgets and hourly big-4 consulting — both fail structurally. Overlays were the subject of a $1M FTC enforcement action for false advertising and are now cited as evidence of noncompliance in nearly a quarter of new suits. Hourly consultancies price out small and mid-market defendants and rarely execute the code fix. The gap is a productized, fixed-fee, manual-audit-plus-human-verified-remediation service that produces a signed VPAT/ACR and a dated evidence file defense counsel can use — delivered at a fraction of $50k–$200k/year legacy consulting cost via an AI scanning-and-drafting engine with certified human testers at the judgment chokepoints. Wedge ICP: mid-market e-commerce and retail brands (the most-sued vertical, ~70% of 2025 suits) that received a demand letter or want to get ahead of one.
Thesis
Web accessibility remediation is a bounded, largely automatable production pipeline — crawl, render, run automated WCAG rule engines, classify violations by success criterion, draft code-level fixes, verify with assistive technology — with genuine judgment concentrated at a few chokepoints: does an automated "pass" reflect real usability for a screen-reader or keyboard user, and does a given fix actually resolve the barrier without regressing functionality. That judgment requires certified human testers (CPACC/WAS credentialed) using real assistive technology, which is exactly why automated tools plateau at 30–40% issue detection and overlays fail in court. AI does not replace that judgment; it multiplies it — collapsing the 60–70% of the pipeline that is mechanical rule-checking, code-pattern-matching, and report drafting, so certified testers spend their scarce hours only where a machine cannot substitute. The regulatory backdrop (Title III case law, DOJ's 2024 Title II WCAG 2.1 AA rule, the European Accessibility Act effective June 2025) is a durable moat: it requires human-attestable proof, which is precisely what AI-native, human-verified delivery can produce more cheaply than legacy consultancies and more credibly than SaaS overlays. Pricing is per-property/per-page and outcome-based (a signed conformance artifact), never hourly.
Discovery Rationale
This run generated candidates from the assigned unexplored-terrain list plus independent research: (1) ADA Title III/WCAG digital accessibility audit-remediation-VPAT-monitoring; (2) DSAR fulfillment under CCPA/CPRA and the growing patchwork of state privacy statutes; (3) AI vendor risk/third-party AI governance documentation (NIST AI RMF/EU AI Act); (4) state data-broker registration and universal opt-out compliance (CA Delete Act, OR, TX, VT); (5) PAGA wage-and-hour exposure audits for California employers. ADA/WCAG accessibility won because it combines the strongest evidence across every dimension: the largest, most current litigation-volume statistic of any candidate this run (8,667 federal filings in 2025, verified via a specialist law-firm tracker), a discredited and FTC-sanctioned incumbent product category (overlays) that the service explicitly displaces, existing venture-funded AI-native competitors proving the model works commercially (TestParty), and zero overlap with any of the 204 prior blueprints — none of which touch WCAG success criteria, assistive-technology testing, or VPAT/ACR production. It is also the only candidate this run with a live, free, self-service lead magnet: the prospect's own public website is the diagnostic.
Candidate Comparison
Five candidates generated this run; scored 1–5 on the 20 standard criteria.
| Criterion | ADA/WCAG accessibility audit+remediation | DSAR fulfillment (CCPA/CPRA) | AI vendor risk / third-party AI governance | Data-broker registration & opt-out compliance | PAGA wage-and-hour exposure audits |
|---|---|---|---|---|---|
| 1. Low trust burden | 5 | 4 | 3 | 4 | 2 |
| 2. Low task-level judgment | 4 | 4 | 2 | 5 | 2 |
| 3. High intelligence threshold | 4 | 2 | 4 | 2 | 4 |
| 4. Regulation as moat | 5 | 4 | 3 | 4 | 5 |
| 5. No physical labor | 5 | 5 | 5 | 5 | 4 |
| 6. Sam Altman test | 5 | 3 | 4 | 2 | 4 |
| 7. Outcome-pricing potential | 5 | 3 | 3 | 3 | 3 |
| 8. Gross-margin potential | 5 | 4 | 4 | 3 | 3 |
| 9. Buyer urgency | 5 | 3 | 2 | 2 | 4 |
| 10. Competitive whitespace | 4 | 2 | 3 | 4 | 3 |
| 11. Novelty vs prior 204 outputs | 5 | 4 | 5 | 5 | 4 |
| 12. Fit with current AI capability | 5 | 4 | 4 | 3 | 3 |
| 13. Active demand evidence | 5 | 3 | 2 | 2 | 4 |
| 14. Existing budget/competitor proof | 5 | 4 | 3 | 2 | 3 |
| 15. Waitlist/lead-magnet potential | 5 | 2 | 2 | 2 | 2 |
| 16. Narrow MVP wedge clarity | 5 | 4 | 3 | 3 | 3 |
| 17. Distribution-channel clarity | 5 | 3 | 2 | 2 | 3 |
| 18. Licensing feasibility | 4 | 4 | 4 | 4 | 2 |
| 19. Operational repeatability | 5 | 5 | 3 | 4 | 3 |
| 20. Speed to first revenue | 5 | 4 | 3 | 3 | 3 |
| Total (max 100) | 96 | 71 | 62 | 64 | 62 |
Why runners-up lost: DSAR fulfillment — real per-request cost pain (~$1,400/request manually) but low intelligence threshold (largely a data-mapping/workflow-execution task well-suited to pure SaaS, e.g., OneTrust/Securiti/Osano already own it as a feature, not a standalone service opportunity) and thin evidence of an unmet done-for-you niche. AI vendor risk/third-party AI governance — directionally strong long-term (EU AI Act enforcement from Aug 2026) but task-level judgment is high (assessing a vendor's model risk resists confident automation this year) and demand is still mostly "read the framework," not yet "buy the audit" — too early for a fixed-fee wedge. Data-broker registration — genuinely low-judgment, checklist-shaped work, but the regulatory footprint (CA, OR, TX, VT only) is narrow, per-unit fees are small ($400/yr-ish per state), and it lacks buyer urgency (no litigation forcing function). PAGA audits — very real California employer pain but sits close to existing wage-and-hour/employment-law practice (UPL risk high — this is legal risk-quantification work courts and the plaintiffs' bar treat as legal advice) and requires attorney sign-off on nearly every deliverable, weakening the licensing-feasibility and low-judgment gates.
CODE Validation
C — Consumer/Buyer Trend
Web-accessibility suits reached 3,117 of 8,667 federal ADA Title III filings in 2025 (36%, up from 28% in 2024), with New York (1,021) and Florida (961, nearly double its 2024 count) leading. Over 5,000 digital accessibility lawsuits were filed in 2025 including state courts. Nearly half of 2025 federal filings named repeat defendants — proof that ad hoc, unverified fixes do not hold up, creating durable recurring demand for verified remediation and monitoring, not a one-time fix. Verified
O — Opportunity
The two dominant products both fail the buyer. Overlay widgets (accessiBe, UserWay, AudioEye-style toolbars) are now themselves cited as the barrier in litigation — 22.6% of H1 2025 website suits targeted sites that already had an overlay installed, and the FTC fined accessiBe $1M in April 2025 for falsely advertising the widget could make any site compliant in 48 hours. Automated-only tools (including AI-powered scanners) catch only 30–40% of WCAG violations by practitioner consensus; screen-reader compatibility, logical reading order, and cognitive accessibility require human evaluation. Legacy manual consultancies (Level Access, Deque) are thorough but priced and staffed for enterprise ($50k–$200k+/year), pricing out the mid-market e-commerce and regional-brand segment that is disproportionately targeted (e-commerce/retail = ~70% of 2025 suits). No mainstream provider sells a fixed-fee, manually-verified, code-remediated, VPAT-backed outcome sized for a $10M–$500M revenue e-commerce brand. Verified (gap characterization Inferred)
D — Demand
Buyers are already paying: in-house "Accessibility Compliance Program Manager" and "Digital Accessibility Specialist" roles are open at companies from Salesforce to state higher-education systems ($55k–$139k salary range), traditional consulting runs $50k–$200k+/year per TestParty's own comparison content, and a venture-funded AI-native competitor (TestParty) already sells a compressed "two-week" managed remediation service — proof of both budget and market validation for the AI-native model. Demand letters seeking $10,000–$50,000+ are a standing, repeatable trigger event; total exposure once settlement, defense, remediation and monitoring are counted runs $55,000–$270,000+ per case. Verified
E — Economic Sizing
The global digital accessibility software market is valued at roughly $0.85–$1.4B in 2025 depending on source methodology, growing 6.8–10.25% CAGR; the narrower accessibility-testing-tools market sits near $610M in 2025 growing to ~$828M by 2031. Layering a services wedge onto that: an estimated several hundred thousand US mid-market e-commerce/retail/financial-services sites face realistic litigation exposure; even a conservative 5,000–15,000 realistic target-organization pool × $8,000–$25,000/year (audit + remediation + monitoring bundle) implies a $40M–$375M serviceable wedge market before expanding beyond e-commerce into healthcare, banking, and higher-ed verticals (which face parallel Title II/Section 508 deadlines). A 150–300 client book at ~$15,000 average ACV ⇒ $2.25M–$4.5M ARR without leaving the wedge vertical. Ranges are constructed estimates. Inferred
Rubric Scorecard (Six Gates)
| Gate | Score | Reasoning |
|---|---|---|
| 1. Low trust burden | 5/5 | Accessibility audits are routinely outsourced today (Level Access, Deque, boutique auditors); buyers already grant read access to staging sites and CMS/design systems to third-party auditors as standard practice. No novel trust ask. |
| 2. Low task-level judgment | 4/5 | Crawl → automated rule scan → AI classification/drafting → human AT verification → code fix → re-test is a discrete, repeatable pipeline. Judgment concentrates at two chokepoints: does a page genuinely pass for a screen-reader/keyboard user (not just an automated-checker "pass"), and does a proposed code fix introduce a functional regression. |
| 3. High intelligence threshold | 4/5 | Correctly diagnosing WCAG 2.2 failures requires synthesizing DOM structure, ARIA semantics, visual design intent, and real assistive-technology behavior — a genuinely hard reasoning task where frontier-model-assisted classification plus human AT testing outperforms rule-based scanners, which plateau at 30-40% detection by practitioner consensus. |
| 4. Regulation as moat | 5/5 | ADA Title III case law, DOJ's April 2024 Title II rule mandating WCAG 2.1 AA for state/local government sites (compliance deadlines April 2026/2027 by population), Section 508, and the EU's June 2025 European Accessibility Act create overlapping, durable legal exposure that a casual DIY entrant cannot credibly speak to. |
| 5. No physical labor | 5/5 | Entirely remote: automated scanning, code review, screen-reader/keyboard testing (can be done remotely against staging URLs), document production, video read-outs. |
| 6. Sam Altman test | 5/5 | Better models directly improve DOM/ARIA reasoning, code-fix generation quality, and violation-classification accuracy — the service gets cheaper and more accurate every model generation, while the human AT-verification chokepoint remains necessary and billable regardless of model quality (courts require human-attestable proof, not an AI's self-certification). |
Target Buyer
- Wedge ICP: Mid-market e-commerce and multi-location retail brands, $10M–$500M revenue, with in-house marketing/engineering but no dedicated accessibility function — large enough to be a litigation target, too small for a Level Access/Deque enterprise engagement.
