From 41388ed0e70dd91458e8db6b0421d5198694365a Mon Sep 17 00:00:00 2001 From: Kisa Date: Mon, 22 Jun 2026 09:55:52 -0400 Subject: [PATCH] docs(shield): update target customer to small healthcare ops + AI SaaS, add Consent Engine delivery options (GitHub template, hosted, hybrid) --- .../specs/2026-06-22-shield-architecture.md | 237 +++++++++++++----- 1 file changed, 170 insertions(+), 67 deletions(-) diff --git a/docs/superpowers/specs/2026-06-22-shield-architecture.md b/docs/superpowers/specs/2026-06-22-shield-architecture.md index a7ebe7b..d052cea 100644 --- a/docs/superpowers/specs/2026-06-22-shield-architecture.md +++ b/docs/superpowers/specs/2026-06-22-shield-architecture.md @@ -9,23 +9,23 @@ ## 1. Product Definition **What Shield is:** -A standalone compliance automation platform for healthcare-adjacent SaaS companies, startups, and small supplier operations. Think "Dash ComplyOps, but simpler and cheaper, with an AI Consent Addendum as the lead-gen engine." +A standalone compliance automation platform for small healthcare operations and SaaS companies that engage with PHI and AI and need compliance — without paying enterprise prices. **What Shield is NOT:** - Not DMEPOS-specific (that's Signal's lane) -- Not a replacement for Vanta/Drata (different tier — Shield targets micro-SaaS) +- Not a replacement for Vanta/Drata (different tier — Shield targets smaller orgs) - Not a consulting service (self-serve compliance tooling) **Target customer:** -- Micro-SaaS companies that need HIPAA/SOC 2 readiness (1-20 employees) -- Healthcare adjacent startups building on top of HIPAA-covered infrastructure -- Small DME suppliers who want compliance basics without Signal (Shield standalone) -- DMEPOS suppliers who want both: Shield + Signal bundle (optional upsell) +- **Small healthcare ops** — clinics, therapy practices, home health agencies, DME suppliers of any type who handle PHI and need HIPAA compliance +- **Healthcare-adjacent SaaS** — startups building AI tools for healthcare, digital health apps, telemedicine platforms, patient communication tools +- **AI companies handling PHI** — any company building AI/ML products that touch protected health information and need to prove compliance to customers +- **Shield + Signal bundle** — DMEPOS suppliers who need both documentation readiness (Signal) and overall compliance (Shield) **Core value proposition:** -"Get compliant in days, not months. Pre-built policies, automated evidence collection, and audit-ready reporting — starting at less than Dash ComplyOps." +"Get HIPAA compliant in days, not months. Pre-built policies, automated evidence collection, audit-ready reporting, and a free open-source AI Consent Engine — starting at less than any competitor." --- @@ -33,17 +33,17 @@ A standalone compliance automation platform for healthcare-adjacent SaaS compani | Competitor | Price | Frameworks | Target | Shield Advantage | |-----------|-------|-----------|--------|-----------------| -| **Vanta** | $10K-$100K+/yr | SOC 2, HIPAA, ISO, PCI | Enterprise | Too expensive for micro | -| **Drata** | $7.5K-$100K+/yr | SOC 2, HIPAA, ISO, PCI | Mid-market | Too expensive for micro | -| **Secureframe** | $7.5K-$80K+/yr | SOC 2, HIPAA, ISO, PCI | Mid-market | Too expensive for micro | -| **Dash ComplyOps** | **$3K/yr flat** | HIPAA, SOC 2, PCI, ISO, NIST | Small teams | **Direct competitor — closest** | -| **Shield** | **TBD (target $1.2K-$2.4K/yr)** | HIPAA-first, SOC 2, expand | **Micro-SaaS** | Cheaper + Consent Addendum hook | +| **Vanta** | $10K-$100K+/yr | SOC 2, HIPAA, ISO, PCI | Enterprise | Overkill for small ops | +| **Drata** | $7.5K-$100K+/yr | SOC 2, HIPAA, ISO, PCI | Mid-market | Overkill for small ops | +| **Secureframe** | $7.5K-$80K+/yr | SOC 2, HIPAA, ISO, PCI | Mid-market | Overkill for small ops | +| **Dash ComplyOps** | **$3K/yr flat** | HIPAA, SOC 2, PCI, ISO, NIST | Small teams | **Direct competitor** | +| **Shield** | **TBD (target $1.2K-$2.4K/yr)** | HIPAA-first, SOC 2, expand | **Small healthcare ops + AI SaaS** | Cheaper + Consent Engine lead magnet | **Differentiation strategy:** - Price under Dash (target $100-200/mo instead of $250) -- AI Consent Addendum is a unique lead-gen asset Dash can't match -- Simpler UI — focused on HIPAA-first