AccessLock — The ADA Title III / WCAG Accessibility Audit, Remediation & Litigation-Defense Engine

AI-native service business blueprint · Run date 2026-07-09 · Run #205 · Slug: ada-wcag-accessibility-litigation-defense-engine

Final Decision: Blueprint

GO — BLUEPRINT

A done-for-you digital accessibility service for litigation-exposed mid-market e-commerce, retail, financial-services, and healthcare organizations: manual expert audit (not an overlay widget) + engineer-executed code remediation + signed VPAT/Accessibility Conformance Report + continuous regression monitoring + a litigation-defense evidence file — sold as a fixed-fee outcome, delivered behind an internal AI scanning/classification/remediation-drafting engine with certified human accessibility-tester chokepoints. Positioned explicitly against the two failed incumbent models: self-serve overlay widgets (legally disfavored, FTC-sanctioned) and $150k+ hourly big-4 consultancies.

Executive Summary

8,667
ADA Title III federal lawsuits filed in 2025 Verified
36%
Share that were website-accessibility suits (3,117 of 8,667), up from 28% in 2024 Verified
~50%
Of 2025 federal filings were against repeat defendants — the problem recurs after "fixing" Verified
$1M
FTC fine against accessiBe (Apr 2025) for false compliance-widget advertising Verified
22.6%
Of H1 2025 ADA website suits targeted sites that already had an accessibility overlay installed Verified
$55k–270k+
Typical total exposure per case incl. settlement, defense, remediation, monitoring Inferred

Digital accessibility litigation has become an industrial-scale, repeat-defendant business for plaintiffs' firms, while the two products the market actually sells — self-serve overlay widgets and hourly big-4 consulting — both fail structurally. Overlays were the subject of a $1M FTC enforcement action for false advertising and are now cited as evidence of noncompliance in nearly a quarter of new suits. Hourly consultancies price out small and mid-market defendants and rarely execute the code fix. The gap is a productized, fixed-fee, manual-audit-plus-human-verified-remediation service that produces a signed VPAT/ACR and a dated evidence file defense counsel can use — delivered at a fraction of $50k–$200k/year legacy consulting cost via an AI scanning-and-drafting engine with certified human testers at the judgment chokepoints. Wedge ICP: mid-market e-commerce and retail brands (the most-sued vertical, ~70% of 2025 suits) that received a demand letter or want to get ahead of one.

Thesis

Web accessibility remediation is a bounded, largely automatable production pipeline — crawl, render, run automated WCAG rule engines, classify violations by success criterion, draft code-level fixes, verify with assistive technology — with genuine judgment concentrated at a few chokepoints: does an automated "pass" reflect real usability for a screen-reader or keyboard user, and does a given fix actually resolve the barrier without regressing functionality. That judgment requires certified human testers (CPACC/WAS credentialed) using real assistive technology, which is exactly why automated tools plateau at 30–40% issue detection and overlays fail in court. AI does not replace that judgment; it multiplies it — collapsing the 60–70% of the pipeline that is mechanical rule-checking, code-pattern-matching, and report drafting, so certified testers spend their scarce hours only where a machine cannot substitute. The regulatory backdrop (Title III case law, DOJ's 2024 Title II WCAG 2.1 AA rule, the European Accessibility Act effective June 2025) is a durable moat: it requires human-attestable proof, which is precisely what AI-native, human-verified delivery can produce more cheaply than legacy consultancies and more credibly than SaaS overlays. Pricing is per-property/per-page and outcome-based (a signed conformance artifact), never hourly.

Discovery Rationale

This run generated candidates from the assigned unexplored-terrain list plus independent research: (1) ADA Title III/WCAG digital accessibility audit-remediation-VPAT-monitoring; (2) DSAR fulfillment under CCPA/CPRA and the growing patchwork of state privacy statutes; (3) AI vendor risk/third-party AI governance documentation (NIST AI RMF/EU AI Act); (4) state data-broker registration and universal opt-out compliance (CA Delete Act, OR, TX, VT); (5) PAGA wage-and-hour exposure audits for California employers. ADA/WCAG accessibility won because it combines the strongest evidence across every dimension: the largest, most current litigation-volume statistic of any candidate this run (8,667 federal filings in 2025, verified via a specialist law-firm tracker), a discredited and FTC-sanctioned incumbent product category (overlays) that the service explicitly displaces, existing venture-funded AI-native competitors proving the model works commercially (TestParty), and zero overlap with any of the 204 prior blueprints — none of which touch WCAG success criteria, assistive-technology testing, or VPAT/ACR production. It is also the only candidate this run with a live, free, self-service lead magnet: the prospect's own public website is the diagnostic.

Candidate Comparison

Five candidates generated this run; scored 1–5 on the 20 standard criteria.

CriterionADA/WCAG accessibility audit+remediationDSAR fulfillment (CCPA/CPRA)AI vendor risk / third-party AI governanceData-broker registration & opt-out compliancePAGA wage-and-hour exposure audits
1. Low trust burden54342
2. Low task-level judgment44252
3. High intelligence threshold42424
4. Regulation as moat54345
5. No physical labor55554
6. Sam Altman test53424
7. Outcome-pricing potential53333
8. Gross-margin potential54433
9. Buyer urgency53224
10. Competitive whitespace42343
11. Novelty vs prior 204 outputs54554
12. Fit with current AI capability54433
13. Active demand evidence53224
14. Existing budget/competitor proof54323
15. Waitlist/lead-magnet potential52222
16. Narrow MVP wedge clarity54333
17. Distribution-channel clarity53223
18. Licensing feasibility44442
19. Operational repeatability55343
20. Speed to first revenue54333
Total (max 100)9671626462

Why runners-up lost: DSAR fulfillment — real per-request cost pain (~$1,400/request manually) but low intelligence threshold (largely a data-mapping/workflow-execution task well-suited to pure SaaS, e.g., OneTrust/Securiti/Osano already own it as a feature, not a standalone service opportunity) and thin evidence of an unmet done-for-you niche. AI vendor risk/third-party AI governance — directionally strong long-term (EU AI Act enforcement from Aug 2026) but task-level judgment is high (assessing a vendor's model risk resists confident automation this year) and demand is still mostly "read the framework," not yet "buy the audit" — too early for a fixed-fee wedge. Data-broker registration — genuinely low-judgment, checklist-shaped work, but the regulatory footprint (CA, OR, TX, VT only) is narrow, per-unit fees are small ($400/yr-ish per state), and it lacks buyer urgency (no litigation forcing function). PAGA audits — very real California employer pain but sits close to existing wage-and-hour/employment-law practice (UPL risk high — this is legal risk-quantification work courts and the plaintiffs' bar treat as legal advice) and requires attorney sign-off on nearly every deliverable, weakening the licensing-feasibility and low-judgment gates.