- Economic buyer: General Counsel or VP of E-commerce/Digital, frequently triggered by a demand letter; CTO/VP Engineering co-sponsors remediation execution.
- Expansion buyers: Regional banks and credit unions (parallel ADA + CFPB digital-experience exposure), healthcare provider groups (patient portals), higher-education institutions and state/local government entities facing the DOJ Title II WCAG 2.1 AA deadline (April 2026 for larger jurisdictions, April 2027 for smaller).
- Channel buyer: Employment/consumer-defense law firms who receive the demand letter and need a technical execution partner to remediate and produce evidence, not just respond legally.
Jobs-to-be-Done
- "Tell me, in plain terms, whether we would survive an accessibility audit by a plaintiff's expert — not whether an automated scanner gives us a green checkmark."
- "Fix the actual code, not paper over it with a widget that makes us a bigger target."
- "Give me a signed VPAT/ACR I can hand to our biggest customer's procurement team and to our defense counsel."
- "Make sure the fix stays fixed after the next site redesign — don't just hand me a PDF."
- "Answer the CFO's question: are we going to be the next name on a demand-letter list?"
Painful Problem
Most mid-market digital properties were built by teams with zero accessibility training, layering years of components, third-party widgets, and redesigns with no one auditing WCAG success-criterion conformance. Serial plaintiffs' firms use automated tools to scan thousands of sites, generate demand letters seeking $10,000–$50,000+, and file suit when ignored; the plaintiffs' bar is disproportionately targeting e-commerce (~70% of 2025 suits) because checkout flows are usability-critical and easy to demonstrate as barriers. Installing an overlay widget — the fastest, cheapest-looking fix — makes the target worse: 22.6% of H1 2025 website suits hit sites that already had one installed, and the widget vendor category leader was FTC-fined for the exact claim that its product resolves this. Verified Internal teams lack WCAG expertise, have no source of truth for what's actually broken versus automated-tool noise, and have no artifact to show counsel, customers, or the board that the risk is being actively managed.
The Outcome We Sell
"Your digital properties, tested the way a plaintiff's accessibility expert and a real screen-reader user would test them; every WCAG 2.2 AA failure remediated in your actual code, verified with assistive technology, and documented in a signed VPAT/ACR your procurement teams and defense counsel can rely on. Fixed fee. We run everything; your engineers approve every code change; continuous monitoring keeps you conformant after every release."
Deliverables per cycle: Accessibility Conformance Audit (page-by-page WCAG 2.2 AA findings mapped to success criteria, severity-tiered), Remediation Pull Requests (code-level fixes applied to the client's actual repo/CMS, engineer-approved), a signed VPAT 2.5 / Accessibility Conformance Report (ACR), a litigation-defense Evidence File (dated test logs, before/after AT recordings, remediation changelog), and a Continuous Conformance Monitoring subscription that re-tests on every release.
First One-Feature MVP Wedge
| ICP | Mid-market e-commerce/retail brand, $10M–$500M revenue, in-house engineering team, no dedicated accessibility staff |
| Trigger event | Received an ADA demand letter or suit; a competitor/peer brand was sued; installed an overlay widget and wants a real second opinion; upcoming enterprise customer procurement requiring a VPAT |
| Pain | Unknown number and severity of real WCAG barriers on core purchase/account flows; no code-level fix path; no defensible documentation |
| One-feature MVP | The Conformance Audit & Fix Sprint: automated + AI-assisted scan of up to 5 core user flows (home → category → PDP → cart → checkout), certified human tester verification with screen reader (NVDA/VoiceOver) and keyboard-only navigation, prioritized findings report, and a first remediation sprint fixing the top-severity blockers directly in the client's codebase |
| Input | Site URL(s), staging/dev environment access or a read-only repo branch, CMS/framework details, prior audit reports if any (including any overlay vendor reports, which we treat as noise to be re-verified) |
| Output | Conformance Audit Report (WCAG 2.2 AA success-criterion mapping, severity tiers, screenshots/AT recordings) + remediation pull request(s) + evidence file + VPAT 2.5 draft |
| Human chokepoint | Certified accessibility tester (CPACC/WAS) validates every "fails" and "passes" determination using real assistive technology; senior engineer reviews and approves every code-level remediation PR before merge |
| Success metric | % of critical/serious findings remediated and re-verified within 30 days; VPAT accepted by client's counsel/procurement contact without rework |
| What's next | Continuous Conformance Monitoring retainer; full-site audit beyond the 5 core flows; mobile app (native iOS/Android) audits; PDF/document remediation; annual VPAT refresh; litigation-support expert-witness coordination (via outside counsel, never by us directly) |
Evidence Summary
- 8,667 ADA Title III federal lawsuits filed in 2025; 3,117 (36%) were website-accessibility suits, up from 28% in 2024. Verified
- Over 5,000 total digital accessibility lawsuits filed in 2025 including state courts; New York (1,021) and Florida (961, nearly double 2024) lead. Verified
- Nearly half of 2025 federal filings named repeat defendants. Verified
- E-commerce/retail = ~70% of 2025 digital accessibility lawsuits. Verified
- FTC fined accessiBe $1M (final order approved April 2025) for false advertising and fake reviews about its overlay's compliance claims. Verified
- 22.6% of H1 2025 ADA website lawsuits targeted sites that had an accessibility overlay/widget installed. Verified
- 67% of accessibility practitioners and 72% of respondents with disabilities rate overlays as ineffective; automated/AI-only tools detect 30–40% of WCAG violations. Verified (survey-based)
- European Accessibility Act took full effect June 2025, requiring WCAG 2.1 AA conformance for digital products/services sold in the EU. Verified
- DOJ's April 2024 final rule under ADA Title II requires state/local government web content and mobile apps to meet WCAG 2.1 AA, with compliance deadlines of April 2026 (larger jurisdictions) and April 2027 (smaller). Verified
- Legacy consulting engagements run $50,000–$200,000+/year; venture-backed AI-native competitor TestParty markets "two-week" managed remediation at "a fraction" of that cost — proof of demand and proof the AI-native compressed-delivery model is commercially viable. Verified
- Audit pricing norms: $100–$250/page (or $25-100 for lighter pages) for manual audits; VPAT services $350–$950 depending on edition; document remediation from $7/page. Verified