workflows +- AI Consent Engine is a unique open-source lead-gen asset no competitor has +- Purpose-built for small healthcare operations and AI companies — not enterprise compliance repackaged - Optional Signal bundle for DMEPOS suppliers who also need documentation readiness --- @@ -61,30 +61,121 @@ A standalone compliance automation platform for healthcare-adjacent SaaS compani | **User Management** | Unlimited users (team collaboration) | Match Dash's offering | | **Framework Support** | HIPAA v1, SOC 2 v2, expand to PCI/ISO | Start narrow, grow | -### AI Consent Addendum (Open-Source Lead Magnet) +### AI Consent Engine (Open-Source Lead Magnet) -**Purpose:** Drive leads to Shield. The addendum is a simple, open-source document generator that creates AI/healthcare consent forms. It showcases STTIL's compliance expertise and includes a subtle "Need the full compliance suite? Check out Shield." CTA. +**What it does:** +An open-source tool that lets any healthcare organization generate HIPAA-compliant AI/healthcare consent forms for their patients or end-users. A client (clinic, SaaS, AI company) takes the Consent Engine, brands it with their logo and custom language, and serves it to their own patients so patients can generate consent documents. -**Implementation:** +**How the client uses it:** -- Standalone single-page app (Vite/React or simple HTML/JS) -- User fills in: company name, AI tool name, data types processed -- Generates a formatted HIPAA-compliant consent document PDF -- No login required for basic use -- "Want automated policy management, evidence collection, and audit prep?" → links to Shield signup -- Hosted at `consent.sttilsolutions.com` or similar +1. Fork or clone the open-source GitHub repo +2. Edit a config file (JSON or YAML) with their logo URL, company name, clinic name, custom consent clauses, and branding colors +3. Deploy via one-click to Vercel/Netlify, or self-host +4. Their patients visit their branded consent page, fill in AI tool name and data types, and receive a formatted HIPAA-compliant consent PDF +5. The footer includes: "Powered by STTIL Shield — Need full compliance? Learn more." -**Why open source:** +**Why open source on GitHub:** -- Builds brand trust and community -- SEO magnet for "AI consent form healthcare HIPAA" searches -- Low friction entry point — user sees STTIL quality before buying Shield +- Builds community trust and brand credibility +- SEO magnet for "AI consent form healthcare HIPAA GitHub" +- Low friction — any developer can try it in 5 minutes +- GitHub stars = social proof for Shield +- PR contributions from the community improve the tool +- Client owns their instance, no data flows through STTIL --- -## 4. Technical Architecture +## 4. Consent Engine — Delivery Options -### Option A: Standalone (Recommended) +### Option A: GitHub Template Repo (User's Suggestion) — RECOMMENDED + +Create a GitHub template repository that clients can use with one click. + +**How it works:** + +1. Client clicks "Use this template" on the GitHub repo +2. Their own copy is created with all the code +3. They edit a single `config.yaml` or `config.json` file: + + ```yaml + organization: + name: "City Family Clinic" + logo_url: "https://clinic.com/logo.png" + primary_color: "#2563eb" + website: "https://clinic.com" + consent: + jurisdiction: "US-HIPAA" + custom_clauses: + - "I consent to my data being used for AI-assisted diagnosis" + - "I understand I can revoke consent at any time" + footer_text: "This consent form is managed by City Family Clinic" + ``` + +4. Deploy button (Vercel/Netlify) — one click to production +5. Client gets a live, branded consent form at `consent.clinic.com` or a Vercel subdomain +6. The form is ready for their patients to use + +**Pros:** + +- True open source — client owns the code and deployment +- Developer-friendly — uses familiar GitHub workflow +- No data flows through STTIL — privacy advantage +- Community contributions via PRs +- Huge SEO value for "HIPAA consent form GitHub" + +**Cons:** + +- Requires some technical ability (fork, edit config, deploy) +- No usage analytics for STTIL (can't track how many consents are generated) +- Client self-manages hosting costs (usually free on Vercel/Netlify free tier) + +### Option B: Hosted Multi-Tenant (SaaS) + +A hosted version at `consent.sttilsolutions.com` where clients log in, upload their logo, customize language through a UI, and get a branded page. + +**How it works:** + +1. Client signs up (no payment needed) +2. Uploads logo, sets colors, writes custom clauses in a WYSIWYG editor +3. Gets a branded URL: `consent.sttilsolutions.com/city-family-clinic` +4. Links their patients to that URL +5. Or embeds via iframe on their own website + +**Pros:** + +- Zero technical skills required +- STTIL controls the full experience +- Can track usage, collect emails, measure conversion to Shield paid +- Can A/B test CTAs and optimize lead generation + +**Cons:** + +- STTIL hosts the service (potential PHI adjacency concerns) +- More operational overhead +- Less open/community feel +- Client doesn't own their instance + +### Option C: Hybrid (Recommended as Final State) + +Start with Option A (GitHub template) for the developer audience and open-source community. Later add Option B (hosted) for non-technical clients who want a simpler setup. + +**Phased rollout:** + +1. **Phase 0a:** GitHub template repo — config-driven, deploy button +2. **Phase 0b (later):** Hosted version at consent.sttilsolutions.com — for clinics without developers +3. Both share the same rendering engine (the GitHub repo is the source of truth) + +**Best of both worlds:** + +- Developers and open-source community get the GitHub experience +- Non-technical clinics get the hosted experience +- The rendering engine is MIT-licensed on GitHub regardless + +--- + +## 5. Technical Architecture + +### Standalone Codebase (Not Signal Module) Build Shield as a new, independent codebase. No shared infrastructure with Signal. @@ -96,88 +187,100 @@ Build Shield as a new, independent codebase. No shared infrastructure with Signa - Auth: Clerk (separate instance or same with org separation) - Hosting: Railway (separate project) + Vercel (separate deployment) -**Pros:** +**Why standalone:** - Clean separation — Signal issues never affect Shield or vice versa - Independent pricing and scaling - Can sell standalone without bundling concerns - Easier to spin out or sell separately later -**Cons:** +### Consent Engine Architecture (GitHub Template) -- More upfront build time -- Separate Supabase project (extra $25/mo for Pro plan) +``` +shield-consent-engine/ +├── README.md # Quick start, config guide +├── config.yaml # THE config file — client edits this +├── template/ # HTML/CSS/JS rendering engine +│ ├── index.html # Main consent form page +│ ├── style.css # Uses CSS variables from config +│ ├── script.js # Form logic, PDF generation +│ └── preview.png # Screenshot for GitHub social +├── CNAME # Custom domain support +├── vercel.json # One-click deploy config +├── netlify.toml # Netlify deploy config +├── LICENSE # MIT license +└── .github/ + └── CONTRIBUTING.md # How to contribute +``` -### Option B: Signal Extension (Not Recommended) +**Key technical decisions:** -Build Shield as a module inside the Signal codebase. - -**Why not:** Already decided Shield is a standalone product. Sharing infrastructure couples two products with different pricing, compliance posture, and target customers. Avoid. - -### AI Consent Addendum Architecture - -- Standalone single-page app, Vite/React -- No backend needed — PDF generation happens client-side (using a library like jsPDF or pdf-lib) -- Hosted on Vercel under a subdomain -- Links to Shield signup — no data collection on the addendum page itself (privacy-friendly) -- Open-source repo under STTIL GitHub org +- Client-side PDF generation only (jsPDF or pdf-lib) — no backend needed +- CSS custom properties driven by config — instant branding +- Zero data storage — forms generate PDF in-browser, nothing is sent to a server +- Deploy preview on every PR via Vercel/Netlify +- GitHub Actions for CI (validate config, build preview) --- -## 5. Pricing Tiers (Suggested) +## 6. Pricing Tiers (Suggested) | Tier | Price (monthly) | Features | Target | |-----|----------------|---------|--------| -| **Free** | $0 | AI Consent Addendum, 1 policy template | Lead gen | -| **Starter** | **$99/mo** | 12 policies, evidence upload, audit reports | Solopreneurs, tiny teams | -| **Growth** | **$199/mo** | Starter + API integrations, risk assessments, unlimited users | Growing startups | -| **Enterprise** | Custom | Growth + dedicated support, custom frameworks, Signal bundle | DMEPOS suppliers | +| **Free** | $0 | AI Consent Engine (GitHub template, self-hosted) | Lead gen, community | +| **Starter** | **$99/mo** | 12 policies, evidence upload, audit reports | Solo practitioners, tiny teams | +| **Growth** | **$199/mo** | Starter + API integrations, risk assessments, unlimited users | Growing healthcare ops, SaaS | +| **Enterprise** | Custom | Growth + dedicated support, custom frameworks, Signal bundle | DMEPOS suppliers, larger orgs | **Rationale:** - Undercut Dash ($250/mo) at both Starter ($99) and Growth ($199) -- Free tier = Consent Addendum (zero cost to STTIL, drives organic traffic) +- Free tier = Consent Engine (zero cost to STTIL, drives organic traffic and SEO) - Signal bundle upsell to $299/mo for suppliers who need both Signal + Shield --- -## 6. Go-to-Market +## 7. Go-to-Market -### Consent Addendum as Growth Engine +### Consent Engine as Growth Engine -1. Developer discovers "AI consent form" via search -2. Uses the free open-source tool → impressed by quality -3. Sees "Need HIPAA compliance for your whole stack? Try Shield." CTA +1. Developer or clinic ops person discovers "HIPAA consent form" via search +2. Finds the open-source GitHub repo — stars, forks, tries it +3. Impressed by quality → sees Shield CTA in the footer 4. Signs up for Shield Starter ($99/mo) -5. Upgrades to Growth when they need audit prep +5. Upgrades to Growth when they need audit prep and evidence collection ### Channels -- **SEO:** "HIPAA compliance for startups," "AI consent form," "SOC 2 for micro-SaaS" -- **Content:** Blog posts comparing Dash vs Shield, "I built HIPAA compliance in a weekend" type content +- **GitHub:** Stars, trending, HN posts about the open-source Consent Engine +- **SEO:** "HIPAA consent form generator," "AI consent template GitHub," "HIPAA compliance for startups" +- **Content:** Blog posts: "How we built an open-source HIPAA consent engine," "Shield vs Dash ComplyOps" - **Signal cross-sell:** When a DMEPOS supplier signs up for Signal, offer Shield bundle -- **Open-source community:** GitHub stars, HN posts about the Consent Addendum +- **Direct outreach:** Small clinics, digital health startups, AI healthcare companies --- -## 7. Build Phases +## 8. Build Phases | Phase | Scope | Est. | |-------|-------|------| -| **Phase 0: Consent Addendum** | Open-source mini-app, client-side PDF gen, hosted on Vercel | 1 session | +| **Phase 0a: Consent Engine GitHub** | Template repo, config-driven, deploy button, MIT license | 1 session | +| **Phase 0b: Consent Engine Hosted** | Multi-tenant hosted version for non-technical users | 1 session (later) | | **Phase 1: Shield MVP** | Policy templates, evidence upload, audit reports, user auth | 3-4 sessions | | **Phase 2: Risk + Integrations** | Risk assessment module, API integrations (AWS, GCP, Railway) | 2-3 sessions | | **Phase 3: Signal Bundle** | Shared dashboard for suppliers using both products | 1 session | --- -## 8. Open Questions (For Kisa) +## 9. Open Questions (For Kisa) -1. **Pricing:** Does $99/$199 feel right? Too low? Too high relative to Dash at $250? +1. **Pricing:** Does $99/$199 feel right for small healthcare ops? Too low/high vs Dash at $250? 2. **Frameworks:** Start with HIPAA-only and add SOC 2 later? Or launch with both? -3. **Consent Addendum name:** "AI Consent Addendum" vs "STTIL Consent Builder" vs something else? -4. **Signal bundle:** A shared login/dashboard, or just a discount code? -5. **Timeline:** Build Consent Addendum first (fast win) or wait for full Shield MVP? +3. **Consent Engine name:** "AI Consent Engine" vs "STTIL Consent Builder" vs "Open Consent"? +4. **Consent Engine approach:** Go with Option A (GitHub template only), Option C (hybrid with hosted later), or something else? +5. **Signal bundle:** A shared login/dashboard, or just a discount code for Shield customers? +6. **Build order:** Consent Engine first (fast win) or Shield MVP first? +7. **PHI concerns with hosted:** If we offer Option B (hosted), does the consent form itself generate PHI? (Patient name + health info in a form = potentially PHI) ---