CODE Validation

C — Consumer/Buyer Trend

Web-accessibility suits reached 3,117 of 8,667 federal ADA Title III filings in 2025 (36%, up from 28% in 2024), with New York (1,021) and Florida (961, nearly double its 2024 count) leading. Over 5,000 digital accessibility lawsuits were filed in 2025 including state courts. Nearly half of 2025 federal filings named repeat defendants — proof that ad hoc, unverified fixes do not hold up, creating durable recurring demand for verified remediation and monitoring, not a one-time fix. Verified

O — Opportunity

The two dominant products both fail the buyer. Overlay widgets (accessiBe, UserWay, AudioEye-style toolbars) are now themselves cited as the barrier in litigation — 22.6% of H1 2025 website suits targeted sites that already had an overlay installed, and the FTC fined accessiBe $1M in April 2025 for falsely advertising the widget could make any site compliant in 48 hours. Automated-only tools (including AI-powered scanners) catch only 30–40% of WCAG violations by practitioner consensus; screen-reader compatibility, logical reading order, and cognitive accessibility require human evaluation. Legacy manual consultancies (Level Access, Deque) are thorough but priced and staffed for enterprise ($50k–$200k+/year), pricing out the mid-market e-commerce and regional-brand segment that is disproportionately targeted (e-commerce/retail = ~70% of 2025 suits). No mainstream provider sells a fixed-fee, manually-verified, code-remediated, VPAT-backed outcome sized for a $10M–$500M revenue e-commerce brand. Verified (gap characterization Inferred)

D — Demand

Buyers are already paying: in-house "Accessibility Compliance Program Manager" and "Digital Accessibility Specialist" roles are open at companies from Salesforce to state higher-education systems ($55k–$139k salary range), traditional consulting runs $50k–$200k+/year per TestParty's own comparison content, and a venture-funded AI-native competitor (TestParty) already sells a compressed "two-week" managed remediation service — proof of both budget and market validation for the AI-native model. Demand letters seeking $10,000–$50,000+ are a standing, repeatable trigger event; total exposure once settlement, defense, remediation and monitoring are counted runs $55,000–$270,000+ per case. Verified

E — Economic Sizing

The global digital accessibility software market is valued at roughly $0.85–$1.4B in 2025 depending on source methodology, growing 6.8–10.25% CAGR; the narrower accessibility-testing-tools market sits near $610M in 2025 growing to ~$828M by 2031. Layering a services wedge onto that: an estimated several hundred thousand US mid-market e-commerce/retail/financial-services sites face realistic litigation exposure; even a conservative 5,000–15,000 realistic target-organization pool × $8,000–$25,000/year (audit + remediation + monitoring bundle) implies a $40M–$375M serviceable wedge market before expanding beyond e-commerce into healthcare, banking, and higher-ed verticals (which face parallel Title II/Section 508 deadlines). A 150–300 client book at ~$15,000 average ACV ⇒ $2.25M–$4.5M ARR without leaving the wedge vertical. Ranges are constructed estimates. Inferred

Rubric Scorecard (Six Gates)

GateScoreReasoning
1. Low trust burden5/5Accessibility audits are routinely outsourced today (Level Access, Deque, boutique auditors); buyers already grant read access to staging sites and CMS/design systems to third-party auditors as standard practice. No novel trust ask.
2. Low task-level judgment4/5Crawl → automated rule scan → AI classification/drafting → human AT verification → code fix → re-test is a discrete, repeatable pipeline. Judgment concentrates at two chokepoints: does a page genuinely pass for a screen-reader/keyboard user (not just an automated-checker "pass"), and does a proposed code fix introduce a functional regression.
3. High intelligence threshold4/5Correctly diagnosing WCAG 2.2 failures requires synthesizing DOM structure, ARIA semantics, visual design intent, and real assistive-technology behavior — a genuinely hard reasoning task where frontier-model-assisted classification plus human AT testing outperforms rule-based scanners, which plateau at 30-40% detection by practitioner consensus.
4. Regulation as moat5/5ADA Title III case law, DOJ's April 2024 Title II rule mandating WCAG 2.1 AA for state/local government sites (compliance deadlines April 2026/2027 by population), Section 508, and the EU's June 2025 European Accessibility Act create overlapping, durable legal exposure that a casual DIY entrant cannot credibly speak to.
5. No physical labor5/5Entirely remote: automated scanning, code review, screen-reader/keyboard testing (can be done remotely against staging URLs), document production, video read-outs.
6. Sam Altman test5/5Better models directly improve DOM/ARIA reasoning, code-fix generation quality, and violation-classification accuracy — the service gets cheaper and more accurate every model generation, while the human AT-verification chokepoint remains necessary and billable regardless of model quality (courts require human-attestable proof, not an AI's self-certification).

Target Buyer

Jobs-to-be-Done

Painful Problem

Most mid-market digital properties were built by teams with zero accessibility training, layering years of components, third-party widgets, and redesigns with no one auditing WCAG success-criterion conformance. Serial plaintiffs' firms use automated tools to scan thousands of sites, generate demand letters seeking $10,000–$50,000+, and file suit when ignored; the plaintiffs' bar is disproportionately targeting e-commerce (~70% of 2025 suits) because checkout flows are usability-critical and easy to demonstrate as barriers. Installing an overlay widget — the fastest, cheapest-looking fix — makes the target worse: 22.6% of H1 2025 website suits hit sites that already had one installed, and the widget vendor category leader was FTC-fined for the exact claim that its product resolves this. Verified Internal teams lack WCAG expertise, have no source of truth for what's actually broken versus automated-tool noise, and have no artifact to show counsel, customers, or the board that the risk is being actively managed.

The Outcome We Sell

"Your digital properties, tested the way a plaintiff's accessibility expert and a real screen-reader user would test them; every WCAG 2.2 AA failure remediated in your actual code, verified with assistive technology, and documented in a signed VPAT/ACR your procurement teams and defense counsel can rely on. Fixed fee. We run everything; your engineers approve every code change; continuous monitoring keeps you conformant after every release."

Deliverables per cycle: Accessibility Conformance Audit (page-by-page WCAG 2.2 AA findings mapped to success criteria, severity-tiered), Remediation Pull Requests (code-level fixes applied to the client's actual repo/CMS, engineer-approved), a signed VPAT 2.5 / Accessibility Conformance Report (ACR), a litigation-defense Evidence File (dated test logs, before/after AT recordings, remediation changelog), and a Continuous Conformance Monitoring subscription that re-tests on every release.

First One-Feature MVP Wedge

ICPMid-market e-commerce/retail brand, $10M–$500M revenue, in-house engineering team, no dedicated accessibility staff
Trigger eventReceived an ADA demand letter or suit; a competitor/peer brand was sued; installed an overlay widget and wants a real second opinion; upcoming enterprise customer procurement requiring a VPAT
PainUnknown number and severity of real WCAG barriers on core purchase/account flows; no code-level fix path; no defensible documentation
One-feature MVPThe Conformance Audit & Fix Sprint: automated + AI-assisted scan of up to 5 core user flows (home → category → PDP → cart → checkout), certified human tester verification with screen reader (NVDA/VoiceOver) and keyboard-only navigation, prioritized findings report, and a first remediation sprint fixing the top-severity blockers directly in the client's codebase
InputSite URL(s), staging/dev environment access or a read-only repo branch, CMS/framework details, prior audit reports if any (including any overlay vendor reports, which we treat as noise to be re-verified)
OutputConformance Audit Report (WCAG 2.2 AA success-criterion mapping, severity tiers, screenshots/AT recordings) + remediation pull request(s) + evidence file + VPAT 2.5 draft
Human chokepointCertified accessibility tester (CPACC/WAS) validates every "fails" and "passes" determination using real assistive technology; senior engineer reviews and approves every code-level remediation PR before merge
Success metric% of critical/serious findings remediated and re-verified within 30 days; VPAT accepted by client's counsel/procurement contact without rework
What's nextContinuous Conformance Monitoring retainer; full-site audit beyond the 5 core flows; mobile app (native iOS/Android) audits; PDF/document remediation; annual VPAT refresh; litigation-support expert-witness coordination (via outside counsel, never by us directly)