- In-house accessibility compliance roles posted at $55,000–$139,000/year (Salesforce, higher-ed, state government) — proof buyers already fund headcount for this function and a per-unit service can substitute or augment it. Verified
Claim Table
| # | Claim | Label |
|---|---|---|
| C1 | 8,667 ADA Title III federal suits filed in 2025; 3,117 (36%) were website-accessibility suits | Verified |
| C2 | 5,000+ total digital accessibility lawsuits filed in 2025 incl. state courts | Verified |
| C3 | Nearly half of 2025 federal filings targeted repeat defendants | Verified |
| C4 | E-commerce/retail ≈ 70% of 2025 digital accessibility suits | Verified |
| C5 | FTC fined accessiBe $1M (final order April 2025) for false widget-compliance advertising | Verified |
| C6 | 22.6% of H1 2025 website suits targeted sites with an overlay already installed | Verified |
| C7 | Automated/AI-only tools detect ~30–40% of WCAG violations; manual AT testing required for the rest | Verified (practitioner-survey based) |
| C8 | European Accessibility Act (EAA) effective June 2025 mandates WCAG 2.1 AA for EU-market digital products/services | Verified |
| C9 | DOJ Title II rule (April 2024) sets WCAG 2.1 AA deadlines of April 2026/2027 for state/local government sites | Verified |
| C10 | Legacy consulting runs $50k–$200k+/yr; TestParty (AI-native competitor) markets compressed 2-week remediation at lower cost | Verified |
| C11 | Manual audit pricing norms $100-250/page; VPAT $350-950; document remediation from $7/page | Verified |
| C12 | In-house accessibility compliance roles posted at $55k-139k/yr | Verified |
| C13 | No mainstream provider sells done-for-you manual-audit + code remediation + signed VPAT + monitoring at fixed fee sized for mid-market ($10M-500M revenue) e-commerce | Inferred (absence of evidence in competitive scan) |
| C14 | Serviceable wedge market $40M–$375M/yr | Inferred (constructed estimate) |
| C15 | Total litigation exposure per case (settlement+defense+remediation+monitoring) $55k-270k+ | Inferred (vendor-compiled range, single-source-heavy) |
| C16 | Demand letters typically seek $10,000-$50,000+; most small-business settlements land $5,000-$15,000 | Verified |
Source-Claim Matrix
| Claim | Label | Source | Type | Date | Conf. | Used in |
|---|---|---|---|---|---|---|
| C1: 8,667 federal ADA Title III suits 2025; 36% website | V | ADA Title III Blog (Seyfarth Shaw) — Federal Filings Fall Slightly to 8,667 in 2025 | Law-firm tracker | Feb 2026 | High | §3,7,14 |
| Website suits bounce back in 2025 | V | ADA Title III Blog — Website Filings Bounce Back in 2025 | Law-firm tracker | Mar 2026 | High | §3,7,14 |
| C2: 5,000+ total digital accessibility suits; NY/FL geography | V | WCAGsafe — ADA Lawsuit Statistics 2025–2026 | Vendor analysis | 2026 | Med-High | §3,7,14 |
| C4: e-commerce ~70% of suits | V | Accessibility.build — Accessibility Lawsuit Tracker 2026 | Litigation tracker | 2026 | Med-High | §3,7,11 |
| C3: repeat defendants ~50% of filings | V | ADA Title III Blog | Law-firm tracker | Feb 2026 | High | §3,7,14 |
| C5: FTC $1M accessiBe fine, April 2025 | V | TestParty — Why 800+ Businesses With AccessiBe Were Still Sued | Company blog citing FTC action | 2025 | High | §3,11,14,19 |
| C6: 22.6% of H1 2025 suits hit overlay-equipped sites | V | Compliapoint — Accessibility Overlays Don't Work: 2025 Lawsuit Data | Vendor/consultancy analysis | 2025 | Med-High | §3,11,14,19 |
| C7: overlays ineffective (67%/72% practitioner & disability-community ratings); 30-40% automated detection rate | V | A11y Collective — Are Accessibility Overlays a Good Investment? | Practitioner survey analysis | 2025 | Med-High | §3,4,7,14,29 |
| NFB statement on overlay interference with screen readers | V | Acute ADA Compliance — Why Accessibility Overlays Are Not Compliance | Consultancy analysis citing NFB | 2025 | Med-High | §11,22 |
| C8: European Accessibility Act effective June 2025, WCAG 2.1 AA | V | GetWCAG — Complete European Accessibility Act Guide 2026 | Compliance vendor guide | 2026 | High | §7,14,22 |
| C9: DOJ Title II rule, April 2024; WCAG 2.1 AA deadlines 2026/2027 | V | D2i Technology — Accessibility Testing 2026: WCAG 3.0, ADA Deadlines | Industry analysis | 2026 | High | §7,9,14,22 |
| C10: legacy consulting $50k-$200k+/yr; TestParty AI-native 2-week model | V | TestParty — Automated WCAG Compliance; TestParty — How Much Does Website Accessibility Cost? 2025 | Company site / vendor blog | 2025 | High | §14,19,20,21 |
| C11: audit pricing $100-250/page; VPAT $350-950; doc remediation from $7/page | V | DigitalA11Y — Web Accessibility Audit Cost Guide 2026; Accessible.org — Pricing | Vendor pricing pages | 2025-2026 | High | §14,21 |
| C12: in-house accessibility roles posted $55k-$139k | V | A11yjobs — Accessibility Compliance Program Manager, Salesforce; ZipRecruiter — Web Accessibility Jobs | Job board | 2026 | High | §14,18,20 |
| Digital accessibility software market $0.85B-$1.4B 2025, 6.8-10.25% CAGR | I | Fortune Business Insights; Straits Research | Market research (multiple, divergent estimates) | 2025-2026 | Med (source divergence) | §7,17 |
| Accessibility testing tools market $610M 2025 → $828M 2031 | I | Cited within QASkills — AI Accessibility Testing Tools 2026 | Industry analysis | 2026 | Med | §7,17 |
| C16: demand letters $10k-$50k+; small-business settlements $5k-$15k; total exposure $55k-$270k+ | V (ranges) / I (upper total) | TestParty — ADA Lawsuit Cost Statistics; Accessible.org — Settlement Amounts | Vendor-compiled litigation-cost data | 2025-2026 | Med-High | §11,14,17,20 |
| Fable Series B $25M (2024) — AI-native accessibility-adjacent funding proof | V | Cited within QASkills — AI Accessibility Testing Tools 2026 | Industry analysis citing funding news | 2024 | Med | §19,20 |
Market and Demand Evidence
Three reinforcing demand engines: (1) Litigation volume and recurrence — 8,667 federal filings in 2025 with website suits growing share to 36%, and nearly half hitting repeat defendants, meaning "we already did a scan once" is not a defense and creates durable recurring-service logic (audit is not a one-time purchase). (2) Incumbent-product collapse — the FTC's own enforcement action against the market-leading overlay vendor, combined with the 22.6% overlay-installed-and-still-sued statistic, gives any credible provider a built-in objection-handling narrative ("your current fix is legally recognized evidence against you"). (3) Regulatory stacking — EAA (June 2025), DOJ Title II WCAG 2.1 AA deadlines (2026/2027), and ongoing Title III case law create simultaneous, non-expiring pressure across consumer, government, and EU-market-facing organizations, unlike single-statute niches that can be legislated away.
