diff --git a/projects/scirium/04-business-proposal-v2.md b/projects/scirium/04-business-proposal-v2.md index 192e14f..7405ce0 100644 --- a/projects/scirium/04-business-proposal-v2.md +++ b/projects/scirium/04-business-proposal-v2.md @@ -1,6 +1,6 @@ # Scirium Business Proposal v2 (DRAFT FOR REVIEW) -**Product:** Scirium (pronounced "sigh-ree-um") - a white-label, self-hosted AI knowledge assistant for document-driven SMBs +**Product:** Scirium (pronounced "sigh-ree-um") - a white-label, self-hosted AI (artificial intelligence) knowledge assistant for document-driven SMBs **Version:** v2 (assembled from the marketing, technical, financial, and legal remediation sections; supersedes the v1 proposal dated 2026-08-16) **Date:** 2026-08-17 **Status:** DRAFT FOR REVIEW - recommended verdict: **GO with conditions** (churn gate, acquisition-maturation gate, professional trademark clearance, Phase 0 data-loss-prevention (DLP) spike). One-line version: build Scirium against a capacity-constrained ramp at a corrected $167K build, and gate all growth spending on measured pilot-cohort churn at or below roughly 3.5% per month. @@ -11,7 +11,7 @@ Scirium is a white-label, self-hosted knowledge assistant for document-driven SMBs (small and midsize businesses; 10 to 200 employees; MSP (managed service provider) clients, healthcare-adjacent practices, legal, accounting). Every knowledge domain inside a business becomes its own scoped chat channel backed by that business's real documents, served through Rocket.Chat, with grounded, cited answers. The hard invariant is one channel equals one knowledge domain, one attached agent, and one scoped knowledge source, enforced in the schema rather than in prompt text, which is why answers are provably grounded and provably isolated. The never-fabricate rail sits on top: mandatory citations and an explicit "I could not find an answer" fallback when retrieval comes back weak. The beachhead is Wall Orthodontics. -The v1 proposal received a CONDITIONAL GO from internal critical review, with seven flaws and seven conditions. This v2 is the remediation, and it changes the recommendation's reason, not its direction. **v1 said build it because the returns are spectacular. v2 says build it because the returns are good if and only if monthly churn holds at or below roughly 3.5% and the acquisition motion matures off cold-outbound cost within the first year.** v1 rested on two load-bearing fictions: a $1,000 CAC that counted no labor and no failed pilots, and a 12-month revenue ramp that assumed no tenant ever cancels. Both are rebuilt here; the honest numbers still clear the bar, but as a good managed-software business, not the ten-month near-zero-marginal-cost business v1 described. +The v1 proposal received a CONDITIONAL GO from internal critical review, with seven flaws and seven conditions. This v2 is the remediation, and it changes the recommendation's reason, not its direction. **v1 said build it because the returns are spectacular. v2 says build it because the returns are good if and only if monthly churn holds at or below roughly 3.5% and the acquisition motion matures off cold-outbound cost within the first year.** v1 rested on two load-bearing fictions: a $1,000 CAC (customer acquisition cost) that counted no labor and no failed pilots, and a 12-month revenue ramp that assumed no tenant ever cancels. Both are rebuilt here; the honest numbers still clear the bar, but as a good managed-software business, not the ten-month near-zero-marginal-cost business v1 described. What survived review unchanged: marginal cost of about $0.42 to $0.50 per 1,000 queries (immaterial even at a 5x LLM (large language model) price rise); the white-label wedge, re-verified against live vendor sources (no incumbent among Glean, Guru, Notion, Moveworks, and Microsoft Copilot offers white-label branding as a purchasable product; a negative finding from public sources and a go-to-market moat, not a technical one); and gross profit per tenant of about $443 per month, a strong per-unit engine. @@ -20,9 +20,9 @@ What survived review unchanged: marginal cost of about $0.42 to $0.50 per 1,000 The numbers that matter in v2: - Build cost: ~$68K to **~$167K** (1,667 hours incl. contingency; connector re-estimated to a 275-hour midpoint; 360 hours of new v2 work (runtime DLP 90, the Rocket.Chat DLP app 50, three-lane routing 60, ops automation 160)). -- CAC: $1,000 to **$3,088 warm / $6,205 cold / $2,053 mature**. LTV:CAC **4.8:1 warm @3%** (7.2:1 mature, 2.9:1 @5%); the old 14.8:1 headline is the arithmetic artifact of the fictional $1,000 CAC, labeled as such. +- CAC: $1,000 to **$3,088 warm / $6,205 cold / $2,053 mature**. LTV (lifetime value):CAC **4.8:1 warm @3%** (7.2:1 mature, 2.9:1 @5%); the old 14.8:1 headline is the arithmetic artifact of the fictional $1,000 CAC, labeled as such. - Ramp rebuilt **net of churn**; recommended planning case is the new **capacity-constrained scenario**: 26 gross adds, 22.05 tenants @3%, **$72.2K net