Evidence Summary

Claim Table

#ClaimLabel
C18,667 ADA Title III federal suits filed in 2025; 3,117 (36%) were website-accessibility suitsVerified
C25,000+ total digital accessibility lawsuits filed in 2025 incl. state courtsVerified
C3Nearly half of 2025 federal filings targeted repeat defendantsVerified
C4E-commerce/retail ≈ 70% of 2025 digital accessibility suitsVerified
C5FTC fined accessiBe $1M (final order April 2025) for false widget-compliance advertisingVerified
C622.6% of H1 2025 website suits targeted sites with an overlay already installedVerified
C7Automated/AI-only tools detect ~30–40% of WCAG violations; manual AT testing required for the restVerified (practitioner-survey based)
C8European Accessibility Act (EAA) effective June 2025 mandates WCAG 2.1 AA for EU-market digital products/servicesVerified
C9DOJ Title II rule (April 2024) sets WCAG 2.1 AA deadlines of April 2026/2027 for state/local government sitesVerified
C10Legacy consulting runs $50k–$200k+/yr; TestParty (AI-native competitor) markets compressed 2-week remediation at lower costVerified
C11Manual audit pricing norms $100-250/page; VPAT $350-950; document remediation from $7/pageVerified
C12In-house accessibility compliance roles posted at $55k-139k/yrVerified
C13No mainstream provider sells done-for-you manual-audit + code remediation + signed VPAT + monitoring at fixed fee sized for mid-market ($10M-500M revenue) e-commerceInferred (absence of evidence in competitive scan)
C14Serviceable wedge market $40M–$375M/yrInferred (constructed estimate)
C15Total litigation exposure per case (settlement+defense+remediation+monitoring) $55k-270k+Inferred (vendor-compiled range, single-source-heavy)
C16Demand letters typically seek $10,000-$50,000+; most small-business settlements land $5,000-$15,000Verified

Source-Claim Matrix

ClaimLabelSourceTypeDateConf.Used in
C1: 8,667 federal ADA Title III suits 2025; 36% websiteVADA Title III Blog (Seyfarth Shaw) — Federal Filings Fall Slightly to 8,667 in 2025Law-firm trackerFeb 2026High§3,7,14
Website suits bounce back in 2025VADA Title III Blog — Website Filings Bounce Back in 2025Law-firm trackerMar 2026High§3,7,14
C2: 5,000+ total digital accessibility suits; NY/FL geographyVWCAGsafe — ADA Lawsuit Statistics 2025–2026Vendor analysis2026Med-High§3,7,14
C4: e-commerce ~70% of suitsVAccessibility.build — Accessibility Lawsuit Tracker 2026Litigation tracker2026Med-High§3,7,11
C3: repeat defendants ~50% of filingsVADA Title III BlogLaw-firm trackerFeb 2026High§3,7,14
C5: FTC $1M accessiBe fine, April 2025VTestParty — Why 800+ Businesses With AccessiBe Were Still SuedCompany blog citing FTC action2025High§3,11,14,19
C6: 22.6% of H1 2025 suits hit overlay-equipped sitesVCompliapoint — Accessibility Overlays Don't Work: 2025 Lawsuit DataVendor/consultancy analysis2025Med-High§3,11,14,19
C7: overlays ineffective (67%/72% practitioner & disability-community ratings); 30-40% automated detection rateVA11y Collective — Are Accessibility Overlays a Good Investment?Practitioner survey analysis2025Med-High§3,4,7,14,29
NFB statement on overlay interference with screen readersVAcute ADA Compliance — Why Accessibility Overlays Are Not ComplianceConsultancy analysis citing NFB2025Med-High§11,22
C8: European Accessibility Act effective June 2025, WCAG 2.1 AAVGetWCAG — Complete European Accessibility Act Guide 2026Compliance vendor guide2026High§7,14,22
C9: DOJ Title II rule, April 2024; WCAG 2.1 AA deadlines 2026/2027VD2i Technology — Accessibility Testing 2026: WCAG 3.0, ADA DeadlinesIndustry analysis2026High§7,9,14,22
C10: legacy consulting $50k-$200k+/yr; TestParty AI-native 2-week modelVTestParty — Automated WCAG Compliance; TestParty — How Much Does Website Accessibility Cost? 2025Company site / vendor blog2025High§14,19,20,21
C11: audit pricing $100-250/page; VPAT $350-950; doc remediation from $7/pageVDigitalA11Y — Web Accessibility Audit Cost Guide 2026; Accessible.org — PricingVendor pricing pages2025-2026High§14,21
C12: in-house accessibility roles posted $55k-$139kVA11yjobs — Accessibility Compliance Program Manager, Salesforce; ZipRecruiter — Web Accessibility JobsJob board2026High§14,18,20
Digital accessibility software market $0.85B-$1.4B 2025, 6.8-10.25% CAGRIFortune Business Insights; Straits ResearchMarket research (multiple, divergent estimates)2025-2026Med (source divergence)§7,17
Accessibility testing tools market $610M 2025 → $828M 2031ICited within QASkills — AI Accessibility Testing Tools 2026Industry analysis2026Med§7,17
C16: demand letters $10k-$50k+; small-business settlements $5k-$15k; total exposure $55k-$270k+V (ranges) / I (upper total)TestParty — ADA Lawsuit Cost Statistics; Accessible.org — Settlement AmountsVendor-compiled litigation-cost data2025-2026Med-High§11,14,17,20
Fable Series B $25M (2024) — AI-native accessibility-adjacent funding proofVCited within QASkills — AI Accessibility Testing Tools 2026Industry analysis citing funding news2024Med§19,20

Market and Demand Evidence

Three reinforcing demand engines: (1) Litigation volume and recurrence — 8,667 federal filings in 2025 with website suits growing share to 36%, and nearly half hitting repeat defendants, meaning "we already did a scan once" is not a defense and creates durable recurring-service logic (audit is not a one-time purchase). (2) Incumbent-product collapse — the FTC's own enforcement action against the market-leading overlay vendor, combined with the 22.6% overlay-installed-and-still-sued statistic, gives any credible provider a built-in objection-handling narrative ("your current fix is legally recognized evidence against you"). (3) Regulatory stacking — EAA (June 2025), DOJ Title II WCAG 2.1 AA deadlines (2026/2027), and ongoing Title III case law create simultaneous, non-expiring pressure across consumer, government, and EU-market-facing organizations, unlike single-statute niches that can be legislated away.