Active Buyer Conversations
- In-house hiring for accessibility compliance roles at both private (Salesforce) and public-sector (state higher-ed, state government) employers shows budget already allocated to solving this internally — a service can substitute for or augment that headcount. Verified
- TestParty's own content marketing (blog posts explicitly titled "Why 800+ Businesses With AccessiBe Were Still Sued," "I Got Sued with AccessiBe Installed — What Actually Happened") is written directly to buyers who installed the wrong fix and are now searching for what actually works — evidence of an active, articulable buyer search journey. Verified
- Multiple law firms (Fox Rothschild, and the broader ADA Title III defense bar) run standing content programs (webinars, "what 2025 filings mean for 2026") advising clients to get ahead of exposure — a referral-channel signal parallel to the tracking-tech blueprint's law-firm alert pattern. Verified
- Compliable and similar vendors market small-business accessibility protection starting near $490/year, showing a live self-serve price floor the mid-market service prices meaningfully above (justified by manual verification and code execution). Verified
Competitive Landscape
| Player | What they sell | Gap we exploit |
|---|---|---|
| accessiBe, UserWay, AudioEye (overlay widgets) | JavaScript snippet claiming automated compliance; self-serve, low price | FTC-sanctioned false-advertising precedent; cited as the barrier in 22.6% of H1 2025 suits; we position explicitly against this category |
| TestParty | AI-native platform: IDE/CI-CD code-fix suggestions, continuous monitoring, "human-first... powered by AI," 2-week managed remediation | Developer-tool-first motion assumes the buyer's engineering team drives adoption; weaker on litigation-defense documentation, VPAT production, and counsel-facing evidence framing — we lead with the legal-defense artifact, not the dev tool |
| Level Access, Deque | Enterprise manual audits, platform + services, $50k-$200k+/yr | Priced and staffed for Fortune 1000; too slow and expensive for mid-market e-commerce; we productize the same manual-audit rigor at 1/5th to 1/10th the price via AI-compressed workflow |
| Automated scanners (axe DevTools, WAVE, Siteimprove, Lumar) | Rule-engine scans developers run themselves | Buyer must operate and interpret; 30-40% detection ceiling; no code execution, no VPAT, no litigation-defense file |
| Boutique accessibility consultancies | Manual audits, sometimes remediation, hourly or project-based | Fragmented, hourly-priced, inconsistent SLAs, no productized monitoring subscription or AI-compressed delivery speed |
| ADA defense law firms | Legal response to demand letters/suits, hourly rates | Do not execute code remediation or produce ongoing conformance evidence; natural referral channel, not a competitor |
Competitor and Budget Validation
Budget already exists in four lines the buyer recognizes: in-house compliance headcount ($55k-$139k/yr per role), overlay-widget subscriptions (now a liability line, easy to redirect), legacy consulting ($50k-$200k+/yr), and defense-counsel spend triggered by demand letters ($5k-$270k+ per case). We redirect overlay and a slice of consulting/counsel spend into a fixed-fee outcome that reduces total exposure. Why alternatives are insufficient: overlays are now litigation evidence against the buyer; automated scanners produce dashboards a non-expert cannot act on; enterprise consultancies are priced out of reach for the most-sued segment (mid-market e-commerce). Why we win: we occupy the seam between "cheap and legally dangerous" (overlays) and "thorough but unaffordable" (Level Access/Deque) — the same seam TestParty has already proven is commercially viable, but we differentiate on litigation-defense documentation and counsel-facing evidence rather than a developer-tool-first motion. Why not a clone: no scanned incumbent sells manual AT-verified audit + code-executed remediation + signed VPAT + litigation evidence file as a single fixed-fee bundle explicitly marketed as the anti-overlay, mid-market-priced alternative.
Pricing Evidence and Proposed Pricing
- Anchors: manual audit market norms $100-250/page; VPAT services $350-950; legacy consultancy annual contracts $50k-$200k+; overlay subscriptions ~$490-$5,000/yr (low end, low credibility); TestParty positions itself as "a fraction" of legacy consulting cost. Verified
- Conformance Audit & Fix Sprint (MVP): $12,000 flat for up to 5 core user flows across one domain (audit + AT verification + first remediation sprint on critical/serious findings + VPAT 2.5 draft). 3-week delivery.
- Full-Site Conformance Program: $2,000-$3,500/mo — monthly automated re-scan, quarterly human AT re-verification, one remediation sprint/quarter, refreshed VPAT/ACR, litigation-defense evidence file maintained continuously.
- Remediation Sprint (standalone): $5,000 fixed per sprint (prioritized code-level fixes for a defined finding set, engineer-executed, AT-reverified).
- VPAT/ACR Production (standalone): $2,500 fixed, for buyers who already remediated elsewhere and need a signed conformance artifact for procurement.
- No hourly billing. Pricing is per-property/per-flow and outcome-based (a delivered conformance artifact), never time-and-materials.
Regulatory and Compliance Considerations
- ADA Title III (42 U.S.C. §12181 et seq.): circuit split persists on whether websites are "places of public accommodation," but plaintiffs continue to file successfully nationwide, especially in 2nd and 11th Circuit states (NY, FL); our audit maps findings to WCAG 2.2 AA as the de facto technical standard courts and DOJ guidance reference.
- ADA Title II (state/local government): DOJ's April 2024 final rule mandates WCAG 2.1 AA for web content and mobile apps, with tiered compliance deadlines of April 2026 (population ≥50,000) and April 2027 (smaller jurisdictions and special district governments) — a hard, dated compliance forcing function distinct from Title III litigation risk.
- Section 508: federal agencies and federal contractors; VPAT/ACR is the standard procurement artifact.
- European Accessibility Act (EAA): effective June 2025, requires WCAG 2.1 AA conformance for digital products/services sold to EU consumers — extends the buyer pool to any US company selling into the EU.
- State-level statutes: California Unruh Act frequently paired with ADA claims (adds statutory damages); other states developing parallel accessibility statutes.
- The service produces compliance artifacts (VPAT/ACR, evidence files); it does not issue legal opinions on litigation exposure or liability — those determinations remain with the client's counsel.
Licensing Boundary
| Layer | Boundary |
|---|---|
| AI system may | Crawl and render pages, run automated WCAG rule engines, classify likely violations by success criterion with confidence scores, draft code-level remediation suggestions, draft VPAT/ACR narrative language, monitor for regressions after each release |
| Certified human testers (CPACC/WAS) may | Verify every AI-flagged violation using real assistive technology (screen readers, keyboard-only navigation, switch access); make the final pass/fail determination per success criterion; sign the VPAT/ACR as the accessibility conformance statement |
| Senior engineers may | Review and approve every remediation pull request before merge into the client's codebase; verify no functional regression |
| Licensed attorneys must (client's counsel, never us) | Advise on litigation exposure, respond to demand letters, make legal-risk determinations, direct privileged engagements |
| We must not claim | To provide legal advice, guarantee immunity from suit, or promise "100% ADA compliant" (no such certification legally exists); engagement letters state findings reflect WCAG 2.2 AA conformance as of the test date, not a legal compliance guarantee |
| Required controls | Engagement disclaimers separating technical findings from legal advice; CPACC/WAS-certified tester sign-off on every conformance determination; audit logs of every test session; versioned evidence files with AT recordings; E&O and cyber insurance |
| UPL risk assessment | Low: technical auditing, code remediation, and conformance-artifact production is engineering/testing work (same posture as SOC 2 readiness and pen-test firms), not legal practice; findings are described in WCAG success-criterion language, never in "you are/are not liable" language |
AI-Native Advantage
AI changes the unit economics of accessibility work, not just its speed: (1) headless-browser crawling plus LLM-assisted DOM/ARIA reasoning collapses the mechanical 60-70% of an audit (rule-based checks, code-pattern detection, screenshot capture) from consultant-days to compute-minutes; (2) LLMs read component code and CMS templates to draft targeted remediation pull requests instead of generic advice, which certified testers then verify and engineers approve — turning "here's what's wrong" into "here's the fix, already written"; (3) VPAT/ACR narrative drafting, per-audience report versions (engineering / legal / procurement), and evidence-file assembly are generated then human-signed; (4) continuous monitoring re-scans on every deployment at near-zero marginal cost, making the recurring conformance subscription — the stickiest deliverable — high margin; (5) every human tester correction (a flagged "pass" that was actually a "fail," or vice versa) feeds a proprietary component-pattern knowledge base that compounds accuracy across clients using similar frameworks (Shopify, Salesforce Commerce Cloud, WordPress/WooCommerce). The customer never operates the AI directly; they receive a certified-tester-signed outcome.
Internal AI Engine Architecture
- Intake layer: structured onboarding form (domains, core user flows to test, CMS/framework, staging access or read-only repo branch); completeness checker blocks scheduling until access and flow definitions are sufficient.
- Normalization layer: site inventory normalized into a test manifest; user flows encoded as replayable scripts (home → category → PDP → cart → checkout, or client-specific critical paths); component inventory extracted from the codebase.
- Retrieval & knowledge layer: WCAG 2.2 success-criterion library, framework-specific component-pattern database (accumulated from prior engagements), case-law/regulatory-deadline tracker, per-client remediation history.
- AI workbench layer: headless-browser + automated rule-engine scan fleet (axe-core class rulesets); LLM classification of DOM/ARIA structure against success criteria with confidence scoring; LLM-drafted remediation pull requests; draft VPAT/ACR and report generation.
- Deterministic rules layer: hard rules for unambiguous automatable checks (color contrast ratios, missing alt attributes, form-label association, heading-order violations); severity-scoring formula (critical/serious/moderate/minor mapped to WCAG conformance level and user-flow criticality).
- Human chokepoint layer: certified tester verifies every AI-flagged "high/critical" finding and every ambiguous case using real assistive technology; senior engineer reviews every remediation PR before merge; lead reviews counsel-facing evidence-file framing.
- QA layer: second-pass sampling of low-severity auto-classifications (10% at launch); gold-standard test-page set re-run weekly to detect pipeline drift; red-team check: "what would a plaintiff's accessibility expert find that we missed?"
- Delivery layer: templated Conformance Audit Report, remediation PRs delivered via client's Git workflow, signed VPAT 2.5/ACR, evidence-file bundle (hashed, timestamped AT recordings and test logs), executive read-out deck.
- Learning loop: every tester correction updates the component-pattern knowledge base, prompts, and deterministic rules; every remediation outcome (verified fixed / broke functionality) feeds the remediation playbook per framework.
