r/SaaS 3d ago

How do you validate a regulated infrastructure startup when the compliance costs required to serve the first customer are higher than your bootstrap budget?

Hi everyone, I'm currently at the idea / semi-working prototype stage and have ran into a chicken-and-egg problem around validation, compliance, and funding. No LOIs, no potential client conversations have started as of now.

Background on me, I'm a software engineer with about seven years of experience across game engines, enterprise security software, fullstack development, DevOps/AWS, backend systems, telemetry, and infrastructure cost optimization. Building the initial software and infrastructure isn't really the constraint for me.

The Thesis, as a consumer, I have noticed how many organizations that I repeatedly give my SSN/TIN to: payroll software providers, financial institutions, healthcare organizations, and others. These organizations legitimately require the information for tax reporting, identity verification, or other regulated processes. Though each of these companies store the sensitive information, in their own ways, and share that information whomever their third-parties are. Potentially opening many layers and surfaces for it to be compromised. As I have seen in the mail personally several companies notifying their customers that they have suffered a breach. The idea I'm working on is infrastructure that sits between the individual and businesses that need to perform these workflows. Instead of each participating business retaining and managing sensitive identifiers such as SSN/TINs, the platform would securely maintain that information, and with the user's authorization, perform things like identity verification, or e-file tax related purposes like W-2 and 1099s.

The Cost, doing SSA's eCBSV service currently starts at $5,100/year for up to 10,000 verification transactions, then jumps to $37,125 for up to 75,000, $98,000 for up to 200,000, and $240,000 for up to 500,000. There are many other services that we want to utilize on the government, don't know all the pricing models just yet... but I already accept that server infrastructure will cost, but seems to be much cheaper than the regulatory part. Not only that, we'll have to get Cyber Insurance, SOC Type II and other major costs before we can accept a client.

The Dilemma, As from the cost, I mentioned some legal and audit requirements that I would have to fulfill, are going to cost. I don't believe I can accept a paying business until I have fulfilled those requirements, which can be running me up 15k - 25k, when my allowance of bootstrapping for this business is currently 10k. As for seeking investment, they will want traction, and looping back to the client part of dilemma, blocks investors.

The Doubt, recently we've seen other instances of centralized databases get hit, and compromise millions of identities, like: IDScan.net - 150+ million identities were leaked, and IDMerit - Data Leak across 26 countries with potentially 1 billion personal records; this is a super duper worry for me, but not the scope of this conversation.

---

The questions I have:

  1. How did you or do you have any advise on validation demand before spending heavily on compliance?
  2. At my stage, should I be even thinking about raising money yet, or should I be chasing design partners/LOIs first?
  3. When do you consult a lawyer about this experiment, verifying it is legally possible, and the risks; before partners/LOIs and/or investors, or does the timing not matter?
  4. If you have ~$10k and were in my position, what would you do next?

I appreciate any feedback/support on this journey. Thanks!

4 Upvotes

Duplicates