Active Buyer Conversations

Competitive Landscape

PlayerWhat they sellGap we exploit
accessiBe, UserWay, AudioEye (overlay widgets)JavaScript snippet claiming automated compliance; self-serve, low priceFTC-sanctioned false-advertising precedent; cited as the barrier in 22.6% of H1 2025 suits; we position explicitly against this category
TestPartyAI-native platform: IDE/CI-CD code-fix suggestions, continuous monitoring, "human-first... powered by AI," 2-week managed remediationDeveloper-tool-first motion assumes the buyer's engineering team drives adoption; weaker on litigation-defense documentation, VPAT production, and counsel-facing evidence framing — we lead with the legal-defense artifact, not the dev tool
Level Access, DequeEnterprise manual audits, platform + services, $50k-$200k+/yrPriced and staffed for Fortune 1000; too slow and expensive for mid-market e-commerce; we productize the same manual-audit rigor at 1/5th to 1/10th the price via AI-compressed workflow
Automated scanners (axe DevTools, WAVE, Siteimprove, Lumar)Rule-engine scans developers run themselvesBuyer must operate and interpret; 30-40% detection ceiling; no code execution, no VPAT, no litigation-defense file
Boutique accessibility consultanciesManual audits, sometimes remediation, hourly or project-basedFragmented, hourly-priced, inconsistent SLAs, no productized monitoring subscription or AI-compressed delivery speed
ADA defense law firmsLegal response to demand letters/suits, hourly ratesDo not execute code remediation or produce ongoing conformance evidence; natural referral channel, not a competitor

Competitor and Budget Validation

Budget already exists in four lines the buyer recognizes: in-house compliance headcount ($55k-$139k/yr per role), overlay-widget subscriptions (now a liability line, easy to redirect), legacy consulting ($50k-$200k+/yr), and defense-counsel spend triggered by demand letters ($5k-$270k+ per case). We redirect overlay and a slice of consulting/counsel spend into a fixed-fee outcome that reduces total exposure. Why alternatives are insufficient: overlays are now litigation evidence against the buyer; automated scanners produce dashboards a non-expert cannot act on; enterprise consultancies are priced out of reach for the most-sued segment (mid-market e-commerce). Why we win: we occupy the seam between "cheap and legally dangerous" (overlays) and "thorough but unaffordable" (Level Access/Deque) — the same seam TestParty has already proven is commercially viable, but we differentiate on litigation-defense documentation and counsel-facing evidence rather than a developer-tool-first motion. Why not a clone: no scanned incumbent sells manual AT-verified audit + code-executed remediation + signed VPAT + litigation evidence file as a single fixed-fee bundle explicitly marketed as the anti-overlay, mid-market-priced alternative.

Pricing Evidence and Proposed Pricing

Regulatory and Compliance Considerations

Licensing Boundary

LayerBoundary
AI system mayCrawl and render pages, run automated WCAG rule engines, classify likely violations by success criterion with confidence scores, draft code-level remediation suggestions, draft VPAT/ACR narrative language, monitor for regressions after each release
Certified human testers (CPACC/WAS) mayVerify every AI-flagged violation using real assistive technology (screen readers, keyboard-only navigation, switch access); make the final pass/fail determination per success criterion; sign the VPAT/ACR as the accessibility conformance statement
Senior engineers mayReview and approve every remediation pull request before merge into the client's codebase; verify no functional regression
Licensed attorneys must (client's counsel, never us)Advise on litigation exposure, respond to demand letters, make legal-risk determinations, direct privileged engagements
We must not claimTo provide legal advice, guarantee immunity from suit, or promise "100% ADA compliant" (no such certification legally exists); engagement letters state findings reflect WCAG 2.2 AA conformance as of the test date, not a legal compliance guarantee
Required controlsEngagement disclaimers separating technical findings from legal advice; CPACC/WAS-certified tester sign-off on every conformance determination; audit logs of every test session; versioned evidence files with AT recordings; E&O and cyber insurance
UPL risk assessmentLow: technical auditing, code remediation, and conformance-artifact production is engineering/testing work (same posture as SOC 2 readiness and pen-test firms), not legal practice; findings are described in WCAG success-criterion language, never in "you are/are not liable" language

AI-Native Advantage

AI changes the unit economics of accessibility work, not just its speed: (1) headless-browser crawling plus LLM-assisted DOM/ARIA reasoning collapses the mechanical 60-70% of an audit (rule-based checks, code-pattern detection, screenshot capture) from consultant-days to compute-minutes; (2) LLMs read component code and CMS templates to draft targeted remediation pull requests instead of generic advice, which certified testers then verify and engineers approve — turning "here's what's wrong" into "here's the fix, already written"; (3) VPAT/ACR narrative drafting, per-audience report versions (engineering / legal / procurement), and evidence-file assembly are generated then human-signed; (4) continuous monitoring re-scans on every deployment at near-zero marginal cost, making the recurring conformance subscription — the stickiest deliverable — high margin; (5) every human tester correction (a flagged "pass" that was actually a "fail," or vice versa) feeds a proprietary component-pattern knowledge base that compounds accuracy across clients using similar frameworks (Shopify, Salesforce Commerce Cloud, WordPress/WooCommerce). The customer never operates the AI directly; they receive a certified-tester-signed outcome.

Internal AI Engine Architecture

  1. Intake layer: structured onboarding form (domains, core user flows to test, CMS/framework, staging access or read-only repo branch); completeness checker blocks scheduling until access and flow definitions are sufficient.
  2. Normalization layer: site inventory normalized into a test manifest; user flows encoded as replayable scripts (home → category → PDP → cart → checkout, or client-specific critical paths); component inventory extracted from the codebase.
  3. Retrieval & knowledge layer: WCAG 2.2 success-criterion library, framework-specific component-pattern database (accumulated from prior engagements), case-law/regulatory-deadline tracker, per-client remediation history.
  4. AI workbench layer: headless-browser + automated rule-engine scan fleet (axe-core class rulesets); LLM classification of DOM/ARIA structure against success criteria with confidence scoring; LLM-drafted remediation pull requests; draft VPAT/ACR and report generation.
  5. Deterministic rules layer: hard rules for unambiguous automatable checks (color contrast ratios, missing alt attributes, form-label association, heading-order violations); severity-scoring formula (critical/serious/moderate/minor mapped to WCAG conformance level and user-flow criticality).
  6. Human chokepoint layer: certified tester verifies every AI-flagged "high/critical" finding and every ambiguous case using real assistive technology; senior engineer reviews every remediation PR before merge; lead reviews counsel-facing evidence-file framing.
  7. QA layer: second-pass sampling of low-severity auto-classifications (10% at launch); gold-standard test-page set re-run weekly to detect pipeline drift; red-team check: "what would a plaintiff's accessibility expert find that we missed?"
  8. Delivery layer: templated Conformance Audit Report, remediation PRs delivered via client's Git workflow, signed VPAT 2.5/ACR, evidence-file bundle (hashed, timestamped AT recordings and test logs), executive read-out deck.
  9. Learning loop: every tester correction updates the component-pattern knowledge base, prompts, and deterministic rules; every remediation outcome (verified fixed / broke functionality) feeds the remediation playbook per framework.
  10. Model-portability layer: provider-agnostic prompt/eval harness; classification accuracy evals re-run against a frozen gold test set on each new frontier model release; crawl/capture pipeline independent of any single LLM vendor.