- Model-portability layer: provider-agnostic prompt/eval harness; classification accuracy evals re-run against a frozen gold test set on each new frontier model release; crawl/capture pipeline independent of any single LLM vendor.
AI-vs-Human Operations Pipeline
Dynasty Translation Layer
1. Buyer translation
Who pays: the GC or VP Digital/E-commerce of a mid-market retail/e-commerce brand (engineering co-sponsors). Urgent problem: "We got a demand letter (or a peer did) and I don't know if our site would survive real scrutiny." Outcome wanted: verified, code-level fix plus a documented artifact that ends the argument.
2. Service translation
Done-for-you. Customer receives: Conformance Audit Report, executed remediation PRs, signed VPAT/ACR, evidence file, exec read-out, continuous monitoring. Automation handles crawling/scanning/classification/PR-drafting/monitoring. Humans handle AT verification, code-review approval, and counsel-facing framing.
3. Workflow translation
Intake → test manifest approved → automated scan run → AI classification → certified-tester AT verification → remediation PR drafted → engineer review/merge → re-scan verification → VPAT/ACR signed → evidence file sealed → monitoring begins → quarterly refresh → renewal review.
4. Tooling translation
Day one: Playwright for crawl/capture, axe-core ruleset integration, frontier LLM API for classification/PR-drafting, screen-reader test rigs (NVDA/JAWS/VoiceOver), GitHub/GitLab for PR delivery, Notion/Airtable ops board, PandaDoc engagement letters, Stripe billing. No custom platform required before revenue.
5. Sales translation
Offer page: "22.6% of accessibility lawsuits in 2025 hit sites that already had a compliance widget. Find out what a real audit finds on yours — in 3 weeks, fixed fee, with the code fixed." Outreach: a free automated snapshot of the prospect's own site showing 2-3 real, specific findings.
6. Delivery translation
First 3 clients: founder + certified tester contractor + capture scripts + manual PR drafting review. Automate next: classification triage, PR drafting, report generation, monitoring. Never automate first: AT verification judgment, code-merge approval, counsel-facing framing.
7. Expansion translation
Playbooks per vertical (e-commerce → banking/credit union → healthcare patient portals → higher-ed/government Title II); native mobile app (iOS/Android) audit module; PDF/document remediation line; eventually a law-firm white-label/referral program.
Anti-Duplication Analysis
- Vs prior 204 blueprints: nearest neighbors are HIPAA Security Risk Analysis (security posture, not accessibility), Data Breach Notification Filing (incident response, not conformance testing), and the Tracking-Technology Exposure Audit (client-side data-flow/privacy litigation, entirely different regulation, different success criteria, different buyer role — privacy officer vs. GC/digital VP, different artifact — evidence file about data transmission vs. VPAT about WCAG conformance). None of the 204 prior runs test WCAG success criteria, perform assistive-technology verification, execute accessibility code remediation, or produce a VPAT/ACR. Not duplicative.
- Vs generic SaaS/overlay competitors: explicitly not an overlay widget (the category the FTC sanctioned and courts increasingly penalize) and not a self-serve scanner the buyer must operate — a done-for-you, human-verified, code-executed, litigation-documented outcome. Differentiated from TestParty (the closest AI-native competitor) by leading with litigation-defense documentation and a certified-tester sign-off model rather than a developer-tool-first motion.
- Under-served segment: mid-market e-commerce/retail ($10M-$500M revenue) — the most-sued vertical (~70% of suits), priced out of Level Access/Deque, correctly distrustful of overlay widgets after FTC action and their own litigation exposure.
- Unique assets built: framework-specific component-pattern knowledge base (Shopify, WooCommerce, Salesforce Commerce Cloud), certified-tester network, remediation playbook with regression-risk notes, plaintiff-firm demand-letter pattern library for objection handling.
Anti-Commoditization Analysis
Automated scanning will keep commoditizing — assume every CMS platform bundles a basic AI accessibility checker by 2027 (some already do). Defensibility lives in what pure scanners structurally cannot ship: (1) certified human AT verification — real screen-reader and keyboard-only testing that courts and DOJ guidance treat as the credible standard, which no automated tool can claim without repeating accessiBe's FTC problem; (2) code-executed remediation inside the client's actual repo with engineer sign-off — an accountability act, not a report; (3) signed VPAT/ACR — a formal conformance statement with a named certified professional's attestation, which carries evidentiary weight a self-generated scanner report does not; (4) litigation-defense evidence discipline — hashed, dated, AT-recording-backed files built for a courtroom, not a dashboard; (5) recurring conformance monitoring embedded in the client's release process, becoming part of their compliance calendar. If AI makes scanning free, the market response is more (correctly) anxious buyers who cannot tell noise from real risk — concentrating willingness to pay on verification, execution, and attestation, exactly our layers.
Service Delivery Workflow
- Sale closes → engagement letter (WCAG conformance findings, not legal-advice framing) → intake form.
- Test manifest approved by client (domains, core flows, staging access/repo branch).
- Automated scan + crawl run (1-2 days).
- AI classification + severity tiering (same day).
- Certified-tester AT verification of high/critical and ambiguous findings (accessibility engineer, 6-10 hrs).
- Draft report generated → lead review → delivery + 60-min read-out (week 2).
- Remediation sprint: AI-drafted PRs, engineer review/merge with client dev team, verification re-scan, before/after diffs.
- VPAT/ACR signed by certified tester; evidence file sealed (hashed, timestamped).
- Monitoring cadence begins; quarterly refresh repeats steps 3-8 at reduced scope.
- Renewal review with conformance-trend narrative and any new regulatory-deadline updates.
Operations as Product
- SOPs for every step above; test-flow scripts and severity-scoring rubrics are versioned templates, not bespoke work.
- Structured intake checklist with automated completeness validation (missing staging access blocks scheduling).
- Exception queue: any novel component pattern, ambiguous AT result, or scan failure routes to certified-tester review with SLA.
- Reviewer assignment by framework expertise (Shopify vs. custom React vs. WordPress); confidence scores on every AI classification drive review depth.
- Audit trail: immutable test-session logs and AT recordings; report versions in git; gold-standard example reports define "done."
- Red-team check on every report: one reviewer plays plaintiff's expert against our own findings before delivery.
- Root-cause postmortem for any counsel-rejected VPAT, missed violation discovered later, or remediation PR that broke client functionality — each becomes a rule, prompt, or SOP update.
No-Holes Quality Engine
- Dual-pass classification: deterministic WCAG rule signatures first, LLM reasoning second; disagreements auto-escalate to certified tester.
- 10% human sampling of auto-cleared low-severity items, tightened or loosened by measured error rate.
- Weekly pipeline regression against a frozen gold test-page set (drift detection across model updates).
- Report linting: every finding must cite a specific success criterion, page/component, and test artifact (screenshot or AT recording ID); no orphan claims.
- Client-facing accuracy SLA: any materially wrong finding corrected at no charge and logged as a quality-failure metric.
What the Human Expert Actually Does
| Task | License | Min/unit launch | Min/unit day-90 | Automation path | Quality risk | Cannot automate | Audit trail |
|---|---|---|---|---|---|---|---|
| AT verification of high/critical findings (screen reader + keyboard) | None (CPACC/WAS certification preferred) | 270 | 150 | Confidence-gated review; component-pattern knowledge base growth | False negative = missed litigation exposure; false positive erodes trust | Real assistive-technology usability judgment | AT recording + finding log per issue |
| Ambiguous/novel-component determinations | None (CPACC/WAS) | 90 | 45 | Pattern library narrows novel cases over time | High | Final call on edge-case conformance | Decision memo per component |
| VPAT/ACR sign-off | None (named certified professional attestation) | 45 | 25 | Templated narrative; human confirms accuracy | Overclaiming conformance is a legal/reputational risk | Attestation itself | Signed, versioned VPAT copy |
| Remediation PR review & merge approval | None (senior engineer) | 200 | 100 | AI-drafted PRs; engineer approves/edits | Breaking client functionality | Production-merge approval | Git PR review log + re-scan diff |
| Client read-out & engineering-team negotiation | None | 90 | 60 | Deck auto-generated; call stays human | Relationship/trust | Trust interface with client team | Call notes in CRM |
| Evidence-file sealing & QA | None | 45 | 15 | Fully scriptable | Low | — | Hash manifest |
Launch: ~12-13 expert hours per full audit+remediation cycle. Day-90 target: ~6.5 hours. Year-1 target: ~4.5 hours.
Minimum Viable Offer
The Conformance Audit & Fix Sprint — $12,000 fixed, 3 weeks. We test your five most critical user flows the way a plaintiff's accessibility expert and a real screen-reader user would test them, fix the highest-severity code-level barriers directly in your repo, and deliver a signed VPAT plus a dated evidence file your counsel and procurement partners can rely on. Includes a 60-minute read-out with engineering, digital, and legal at the same table.