AI-vs-Human Operations Pipeline

AICrawl + render core user flows; run automated WCAG rule-engine scan across full DOM/ARIA tree
AIClassify likely violations by WCAG 2.2 success criterion; confidence-score each finding; draft severity tiers
RulesAuto-confirm unambiguous deterministic failures (contrast ratio, missing alt text, label association)
HUMANCertified tester (CPACC/WAS) verifies high/critical and ambiguous findings using real screen reader + keyboard-only navigation
AIDraft code-level remediation pull requests targeted to the client's actual components/templates
HUMANSenior engineer reviews and approves every PR before merge; verifies no functional regression
AIRe-scan post-merge; generate before/after diff, VPAT/ACR draft, evidence-file bundle
HUMANCertified tester signs the VPAT/ACR conformance statement; lead reviews client/counsel read-out framing
AIContinuous monitoring on every deployment; regression alerts; quarterly refresh cycle

Dynasty Translation Layer

1. Buyer translation

Who pays: the GC or VP Digital/E-commerce of a mid-market retail/e-commerce brand (engineering co-sponsors). Urgent problem: "We got a demand letter (or a peer did) and I don't know if our site would survive real scrutiny." Outcome wanted: verified, code-level fix plus a documented artifact that ends the argument.

2. Service translation

Done-for-you. Customer receives: Conformance Audit Report, executed remediation PRs, signed VPAT/ACR, evidence file, exec read-out, continuous monitoring. Automation handles crawling/scanning/classification/PR-drafting/monitoring. Humans handle AT verification, code-review approval, and counsel-facing framing.

3. Workflow translation

Intake → test manifest approved → automated scan run → AI classification → certified-tester AT verification → remediation PR drafted → engineer review/merge → re-scan verification → VPAT/ACR signed → evidence file sealed → monitoring begins → quarterly refresh → renewal review.

4. Tooling translation

Day one: Playwright for crawl/capture, axe-core ruleset integration, frontier LLM API for classification/PR-drafting, screen-reader test rigs (NVDA/JAWS/VoiceOver), GitHub/GitLab for PR delivery, Notion/Airtable ops board, PandaDoc engagement letters, Stripe billing. No custom platform required before revenue.

5. Sales translation

Offer page: "22.6% of accessibility lawsuits in 2025 hit sites that already had a compliance widget. Find out what a real audit finds on yours — in 3 weeks, fixed fee, with the code fixed." Outreach: a free automated snapshot of the prospect's own site showing 2-3 real, specific findings.

6. Delivery translation

First 3 clients: founder + certified tester contractor + capture scripts + manual PR drafting review. Automate next: classification triage, PR drafting, report generation, monitoring. Never automate first: AT verification judgment, code-merge approval, counsel-facing framing.

7. Expansion translation

Playbooks per vertical (e-commerce → banking/credit union → healthcare patient portals → higher-ed/government Title II); native mobile app (iOS/Android) audit module; PDF/document remediation line; eventually a law-firm white-label/referral program.

Anti-Duplication Analysis

Anti-Commoditization Analysis

Automated scanning will keep commoditizing — assume every CMS platform bundles a basic AI accessibility checker by 2027 (some already do). Defensibility lives in what pure scanners structurally cannot ship: (1) certified human AT verification — real screen-reader and keyboard-only testing that courts and DOJ guidance treat as the credible standard, which no automated tool can claim without repeating accessiBe's FTC problem; (2) code-executed remediation inside the client's actual repo with engineer sign-off — an accountability act, not a report; (3) signed VPAT/ACR — a formal conformance statement with a named certified professional's attestation, which carries evidentiary weight a self-generated scanner report does not; (4) litigation-defense evidence discipline — hashed, dated, AT-recording-backed files built for a courtroom, not a dashboard; (5) recurring conformance monitoring embedded in the client's release process, becoming part of their compliance calendar. If AI makes scanning free, the market response is more (correctly) anxious buyers who cannot tell noise from real risk — concentrating willingness to pay on verification, execution, and attestation, exactly our layers.

Service Delivery Workflow

  1. Sale closes → engagement letter (WCAG conformance findings, not legal-advice framing) → intake form.
  2. Test manifest approved by client (domains, core flows, staging access/repo branch).
  3. Automated scan + crawl run (1-2 days).
  4. AI classification + severity tiering (same day).
  5. Certified-tester AT verification of high/critical and ambiguous findings (accessibility engineer, 6-10 hrs).
  6. Draft report generated → lead review → delivery + 60-min read-out (week 2).
  7. Remediation sprint: AI-drafted PRs, engineer review/merge with client dev team, verification re-scan, before/after diffs.
  8. VPAT/ACR signed by certified tester; evidence file sealed (hashed, timestamped).
  9. Monitoring cadence begins; quarterly refresh repeats steps 3-8 at reduced scope.
  10. Renewal review with conformance-trend narrative and any new regulatory-deadline updates.

Operations as Product

No-Holes Quality Engine

What the Human Expert Actually Does

TaskLicenseMin/unit launchMin/unit day-90Automation pathQuality riskCannot automateAudit trail
AT verification of high/critical findings (screen reader + keyboard)None (CPACC/WAS certification preferred)270150Confidence-gated review; component-pattern knowledge base growthFalse negative = missed litigation exposure; false positive erodes trustReal assistive-technology usability judgmentAT recording + finding log per issue
Ambiguous/novel-component determinationsNone (CPACC/WAS)9045Pattern library narrows novel cases over timeHighFinal call on edge-case conformanceDecision memo per component
VPAT/ACR sign-offNone (named certified professional attestation)4525Templated narrative; human confirms accuracyOverclaiming conformance is a legal/reputational riskAttestation itselfSigned, versioned VPAT copy
Remediation PR review & merge approvalNone (senior engineer)200100AI-drafted PRs; engineer approves/editsBreaking client functionalityProduction-merge approvalGit PR review log + re-scan diff
Client read-out & engineering-team negotiationNone9060Deck auto-generated; call stays humanRelationship/trustTrust interface with client teamCall notes in CRM
Evidence-file sealing & QANone4515Fully scriptableLowHash manifest

Launch: ~12-13 expert hours per full audit+remediation cycle. Day-90 target: ~6.5 hours. Year-1 target: ~4.5 hours.

Minimum Viable Offer

The Conformance Audit & Fix Sprint — $12,000 fixed, 3 weeks. We test your five most critical user flows the way a plaintiff's accessibility expert and a real screen-reader user would test them, fix the highest-severity code-level barriers directly in your repo, and deliver a signed VPAT plus a dated evidence file your counsel and procurement partners can rely on. Includes a 60-minute read-out with engineering, digital, and legal at the same table.

Fulfillment Process

See §30. First-3-clients mode: founder + certified-tester contractor perform steps 3-6 with scripts + manual review (~28-32 hours each); templates harden after each delivery. Capacity math at maturity: one certified tester + one engineer pair supports ~10-12 audit-and-fix cycles/month plus a growing monitoring book; scan/classification fleet scales horizontally with compute only.

Tools and Systems

Human-in-the-Loop Quality Control

Two mandatory chokepoints (AT verification of high/critical findings; remediation-PR merge approval) and one conditional (counsel-facing evidence-file framing review). Confidence-scored AI output routes: below 0.7 auto-escalate, 0.7-0.9 sampled, above 0.9 spot-checked. All chokepoint decisions logged with reviewer identity and credential — the audit trail is itself a sales asset (we practice the evidentiary discipline we sell).