Fulfillment Process
See §30. First-3-clients mode: founder + certified-tester contractor perform steps 3-6 with scripts + manual review (~28-32 hours each); templates harden after each delivery. Capacity math at maturity: one certified tester + one engineer pair supports ~10-12 audit-and-fix cycles/month plus a growing monitoring book; scan/classification fleet scales horizontally with compute only.
Tools and Systems
- Capture/scan: Playwright fleet, axe-core rule engine integration, cloud VMs for consistent rendering.
- AT testing: NVDA, JAWS, VoiceOver, switch-access rigs; screen-recording for evidence artifacts.
- Analysis: frontier LLM APIs (classification, code-fix drafting, report generation), embedding search over the component-pattern knowledge base, deterministic WCAG rule engine.
- Ops: Airtable/Notion production board; git for report/evidence versioning; GitHub/GitLab for remediation PR delivery.
- Client-facing: PandaDoc, Stripe, Cal.com, simple client portal (phase 2), Loom read-out recordings.
- Marketing: webinar stack, LinkedIn, SEO/AEO blog, free public-page snapshot generator (the lead-magnet engine — same pipeline, public pages only, auto-report).
Human-in-the-Loop Quality Control
Two mandatory chokepoints (AT verification of high/critical findings; remediation-PR merge approval) and one conditional (counsel-facing evidence-file framing review). Confidence-scored AI output routes: below 0.7 auto-escalate, 0.7-0.9 sampled, above 0.9 spot-checked. All chokepoint decisions logged with reviewer identity and credential — the audit trail is itself a sales asset (we practice the evidentiary discipline we sell).
Nonlinear Scaling and Unit Economics
| Metric | Target |
|---|---|
| Revenue per FTE | $400k-$550k by month 18 |
| Gross margin | 50-58% at launch → 70-75% at maturity |
| COGS per $12,000 audit+fix sprint (launch) | ≈ $5,100: certified-tester labor ~$2,300 (13 hrs blended $175), engineer PR-review labor ~$1,000, scan compute $80-150, LLM inference $40-100, tooling/hosting amortized $200, QA sampling $300, PM/support $500, insurance/compliance allocation $350, sales-support materials $270 |
| COGS per unit (day-90 / yr-1) | ≈ $3,200 / ≈ $2,400 (tester hours fall to 6.5 → 4.5, PR-drafting near-free) |
| Model cost per unit | $40-100 launch → <$30 yr-1 Inferred |
| Monitoring COGS | <$300/mo per client vs $2,000-$3,500/mo price ⇒ 85%+ marginal margin |
| Automation % | Launch ~55% of task-minutes → 90-day ~68% → yr-1 ~82% |
| Throughput per tester+engineer pair/day | Launch 0.25 cycles → yr-1 0.55 cycles + monitoring book |
| Cycle time | 21 days → 12 days |
| Rework rate target | <8% of reports/PRs require post-delivery correction; <3% yr-1 |
| Quality failure target | 0 counsel/procurement-rejected VPATs; <2% materially wrong findings |
| Escalation rate target | <18% of auto-classifications escalate by yr-1 |
| CAC payback | <60 days (audit fee covers CAC in wedge motion) |
| Lead-magnet → consult conversion | Assume 12-20% of snapshot recipients book (personalized findings) Inferred |
| Consult → paid audit | Assume 25-35% Inferred |
| Audit → monitoring retainer | Target 55%+ attach |
| Retention | Target 80%+ annual retainer retention (compliance-calendar and release-process embedded) |
| Margin expansion path | Monitoring mix shift + automation of low-severity classification + PR drafting ⇒ blended GM 70-75% as retainer book grows |
Distribution Proof Table
| Channel | Why ICP is reachable | First message/content angle | Conv. assumption | Proof source | Measurement | Follow-up |
|---|---|---|---|---|---|---|
| Personalized outbound (free snapshot memo) | E-commerce/digital VPs named on company sites/LinkedIn; their site is publicly scannable for automated-tier findings | "3 accessibility barriers we found on [site] in 10 minutes — and why your overlay didn't catch them" | 5-9% reply; 12-20% of repliers book I | Demand-letter wave and overlay-failure narrative make topic pre-sold | Reply/booking rate per 100 sends | Full snapshot → consult → audit |
| ADA defense law firm referrals | Firms handle the legal response to demand letters but don't execute code remediation | "We're the technical execution bench for your clients' remediation and VPAT needs — referral or white-label" | 2-5 firm partners yr-1, 1-3 referrals/quarter each I | Active ADA defense-bar content programs (Fox Rothschild and peers) | Referrals per partner | Co-webinars, shared checklists |
| E-commerce platform communities (Shopify Plus partner network, BigCommerce, WooCommerce agencies) | Agencies build the sites getting sued and want a trusted remediation partner to refer to | "Add accessibility remediation to your service stack without hiring a certified tester" | 3-6 agency partnerships yr-1 I | Platform partner-directory precedent (accessibility apps already listed) | Referrals per agency partner | Partner-tier pricing, co-marketing |
| LinkedIn founder content | ICP (GC, VP Digital, VP Engineering) over-indexes on LinkedIn compliance/e-commerce content | Overlay-failure teardowns, ruling explainers, before/after remediation diffs | Compounding; 1-2 inbound/mo by day 90 I | TestParty's own content-marketing volume proves the ICP consumes this content | Followers→DM→consult funnel | — |
| SEO/AEO | Buyers search "ADA demand letter what to do," "accessiBe alternative," "WCAG audit cost," "is my overlay enough"; answer engines cite explainer content | Definitive guides + free snapshot CTA | Slow build; 5-10 leads/mo by month 6 I | TestParty/DigitalA11Y/Accessible.org content already ranks and drives leads in this niche | Organic + AI-referral leads | — |
| Cyber/E&O insurance broker panels | Some carriers ask about accessibility posture at renewal; parallel to cyber-insurance pattern in prior blueprints | "Pre-renewal accessibility attestation package" | Exploratory U | — | Broker intros/quarter | Panel-vendor application |
Sales and Outreach Plan
Founder-led sales for the first 20 clients. Motion: free snapshot memo → 30-min findings call (diagnostic, not demo) → fixed-fee audit+fix proposal same day → audit read-out doubles as monitoring-retainer upsell. Sales collateral: two anonymized before/after remediation teardowns, litigation-cost calculator, one-page "how we work alongside your defense counsel" explainer. Objection playbook: "we already have an overlay" (show the 22.6%-of-suits and FTC-fine data), "our dev team can do this" (show the 30-40% automated-detection ceiling and AT-verification gap), "we use axe DevTools" (show the certified-tester verification and VPAT sign-off gap).
Founder-Led Content Plan
Positioning: the technical and evidentiary translator between the courtroom and the codebase. Cadence: 3 LinkedIn posts/week + 1 long-form piece/week. Pillars: overlay-failure teardowns (real capture evidence of what widgets miss), ruling/settlement explainers in operator language, remediation field notes (what broke, what didn't, framework-specific), WCAG success-criterion myth-busting, quarterly "State of Mid-Market Accessibility" mini-research from anonymized aggregate scan data — a defensible data asset competitors lack.
First 30 Days of Content
10 educational posts
- Your accessibility overlay is legal evidence against you. Here's the FTC case that proves it.
- 3,117 website-accessibility suits in 2025. Here's exactly what plaintiffs' experts test first.
- Anatomy of an ADA demand letter — and the 3 mistakes recipients make in week one.
- Automated scanners catch 30-40% of WCAG violations. Here's what the other 60% looks like on a real screen reader.
- Nearly half of 2025 ADA suits hit repeat defendants. Why "we fixed it once" doesn't hold up.
- The European Accessibility Act is live. If you sell to the EU, here's what changed in June 2025.
- DOJ's Title II WCAG 2.1 AA deadline is April 2026 for larger jurisdictions. What that means if you're a vendor to government.
- What a VPAT actually proves — and why a self-generated scanner PDF isn't one.
- The checkout flow is where 70% of e-commerce accessibility suits start. Here's how to test yours in 10 minutes.
- What a plaintiff's accessibility expert sees in your DOM that your automated scanner doesn't.
3 diagnostic teardown formats
- Anonymized Conformance Teardown: real screen-reader test recording of a (permissioned/anonymized) e-commerce checkout flow, showing exactly where it breaks.
- Before/After Remediation Diff: code-level pull request pre/post fix, with functional demo intact.
- Overlay Autopsy: side-by-side of what an installed overlay widget claims to fix vs. what a certified tester still finds broken.
2 lead-magnet angles
- Free Accessibility Snapshot: automated public-page scan of the prospect's own domain → 2-page findings memo with 2-3 specific, real issues (the conversion engine).
- Accessibility Litigation Readiness Kit: demand-letter response checklist + WCAG 2.2 AA self-assessment worksheet + overlay-vs-remediation comparison one-pager.
1 webinar
"Your Overlay Isn't Protecting You — Here's the Proof" — co-hosted with an ADA defense attorney: 20 min litigation landscape (them), 20 min live AT-testing demo on a volunteer site (us), 20 min Q&A. CTA: free Snapshot.
1 outbound diagnosis template
Subject: What a screen reader found on [Company]'s checkout page
[Name] — we ran a standard accessibility scan on [company domain]'s checkout flow last week (public pages only). Three things a screen-reader user would hit before completing a purchase: [finding 1], [finding 2], [finding 3]. This pattern matches what plaintiffs' experts document in the [comparable] cases we've reviewed. Happy to send the 2-page findings memo — no strings. If it's already handled, the memo is still useful for your file. — [Founder]
Lead Magnet and Waitlist Plan
What the buyer receives before paying: the Accessibility Snapshot — real findings from their own property, produced by the same engine that powers paid audits. Why it creates trust: it is evidence, not marketing; it demonstrates certified-tester-grade capability in one artifact and specifically calls out overlay-widget gaps if one is installed. Pain signal captured: requesting a scan of specific domains self-identifies litigation anxiety and names the properties they worry about. Follow-up: findings call within 48 hours of delivery; nurture sequence keyed to their vertical's recent settlement/lawsuit news. Sales-ready qualification: (a) demand letter received or peer-brand suit in the news, (b) has an overlay widget installed (strong pain signal), (c) digital/engineering owner engaged, (d) $10M+ revenue. Waitlist mechanic for launch: "10 founding brands at $8,500 (charter pricing) — capped." Signups are not PMF; paid audits and retainer attach are the metrics that matter.
Warm GTM Plan
Sequence all Snapshot recipients, webinar attendees, and content engagers into a 6-touch nurture: news-trigger emails ("[Peer Brand] was sued today — your Snapshot flagged the same pattern"), quarterly re-scan offers, and law-firm-introduction offers. Every existing contact of the operator in e-commerce, retail-tech, and digital-agency circles gets a personal note with one relevant finding, not a pitch.
Targeted Outbound Plan
List build: litigation trackers (recently-sued brands' direct competitors first) × Shopify Plus/BigCommerce merchant directories × LinkedIn digital/e-commerce/GC titles. Prioritize: (1) brands in the most-litigious states (NY, FL, Illinois), (2) brands whose public pages our engine already flags with an installed overlay, (3) brands with recent site redesigns (new, unaudited code). 25 personalized memos/week; each contains real findings. This is diagnosis-led outbound — the memo is the product demo.
Answer-Engine / Search Visibility Plan
Own the question space buyers ask ChatGPT/Perplexity/Google: "received ADA demand letter what to do," "is my accessibility overlay enough," "accessiBe alternative," "how much does a WCAG audit cost," "VPAT vs ACR difference." Tactics: definitive long-form guides with original data (our anonymized scan statistics), structured FAQ schema, citations-friendly formatting, attorney co-authored pieces for authority, and a public (redacted) settlement/lawsuit tracker page updated monthly — link-magnet and AEO citation target.
Pilot Design and Early-Demand Trap Mitigation
Charter cohort: cap 8 e-commerce/retail brands at $8,500 (vs $12,000 list) in exchange for reference rights (logo optional), a feedback call after each deliverable, and permission to anonymize findings for research content. Learning objectives: component-pattern knowledge-base coverage, classification error rate, read-out format resonance, engineering-team objection patterns, monitoring-retainer attach willingness. Trap mitigation: charter price still profitable (>35% GM at launch COGS); no custom scopes accepted; "free pilot" explicitly rejected — payment is the demand test.
Early-Access Feedback Flywheel
- Weekly internal triage of all pilot feedback; tagged as product feedback (template/rule/prompt change) vs custom work (declined or priced separately).
- Every tester correction during AT verification auto-files a knowledge-base entry (component pattern, framework quirk, success-criterion edge case).
- Every read-out records the three questions the client asked first — these reorder the report's executive section.
- Fix-before-expand list: any classification error class seen twice, any scan failure mode, any counsel/procurement VPAT objection.
Build-Before-Scale Checkpoints
- After 5 pilots: harden intake (domain/framework/access checklist), component-pattern knowledge base v1, evidence-file spec frozen, QA sampling calibrated.
- After 10 clients: SOPs complete; exception queue with SLAs; reviewer checklist v2; delivery templates locked; measure real hours/unit.
- After 20 clients: pause new sales until measured: COGS/unit, rework %, escalation %, cycle time, retainer attach, monitoring margin. Acceptable temporary manual work: test-flow scripting for novel frameworks, read-out decks. Red-flag manual work (signals non-scalability if persistent): per-client classification from scratch, hand-built PRs, bespoke evidence formats.
- Repeated fixes must land as rules/prompts/templates within one week or they count as unresolved debt.
7-Day Launch Plan
- Day 1-2: entity/insurance quotes (E&O + cyber); engagement-letter template with UPL/no-guarantee disclaimers; scan pipeline MVP on own test sites plus axe-core integration.
- Day 3: run full pipeline against 3 public e-commerce sites (public pages only) → 3 teardown drafts.
- Day 4: offer page + Snapshot request form live; charter-cohort waitlist CTA.
- Day 5: 25 outbound memos to recently-sued brands' direct competitors; 3 ADA-defense law-firm partner emails.
- Day 6: first LinkedIn overlay-failure teardown post; webinar co-host outreach.
- Day 7: review replies; book findings calls; refine memo template from response data.
30-Day Launch Plan
- Close 2-4 charter audits ($17k-$34k). Deliver first audit end-to-end; harden templates.
- 100 outbound memos cumulative; 1 webinar delivered; 12+ content pieces published.
- Component-pattern knowledge base v1 (150+ validated patterns across 2-3 major frameworks); classification eval harness running.
- 1 law-firm referral relationship in writing; 1 e-commerce agency partnership discussion started.
- Metrics baseline: reply rate, snapshot→call, call→close, hours/unit, COGS/unit.
90-Day Launch Plan
- 8-pilot charter cohort complete → checkpoint review (§49). List price to $12,000; monitoring retainer launched with 55%+ attach target.
- Hire/contract certified tester #1 when founder validation hours exceed 60/mo.
- Publish "State of Mid-Market Accessibility Q3 2026" research report (anonymized aggregate) — PR/AEO anchor.
- 2-3 firm referral partners active; 12-18 total clients; ~$140k-$210k cumulative revenue Inferred plan targets.
- Decide vertical #2 (regional banking vs. healthcare patient portals vs. higher-ed Title II) from inbound mix.
Metrics and KPIs
- Demand: memos sent, reply %, snapshots delivered, findings calls, close rate, pipeline $.
- Delivery: cycle time, expert hours/unit, automation %, escalation %, rework %, VPAT/procurement-acceptance rate.
- Economics: COGS/unit, gross margin, ACV, retainer attach %, retention %, revenue/FTE, CAC payback.
- Quality: materially-wrong-finding rate, missed-violation discoveries post-delivery (target 0), VPAT challenges (target 0).
- Learning: knowledge-base entries/week, eval accuracy per model release.
Risks and Mitigations
Top three: (1) Title III circuit split resolves unfavorably or Congress narrows ADA website applicability — mitigation: multi-statute positioning (Title II government deadlines, Section 508, EAA, state Unruh-style statutes) means the underlying compliance need survives any single-theory setback; monitor quarterly. (2) TestParty or a well-funded competitor moves into litigation-defense documentation — mitigation: build the certified-tester network, component-pattern knowledge base, and law-firm referral relationships as durable assets faster than a developer-tool-first competitor can pivot its GTM motion. (3) UPL or overclaiming-conformance liability — mitigation: strict "WCAG conformance as of test date" framing, never "ADA compliant" or "lawsuit-proof" language, E&O insurance, attorney-reviewed engagement letters.
Exhaustive Risk Register
R1 — ADA Title III website applicability narrowed by courts/Congress (Likelihood: Low-Med · Impact: High)
The "is a website a place of public accommodation" circuit split has persisted for years without full resolution; a narrowing ruling or federal legislation could reduce Title III filing volume. Mitigation: revenue mix shifted toward Title II government deadlines, Section 508 procurement (VPAT demand independent of litigation), and EAA-driven EU-market exposure by month 9-12; the audit and remediation product remains valuable for these independently. Trigger: any circuit-splitting Supreme Court grant of cert → reweight GTM within 30 days.
R2 — Overlay vendors improve product and reduce their own litigation-trigger rate (Med · Med)
If accessiBe/UserWay materially improve underlying accessibility (not just marketing claims), the "overlay is dangerous" objection-handling narrative weakens over time. Mitigation: our value proposition shifts emphasis toward code-level ownership, VPAT attestation, and continuous monitoring rather than solely "overlays are bad" messaging; monitor overlay vendor product changes quarterly.