Nonlinear Scaling and Unit Economics

MetricTarget
Revenue per FTE$400k-$550k by month 18
Gross margin50-58% at launch → 70-75% at maturity
COGS per $12,000 audit+fix sprint (launch)≈ $5,100: certified-tester labor ~$2,300 (13 hrs blended $175), engineer PR-review labor ~$1,000, scan compute $80-150, LLM inference $40-100, tooling/hosting amortized $200, QA sampling $300, PM/support $500, insurance/compliance allocation $350, sales-support materials $270
COGS per unit (day-90 / yr-1)≈ $3,200 / ≈ $2,400 (tester hours fall to 6.5 → 4.5, PR-drafting near-free)
Model cost per unit$40-100 launch → <$30 yr-1 Inferred
Monitoring COGS<$300/mo per client vs $2,000-$3,500/mo price ⇒ 85%+ marginal margin
Automation %Launch ~55% of task-minutes → 90-day ~68% → yr-1 ~82%
Throughput per tester+engineer pair/dayLaunch 0.25 cycles → yr-1 0.55 cycles + monitoring book
Cycle time21 days → 12 days
Rework rate target<8% of reports/PRs require post-delivery correction; <3% yr-1
Quality failure target0 counsel/procurement-rejected VPATs; <2% materially wrong findings
Escalation rate target<18% of auto-classifications escalate by yr-1
CAC payback<60 days (audit fee covers CAC in wedge motion)
Lead-magnet → consult conversionAssume 12-20% of snapshot recipients book (personalized findings) Inferred
Consult → paid auditAssume 25-35% Inferred
Audit → monitoring retainerTarget 55%+ attach
RetentionTarget 80%+ annual retainer retention (compliance-calendar and release-process embedded)
Margin expansion pathMonitoring mix shift + automation of low-severity classification + PR drafting ⇒ blended GM 70-75% as retainer book grows

Distribution Proof Table

ChannelWhy ICP is reachableFirst message/content angleConv. assumptionProof sourceMeasurementFollow-up
Personalized outbound (free snapshot memo)E-commerce/digital VPs named on company sites/LinkedIn; their site is publicly scannable for automated-tier findings"3 accessibility barriers we found on [site] in 10 minutes — and why your overlay didn't catch them"5-9% reply; 12-20% of repliers book IDemand-letter wave and overlay-failure narrative make topic pre-soldReply/booking rate per 100 sendsFull snapshot → consult → audit
ADA defense law firm referralsFirms handle the legal response to demand letters but don't execute code remediation"We're the technical execution bench for your clients' remediation and VPAT needs — referral or white-label"2-5 firm partners yr-1, 1-3 referrals/quarter each IActive ADA defense-bar content programs (Fox Rothschild and peers)Referrals per partnerCo-webinars, shared checklists
E-commerce platform communities (Shopify Plus partner network, BigCommerce, WooCommerce agencies)Agencies build the sites getting sued and want a trusted remediation partner to refer to"Add accessibility remediation to your service stack without hiring a certified tester"3-6 agency partnerships yr-1 IPlatform partner-directory precedent (accessibility apps already listed)Referrals per agency partnerPartner-tier pricing, co-marketing
LinkedIn founder contentICP (GC, VP Digital, VP Engineering) over-indexes on LinkedIn compliance/e-commerce contentOverlay-failure teardowns, ruling explainers, before/after remediation diffsCompounding; 1-2 inbound/mo by day 90 ITestParty's own content-marketing volume proves the ICP consumes this contentFollowers→DM→consult funnel
SEO/AEOBuyers search "ADA demand letter what to do," "accessiBe alternative," "WCAG audit cost," "is my overlay enough"; answer engines cite explainer contentDefinitive guides + free snapshot CTASlow build; 5-10 leads/mo by month 6 ITestParty/DigitalA11Y/Accessible.org content already ranks and drives leads in this nicheOrganic + AI-referral leads
Cyber/E&O insurance broker panelsSome carriers ask about accessibility posture at renewal; parallel to cyber-insurance pattern in prior blueprints"Pre-renewal accessibility attestation package"Exploratory UBroker intros/quarterPanel-vendor application

Sales and Outreach Plan

Founder-led sales for the first 20 clients. Motion: free snapshot memo → 30-min findings call (diagnostic, not demo) → fixed-fee audit+fix proposal same day → audit read-out doubles as monitoring-retainer upsell. Sales collateral: two anonymized before/after remediation teardowns, litigation-cost calculator, one-page "how we work alongside your defense counsel" explainer. Objection playbook: "we already have an overlay" (show the 22.6%-of-suits and FTC-fine data), "our dev team can do this" (show the 30-40% automated-detection ceiling and AT-verification gap), "we use axe DevTools" (show the certified-tester verification and VPAT sign-off gap).

Founder-Led Content Plan

Positioning: the technical and evidentiary translator between the courtroom and the codebase. Cadence: 3 LinkedIn posts/week + 1 long-form piece/week. Pillars: overlay-failure teardowns (real capture evidence of what widgets miss), ruling/settlement explainers in operator language, remediation field notes (what broke, what didn't, framework-specific), WCAG success-criterion myth-busting, quarterly "State of Mid-Market Accessibility" mini-research from anonymized aggregate scan data — a defensible data asset competitors lack.

First 30 Days of Content

10 educational posts

  1. Your accessibility overlay is legal evidence against you. Here's the FTC case that proves it.
  2. 3,117 website-accessibility suits in 2025. Here's exactly what plaintiffs' experts test first.
  3. Anatomy of an ADA demand letter — and the 3 mistakes recipients make in week one.
  4. Automated scanners catch 30-40% of WCAG violations. Here's what the other 60% looks like on a real screen reader.
  5. Nearly half of 2025 ADA suits hit repeat defendants. Why "we fixed it once" doesn't hold up.
  6. The European Accessibility Act is live. If you sell to the EU, here's what changed in June 2025.
  7. DOJ's Title II WCAG 2.1 AA deadline is April 2026 for larger jurisdictions. What that means if you're a vendor to government.
  8. What a VPAT actually proves — and why a self-generated scanner PDF isn't one.
  9. The checkout flow is where 70% of e-commerce accessibility suits start. Here's how to test yours in 10 minutes.
  10. What a plaintiff's accessibility expert sees in your DOM that your automated scanner doesn't.

3 diagnostic teardown formats

  1. Anonymized Conformance Teardown: real screen-reader test recording of a (permissioned/anonymized) e-commerce checkout flow, showing exactly where it breaks.
  2. Before/After Remediation Diff: code-level pull request pre/post fix, with functional demo intact.
  3. Overlay Autopsy: side-by-side of what an installed overlay widget claims to fix vs. what a certified tester still finds broken.

2 lead-magnet angles

  1. Free Accessibility Snapshot: automated public-page scan of the prospect's own domain → 2-page findings memo with 2-3 specific, real issues (the conversion engine).
  2. Accessibility Litigation Readiness Kit: demand-letter response checklist + WCAG 2.2 AA self-assessment worksheet + overlay-vs-remediation comparison one-pager.

1 webinar

"Your Overlay Isn't Protecting You — Here's the Proof" — co-hosted with an ADA defense attorney: 20 min litigation landscape (them), 20 min live AT-testing demo on a volunteer site (us), 20 min Q&A. CTA: free Snapshot.