R3 — TestParty or Level Access launches a competing litigation-defense-documentation product (High · Med)
Natural expansion for either. Mitigation: certified-tester network, framework-specific knowledge base, and law-firm referral relationships are hard to replicate quickly; position as their partner/referral bench before competing head-on with either.
R4 — Overclaiming-conformance liability / false-advertising exposure for us (Low · High)
Mitigation: never claim "100% ADA compliant" or "lawsuit-proof"; all findings framed as "WCAG 2.2 AA conformance as of test date"; engagement letters reviewed by outside counsel; E&O insurance; explicit disclaimer that no legal guarantee exists (learned directly from the accessiBe FTC precedent).
R5 — Missed violation after we delivered a "conformant" report (Med · High)
Reputation-critical, parallel to the tracking-tech blueprint's "missed tracker" risk. Mitigation: scope language ("point-in-time, enumerated flows"), continuous monitoring upsell, red-team pass before delivery, gold-set regression testing, insurance.
R6 — Client engineering team won't grant repo/staging access (Med · Med)
Mitigation: read-only branch access options, screen-share-applied changes with client engineer pairing, or ticket handoff with verification re-scan; the audit product works even without code access (findings-only tier).
R7 — Remediation PR breaks client functionality (Med · High)
Mitigation: senior engineer review mandatory before every merge; staging-environment testing required; rollback plan documented; functional regression test suite run post-merge.
R8 — Framework fragmentation limits knowledge-base reuse (Med · Med)
Every CMS/framework combination is somewhat different, capping automation leverage. Mitigation: focus wedge on 2-3 dominant e-commerce platforms (Shopify Plus, WooCommerce, Salesforce Commerce Cloud) first; expand framework coverage deliberately, not opportunistically.
R9 — Price compression from offshore/cheap automated-only competitors (High · Med)
$500 "AI accessibility scan" offers will proliferate. Mitigation: we don't sell scans; we sell certified verification + code execution + signed VPAT + evidence file + accountability; publish comparison content explicitly (as TestParty already does against overlays).
R10 — Concentration in e-commerce wedge during a retail-margin squeeze (Med · Med)
Compliance/discretionary budgets tighten in a retail downturn. Mitigation: litigation exposure is board-level and often insurance-linked; price point sits under most approval-committee thresholds; vertical #2 (banking or healthcare) ready by month 6.
R11 — Founder/certified-tester dependency at chokepoints (High · Med)
Mitigation: decision memos + gold examples from engagement #1; hire second certified tester at 60 validation-hours/mo; reviewer certification checklist; cross-train engineers on remediation patterns.
R12 — Certified-tester talent scarcity (Med · Med)
CPACC/WAS-certified professionals are a small labor pool. Mitigation: build a contractor bench early, invest in internal certification pathway for engineers, avoid over-promising capacity before headcount is secured.
R13 — Scan pipeline flagged as hostile traffic / blocked (Low · Low)
Mitigation: client-authorized scans with allowlisted agents; public-page snapshots kept polite (rate-limited, robots-aware) and legally reviewed.
R14 — Data-handling incident on our side (Low · High)
We hold scan/test artifacts describing client vulnerabilities. Mitigation: encrypted storage, access controls, no real end-user PII captured (synthetic test sessions only), SOC 2 roadmap, cyber insurance.
R15 — Serial-plaintiff or "professional tester" ethics concerns affect market perception (Low · Med)
Some ADA Title III litigation is criticized as serial-plaintiff abuse, which could create buyer skepticism toward accessibility vendors generally. Mitigation: position clearly as a defense-side/proactive-compliance service working with the client's counsel, never as a plaintiff-side or enforcement entity; content emphasizes genuine usability outcomes for people with disabilities, not just litigation avoidance.
What Could Kill This
Simultaneous narrowing of ADA Title III website applicability by courts/Congress and failure to convert audit clients into Title II/Section 508/EAA-driven governance retainers before that happens; a well-funded competitor (TestParty, Level Access, or a new entrant) launching true litigation-defense documentation at software prices; or a certified-tester talent bottleneck that caps growth below what demand supports. The kill-switch metric: if by month 6 monitoring-retainer attach is <25% and audit demand is purely demand-letter-reactive with no Title II/EAA/procurement-driven pipeline, the business is a project shop, not an engine — pivot toward the law-firm white-label model or the higher-ed/government Title II vertical.
Go/No-Go Reasoning
Go. Evidence threshold met on every element: identified buyer (e-commerce GC/VP Digital) V; painful specific problem (unverified accessibility barriers under active, growing litigation) V; existing spend (in-house headcount, overlay subscriptions, legacy consulting, defense counsel) V; active demand (8,667 filings, 36% website share, repeat-defendant pattern) V; competitor/budget validation (Level Access, Deque, TestParty, overlay vendors) V; credible win path (service seam between discredited overlays and unaffordable enterprise consulting) I; narrow wedge (Conformance Audit & Fix Sprint) defined; first-sale path (free snapshot outbound) executable week 1; no platform build required; no unresolved fatal blocker (UPL/overclaiming risk mitigable via disclosure discipline learned from the accessiBe precedent); 50%+ GM credible at launch and 70%+ at maturity; believable distribution (law-firm referrals + diagnosis-led outbound + agency partnerships). Honest caveats: competitive whitespace is a 4/5, not 5/5 — TestParty already occupies a credible AI-native position and the win depends on differentiated litigation-defense positioning and certified-tester credibility; and Title III litigation tailwind must be converted into Title II/Section 508/EAA-driven recurring governance revenue within ~12 months to de-risk R1.
Final Recommendation
Launch the Conformance Audit & Fix Sprint for mid-market e-commerce/retail brands immediately: the scan-and-classification pipeline is buildable in days on top of axe-core and a frontier LLM, the lead magnet is the product (a free snapshot of the prospect's own site), buyers are pre-educated by settlement headlines and their own overlay's litigation record, and the first invoice is realistically 2-4 weeks out. Convert every audit into the Full-Site Conformance Program; convert every plaintiff-firm filing surge into outbound; convert every certified-tester correction into the knowledge base. Re-evaluate vertical expansion (banking, healthcare patient portals, higher-ed/government Title II) and the law-firm white-label channel at day 90.
Source List
- ADA Title III Blog — Federal Lawsuit Filings Fall Slightly to 8,667 in 2025
- ADA Title III Blog — Website Accessibility Lawsuit Filings Bounce Back in 2025
- WCAGsafe — ADA Lawsuit Statistics 2025–2026: Data & Trends
- Accessibility.build — Accessibility Lawsuit Tracker 2026
- Marker Seven — What 2025's Accessibility Lawsuit Numbers Mean for 2026
- BeAccessible — ADA Lawsuit Statistics by Year, Industry, and State
- TestParty — Why 800+ Businesses With AccessiBe Were Still Sued
- TestParty — "I Got Sued with AccessiBe Installed" — What Actually Happened
- Compliapoint — Accessibility Overlays Don't Work: The 2025 Lawsuit Data
- A11y Collective — Are Accessibility Overlays a Good Investment?
- Acute ADA Compliance — Why Accessibility Overlays Are Not Compliance
- The Samuel Law Firm — Using an Accessibility Widget? You Risk ADA Litigation
- GetWCAG — Complete European Accessibility Act (EAA) Guide 2026
- D2i Technology — Accessibility Testing 2026: WCAG 3.0, ADA Deadlines & AI-Driven Compliance
- Vervali — WCAG 3.0 Accessibility Testing & Compliance 2026
- QASkills — AI Accessibility Testing Tools 2026: Complete Guide
- TestParty — Automated WCAG Compliance
- TestParty — How Much Does Website Accessibility Cost? 2025 Pricing Guide
- TestParty — ADA Lawsuit Cost Statistics: Settlement & Defense Data
- TestParty — How Much Does Level Access Cost and Is It Worth It?
- DigitalA11Y — Web Accessibility Audit Cost Guide: Detailed Pricing Factors 2026
- DigitalA11Y — Digital Accessibility Services Pricing Guide
- Accessible.org — Accessibility Services Pricing Page
- Accessible.org — ADA Website Compliance Lawsuit Settlement Amounts
- Accessible.org — How Much Does a Digital Accessibility Audit Cost?
- Compliable — Small Business ADA Compliance Protection
- A11yjobs — Accessibility Compliance Program Manager, Salesforce
- ZipRecruiter — Web Accessibility Jobs
- A11yjobs — Digital Accessibility & Assistive Technology Jobs
- Fortune Business Insights — Digital Accessibility Software Market Size
- Straits Research — Digital Accessibility Market Size, Share, Growth
- Precedence Research — Digital Accessibility Software Market Size
- CHEQ — How to Deal with CPRA Data Subject Access Requests (candidate-comparison evidence)
- EC-Council — EU AI Act vs NIST AI RMF vs ISO/IEC 42001 (candidate-comparison evidence)
- LearnTPRM — AI Vendor Risk Management: Complete TPRM Guide 2026 (candidate-comparison evidence)