1 outbound diagnosis template

Subject: What a screen reader found on [Company]'s checkout page

[Name] — we ran a standard accessibility scan on [company domain]'s checkout flow last week (public pages only). Three things a screen-reader user would hit before completing a purchase: [finding 1], [finding 2], [finding 3]. This pattern matches what plaintiffs' experts document in the [comparable] cases we've reviewed. Happy to send the 2-page findings memo — no strings. If it's already handled, the memo is still useful for your file. — [Founder]

Lead Magnet and Waitlist Plan

What the buyer receives before paying: the Accessibility Snapshot — real findings from their own property, produced by the same engine that powers paid audits. Why it creates trust: it is evidence, not marketing; it demonstrates certified-tester-grade capability in one artifact and specifically calls out overlay-widget gaps if one is installed. Pain signal captured: requesting a scan of specific domains self-identifies litigation anxiety and names the properties they worry about. Follow-up: findings call within 48 hours of delivery; nurture sequence keyed to their vertical's recent settlement/lawsuit news. Sales-ready qualification: (a) demand letter received or peer-brand suit in the news, (b) has an overlay widget installed (strong pain signal), (c) digital/engineering owner engaged, (d) $10M+ revenue. Waitlist mechanic for launch: "10 founding brands at $8,500 (charter pricing) — capped." Signups are not PMF; paid audits and retainer attach are the metrics that matter.

Warm GTM Plan

Sequence all Snapshot recipients, webinar attendees, and content engagers into a 6-touch nurture: news-trigger emails ("[Peer Brand] was sued today — your Snapshot flagged the same pattern"), quarterly re-scan offers, and law-firm-introduction offers. Every existing contact of the operator in e-commerce, retail-tech, and digital-agency circles gets a personal note with one relevant finding, not a pitch.

Targeted Outbound Plan

List build: litigation trackers (recently-sued brands' direct competitors first) × Shopify Plus/BigCommerce merchant directories × LinkedIn digital/e-commerce/GC titles. Prioritize: (1) brands in the most-litigious states (NY, FL, Illinois), (2) brands whose public pages our engine already flags with an installed overlay, (3) brands with recent site redesigns (new, unaudited code). 25 personalized memos/week; each contains real findings. This is diagnosis-led outbound — the memo is the product demo.

Answer-Engine / Search Visibility Plan

Own the question space buyers ask ChatGPT/Perplexity/Google: "received ADA demand letter what to do," "is my accessibility overlay enough," "accessiBe alternative," "how much does a WCAG audit cost," "VPAT vs ACR difference." Tactics: definitive long-form guides with original data (our anonymized scan statistics), structured FAQ schema, citations-friendly formatting, attorney co-authored pieces for authority, and a public (redacted) settlement/lawsuit tracker page updated monthly — link-magnet and AEO citation target.

Pilot Design and Early-Demand Trap Mitigation

Charter cohort: cap 8 e-commerce/retail brands at $8,500 (vs $12,000 list) in exchange for reference rights (logo optional), a feedback call after each deliverable, and permission to anonymize findings for research content. Learning objectives: component-pattern knowledge-base coverage, classification error rate, read-out format resonance, engineering-team objection patterns, monitoring-retainer attach willingness. Trap mitigation: charter price still profitable (>35% GM at launch COGS); no custom scopes accepted; "free pilot" explicitly rejected — payment is the demand test.

Early-Access Feedback Flywheel

Build-Before-Scale Checkpoints

7-Day Launch Plan

  1. Day 1-2: entity/insurance quotes (E&O + cyber); engagement-letter template with UPL/no-guarantee disclaimers; scan pipeline MVP on own test sites plus axe-core integration.
  2. Day 3: run full pipeline against 3 public e-commerce sites (public pages only) → 3 teardown drafts.
  3. Day 4: offer page + Snapshot request form live; charter-cohort waitlist CTA.
  4. Day 5: 25 outbound memos to recently-sued brands' direct competitors; 3 ADA-defense law-firm partner emails.
  5. Day 6: first LinkedIn overlay-failure teardown post; webinar co-host outreach.
  6. Day 7: review replies; book findings calls; refine memo template from response data.

30-Day Launch Plan

90-Day Launch Plan

Metrics and KPIs

Risks and Mitigations

Top three: (1) Title III circuit split resolves unfavorably or Congress narrows ADA website applicability — mitigation: multi-statute positioning (Title II government deadlines, Section 508, EAA, state Unruh-style statutes) means the underlying compliance need survives any single-theory setback; monitor quarterly. (2) TestParty or a well-funded competitor moves into litigation-defense documentation — mitigation: build the certified-tester network, component-pattern knowledge base, and law-firm referral relationships as durable assets faster than a developer-tool-first competitor can pivot its GTM motion. (3) UPL or overclaiming-conformance liability — mitigation: strict "WCAG conformance as of test date" framing, never "ADA compliant" or "lawsuit-proof" language, E&O insurance, attorney-reviewed engagement letters.

Exhaustive Risk Register

R1 — ADA Title III website applicability narrowed by courts/Congress (Likelihood: Low-Med · Impact: High)

The "is a website a place of public accommodation" circuit split has persisted for years without full resolution; a narrowing ruling or federal legislation could reduce Title III filing volume. Mitigation: revenue mix shifted toward Title II government deadlines, Section 508 procurement (VPAT demand independent of litigation), and EAA-driven EU-market exposure by month 9-12; the audit and remediation product remains valuable for these independently. Trigger: any circuit-splitting Supreme Court grant of cert → reweight GTM within 30 days.

R2 — Overlay vendors improve product and reduce their own litigation-trigger rate (Med · Med)

If accessiBe/UserWay materially improve underlying accessibility (not just marketing claims), the "overlay is dangerous" objection-handling narrative weakens over time. Mitigation: our value proposition shifts emphasis toward code-level ownership, VPAT attestation, and continuous monitoring rather than solely "overlays are bad" messaging; monitor overlay vendor product changes quarterly.

R3 — TestParty or Level Access launches a competing litigation-defense-documentation product (High · Med)

Natural expansion for either. Mitigation: certified-tester network, framework-specific knowledge base, and law-firm referral relationships are hard to replicate quickly; position as their partner/referral bench before competing head-on with either.

R4 — Overclaiming-conformance liability / false-advertising exposure for us (Low · High)

Mitigation: never claim "100% ADA compliant" or "lawsuit-proof"; all findings framed as "WCAG 2.2 AA conformance as of test date"; engagement letters reviewed by outside counsel; E&O insurance; explicit disclaimer that no legal guarantee exists (learned directly from the accessiBe FTC precedent).

R5 — Missed violation after we delivered a "conformant" report (Med · High)

Reputation-critical, parallel to the tracking-tech blueprint's "missed tracker" risk. Mitigation: scope language ("point-in-time, enumerated flows"), continuous monitoring upsell, red-team pass before delivery, gold-set regression testing, insurance.

R6 — Client engineering team won't grant repo/staging access (Med · Med)

Mitigation: read-only branch access options, screen-share-applied changes with client engineer pairing, or ticket handoff with verification re-scan; the audit product works even without code access (findings-only tier).

R7 — Remediation PR breaks client functionality (Med · High)

Mitigation: senior engineer review mandatory before every merge; staging-environment testing required; rollback plan documented; functional regression test suite run post-merge.

R8 — Framework fragmentation limits knowledge-base reuse (Med · Med)

Every CMS/framework combination is somewhat different, capping automation leverage. Mitigation: focus wedge on 2-3 dominant e-commerce platforms (Shopify Plus, WooCommerce, Salesforce Commerce Cloud) first; expand framework coverage deliberately, not opportunistically.

R9 — Price compression from offshore/cheap automated-only competitors (High · Med)

$500 "AI accessibility scan" offers will proliferate. Mitigation: we don't sell scans; we sell certified verification + code execution + signed VPAT + evidence file + accountability; publish comparison content explicitly (as TestParty already does against overlays).

R10 — Concentration in e-commerce wedge during a retail-margin squeeze (Med · Med)

Compliance/discretionary budgets tighten in a retail downturn. Mitigation: litigation exposure is board-level and often insurance-linked; price point sits under most approval-committee thresholds; vertical #2 (banking or healthcare) ready by month 6.

R11 — Founder/certified-tester dependency at chokepoints (High · Med)

Mitigation: decision memos + gold examples from engagement #1; hire second certified tester at 60 validation-hours/mo; reviewer certification checklist; cross-train engineers on remediation patterns.

R12 — Certified-tester talent scarcity (Med · Med)

CPACC/WAS-certified professionals are a small labor pool. Mitigation: build a contractor bench early, invest in internal certification pathway for engineers, avoid over-promising capacity before headcount is secured.

R13 — Scan pipeline flagged as hostile traffic / blocked (Low · Low)

Mitigation: client-authorized scans with allowlisted agents; public-page snapshots kept polite (rate-limited, robots-aware) and legally reviewed.

R14 — Data-handling incident on our side (Low · High)

We hold scan/test artifacts describing client vulnerabilities. Mitigation: encrypted storage, access controls, no real end-user PII captured (synthetic test sessions only), SOC 2 roadmap, cyber insurance.

R15 — Serial-plaintiff or "professional tester" ethics concerns affect market perception (Low · Med)

Some ADA Title III litigation is criticized as serial-plaintiff abuse, which could create buyer skepticism toward accessibility vendors generally. Mitigation: position clearly as a defense-side/proactive-compliance service working with the client's counsel, never as a plaintiff-side or enforcement entity; content emphasizes genuine usability outcomes for people with disabilities, not just litigation avoidance.

What Could Kill This

Simultaneous narrowing of ADA Title III website applicability by courts/Congress and failure to convert audit clients into Title II/Section 508/EAA-driven governance retainers before that happens; a well-funded competitor (TestParty, Level Access, or a new entrant) launching true litigation-defense documentation at software prices; or a certified-tester talent bottleneck that caps growth below what demand supports. The kill-switch metric: if by month 6 monitoring-retainer attach is <25% and audit demand is purely demand-letter-reactive with no Title II/EAA/procurement-driven pipeline, the business is a project shop, not an engine — pivot toward the law-firm white-label model or the higher-ed/government Title II vertical.

Go/No-Go Reasoning

Go. Evidence threshold met on every element: identified buyer (e-commerce GC/VP Digital) V; painful specific problem (unverified accessibility barriers under active, growing litigation) V; existing spend (in-house headcount, overlay subscriptions, legacy consulting, defense counsel) V; active demand (8,667 filings, 36% website share, repeat-defendant pattern) V; competitor/budget validation (Level Access, Deque, TestParty, overlay vendors) V; credible win path (service seam between discredited overlays and unaffordable enterprise consulting) I; narrow wedge (Conformance Audit & Fix Sprint) defined; first-sale path (free snapshot outbound) executable week 1; no platform build required; no unresolved fatal blocker (UPL/overclaiming risk mitigable via disclosure discipline learned from the accessiBe precedent); 50%+ GM credible at launch and 70%+ at maturity; believable distribution (law-firm referrals + diagnosis-led outbound + agency partnerships). Honest caveats: competitive whitespace is a 4/5, not 5/5 — TestParty already occupies a credible AI-native position and the win depends on differentiated litigation-defense positioning and certified-tester credibility; and Title III litigation tailwind must be converted into Title II/Section 508/EAA-driven recurring governance revenue within ~12 months to de-risk R1.

Final Recommendation

Launch the Conformance Audit & Fix Sprint for mid-market e-commerce/retail brands immediately: the scan-and-classification pipeline is buildable in days on top of axe-core and a frontier LLM, the lead magnet is the product (a free snapshot of the prospect's own site), buyers are pre-educated by settlement headlines and their own overlay's litigation record, and the first invoice is realistically 2-4 weeks out. Convert every audit into the Full-Site Conformance Program; convert every plaintiff-firm filing surge into outbound; convert every certified-tester correction into the knowledge base. Re-evaluate vertical expansion (banking, healthcare patient portals, higher-ed/government Title II) and the law-firm white-label channel at day 90.

Source List

  1. ADA Title III Blog — Federal Lawsuit Filings Fall Slightly to 8,667 in 2025
  2. ADA Title III Blog — Website Accessibility Lawsuit Filings Bounce Back in 2025
  3. WCAGsafe — ADA Lawsuit Statistics 2025–2026: Data & Trends
  4. Accessibility.build — Accessibility Lawsuit Tracker 2026
  5. Marker Seven — What 2025's Accessibility Lawsuit Numbers Mean for 2026
  6. BeAccessible — ADA Lawsuit Statistics by Year, Industry, and State
  7. TestParty — Why 800+ Businesses With AccessiBe Were Still Sued
  8. TestParty — "I Got Sued with AccessiBe Installed" — What Actually Happened
  9. Compliapoint — Accessibility Overlays Don't Work: The 2025 Lawsuit Data
  10. A11y Collective — Are Accessibility Overlays a Good Investment?
  11. Acute ADA Compliance — Why Accessibility Overlays Are Not Compliance
  12. The Samuel Law Firm — Using an Accessibility Widget? You Risk ADA Litigation
  13. GetWCAG — Complete European Accessibility Act (EAA) Guide 2026
  14. D2i Technology — Accessibility Testing 2026: WCAG 3.0, ADA Deadlines & AI-Driven Compliance
  15. Vervali — WCAG 3.0 Accessibility Testing & Compliance 2026
  16. QASkills — AI Accessibility Testing Tools 2026: Complete Guide
  17. TestParty — Automated WCAG Compliance
  18. TestParty — How Much Does Website Accessibility Cost? 2025 Pricing Guide
  19. TestParty — ADA Lawsuit Cost Statistics: Settlement & Defense Data
  20. TestParty — How Much Does Level Access Cost and Is It Worth It?
  21. DigitalA11Y — Web Accessibility Audit Cost Guide: Detailed Pricing Factors 2026
  22. DigitalA11Y — Digital Accessibility Services Pricing Guide
  23. Accessible.org — Accessibility Services Pricing Page
  24. Accessible.org — ADA Website Compliance Lawsuit Settlement Amounts
  25. Accessible.org — How Much Does a Digital Accessibility Audit Cost?
  26. Compliable — Small Business ADA Compliance Protection
  27. A11yjobs — Accessibility Compliance Program Manager, Salesforce
  28. ZipRecruiter — Web Accessibility Jobs
  29. A11yjobs — Digital Accessibility & Assistive Technology Jobs
  30. Fortune Business Insights — Digital Accessibility Software Market Size
  31. Straits Research — Digital Accessibility Market Size, Share, Growth
  32. Precedence Research — Digital Accessibility Software Market Size
  33. CHEQ — How to Deal with CPRA Data Subject Access Requests (candidate-comparison evidence)
  34. EC-Council — EU AI Act vs NIST AI RMF vs ISO/IEC 42001 (candidate-comparison evidence)
  35. LearnTPRM — AI Vendor Risk Management: Complete TPRM Guide 2026 (candidate-comparison evidence)