revenue**, $123.9K year-one CAC spend, operating breakeven crossed in month 6 @3%. The Aggressive 90-tenant case is not executable under the 3.4-wins-per-month sales-capacity ceiling and is struck. -- Opex reconciled to **$5,310/mo** (v1's $4,000 valued product management and admin/insurance at zero). Operating breakeven **12 tenants** steady-state; **26 to 40** cash-neutral while growing. Gross margin is a **band, never a single figure**: 94.4% at the 10-minute support target state, 88.4% at 30-minute stress, ~62-65% at the 1.9 support hours per tenant per month the v1-era ops model implies; support hours are the swing variable and a first-class KPI. +- Opex reconciled to **$5,310/mo** (v1's $4,000 valued product management and admin/insurance at zero). Operating breakeven **12 tenants** steady-state; **26 to 40** cash-neutral while growing. Gross margin is a **band, never a single figure**: 94.4% at the 10-minute support target state, 88.4% at 30-minute stress, ~62-65% at the 1.9 support hours per tenant per month the v1-era ops model implies; support hours are the swing variable and a first-class KPI (key performance indicator). - Payback: **~20 months** build-cost at Realistic @3% (extrapolated estimate), ~18-22 months at the recommended $499 floor, **38-64 months fully loaded** (CAC-dominated, unchanged). The plan adds two validation gates. Gate 1: the beachhead pilot at Wall Orthodontics, strictly internal staff knowledge, no PHI (protected health information). Gate 2 (a commitment): before any ramp figure is treated as a forecast, Scirium must land and fully onboard a second pilot arms-length from the founding relationship with no PHI exposure, in a law firm, accounting firm, or retail group. One friendly pilot proves the software works; it does not prove the product can be sold to a stranger, and the difference between those two claims is the whole business case. @@ -33,7 +33,7 @@ The three conditions the numbers impose: (1) measure real churn in the pilot coh ## 2. Problem & Opportunity -Every organization past a handful of employees has the same failure: new hires take weeks to become useful because institutional knowledge is scattered across SharePoint libraries, PDFs, shared drives, and senior staff memory; repetitive questions interrupt the most expensive people in the building; policy changes never fully propagate, so some staff always operate on a superseded rule. The answer is almost always already written down; it is simply not findable by the person who needs it. Independent studies converge on knowledge workers losing roughly a fifth to a third of the workday to hunting for information that already exists (McKinsey, IDC, and Deloitte estimates are frequently recycled and should be treated as directional, not precise). The cost does not scale down with company size, but the tooling that fixes it does not scale down either. +Every organization past a handful of employees has the same failure: new hires take weeks to become useful because institutional knowledge is scattered across SharePoint libraries, PDFs, shared drives, and senior staff memory; repetitive questions interrupt the most expensive people in the building; policy changes never fully propagate, so some staff always operate on a superseded rule. The answer is almost always already written down; it is simply not findable by the person who needs it. Independent studies converge on knowledge workers losing roughly a fifth to a third of the workday to hunting for information that already exists (McKinsey, IDC (International Data Corporation), and Deloitte estimates are frequently recycled and should be treated as directional, not precise). The cost does not scale down with company size, but the tooling that fixes it does not scale down either. Why every current answer fails: asking a manager interrupts the highest-paid person and does not scale; manual search costs 10 to 20 minutes per hunt with poor recall; printed binders go stale immediately; public consumer LLMs have no access to internal documents, fabricate confidently, and staff paste confidential text into a third-party service; and enterprise knowledge AI works only at enterprise price and enterprise procurement. The incumbents are not failing to serve small firms by accident; their cost structure makes small deals irrational for them. Glean is reported at roughly $50 to $75 per user per month with minimums commonly near 100 seats, a floor near $60,000 per year (third-party; Glean does not publish list pricing). Microsoft 365 Copilot is $30 per user per month on an annual commitment on top of a required base license, or $23.50 in an SMB bundle (vendor-confirmed): the buyer pays per seat, forever, to Microsoft. Guru no longer publishes a per-seat price at all (vendor-confirmed). And nobody sells the brand: even where an incumbent will take a smaller deal, the customer ends up using a product with someone else's name on it, which removes the reason an MSP would ever champion it. @@ -43,15 +43,15 @@ The buyer is not buying "AI." The buyer is buying the removal of four line items ## 3. Product Overview -Scirium is a white-label, self-hosted internal staff knowledge assistant. Every knowledge domain inside a business (employee handbook, billing, IT help, front office, policies) becomes its own scoped chat channel backed by that business's real documents. The product model references no industry; the same core serves a 12-person dental practice and a 200-person law firm. +Scirium is a white-label, self-hosted internal staff knowledge assistant. Every knowledge domain inside a business (employee handbook, billing, IT (information technology) help, front office, policies) becomes its own scoped chat channel backed by that business's real documents. The product model references no industry; the same core serves a 12-person dental practice and a 200-person law firm. **The core primitive: the hard invariant.** Every channel is exactly three things bound together: one knowledge domain, one attached AI agent (a domain-tuned persona), and one scoped knowledge source (one vector namespace over an allowlisted document set). A channel cannot span two domains, and an agent cannot serve two channels. This is enforced in the schema with unique constraints running in both directions, not in application code. It is the reason answers are provably grounded (only one scope feeds the answer) and provably isolated (a billing question cannot surface a neighboring domain or a neighboring tenant). **The never-fabricate rail.** Two mandatory behaviors, both product-defining: every answer carries inline citation markers and a Sources footer linking each cited document; and empty or below-threshold retrieval returns "I could not find an answer" with no sources. Hallucination is the one risk that kills the product: if Scirium ever states a wrong policy or billing rule confidently, trust collapses. This is why the answer engine ships before any "do" capability. -**What changed in the safety posture.** v1 claimed PHI protection was "enforced at ingestion." That claim was not defensible: ingestion filters inspect documents pulled from SharePoint, but they do not see a staff member typing patient data directly into a chat message, and that path reached the third-party LLM unfiltered. v2 adds runtime PHI/PII detection at two independent enforcement points that fail closed (the chat layer and the orchestrator boundary), described in Section 8.2. The v1 claim that data "never leaves the customer's estate" was also factually wrong for the LLM call; v2 replaces it with an explicit three-lane routing model with stated tradeoffs (Section 8.3). +**What changed in the safety posture.** v1 claimed PHI protection was "enforced at ingestion." That claim was not defensible: ingestion filters inspect documents pulled from SharePoint, but they do not see a staff member typing patient data directly into a chat message, and that path reached the third-party LLM unfiltered. v2 adds runtime PHI/PII (personally identifiable information) detection at two independent enforcement points that fail closed (the chat layer and the orchestrator boundary), described in Section 8.2. The v1 claim that data "never leaves the customer's estate" was also factually wrong for the LLM call; v2 replaces it with an explicit three-lane routing model with stated tradeoffs (Section 8.3). -**Honest scope language.** Scirium is not a HIPAA-compliant system and must never be sold as one. It is an internal staff knowledge tool with defense-in-depth controls that reduce the probability of PHI entering the pipeline; detection is probabilistic, and the product is not offered under a Business Associate Agreement. [to verify with counsel before publication: the exact customer-facing phrasing] +**Honest scope language.** Scirium is not a HIPAA (Health Insurance Portability and Accountability Act)-compliant system and must never be sold as one. It is an internal staff knowledge tool with defense-in-depth controls that reduce the probability of PHI entering the pipeline; detection is probabilistic, and the product is not offered under a Business Associate Agreement. [to verify with counsel before publication: the exact customer-facing phrasing] --- @@ -62,14 +62,14 @@ Scirium is a white-label, self-hosted internal staff knowledge assistant. Every Bottom-up, per-seat, blended at $10 per user per month, deliberately below every enterprise incumbent's verified or reported price: ``` -TAM = ~1.0B global knowledge workers x $10/mo x 12 = ~$120B/year -SAM = 1.0B x ~46% (SMB share of private-sector employment) = ~460M workers +TAM (total addressable market) = ~1.0B global knowledge workers x $10/mo x 12 = ~$120B/year +SAM (serviceable addressable market) = 1.0B x ~46% (SMB share of private-sector employment) = ~460M workers x $10/mo x 12 = ~$55B/year -SOM = $55B x 1% (category winner, 3 to 5 year horizon) = ~$550M/year +SOM (serviceable obtainable market) = $55B x 1% (category winner, 3 to 5 year horizon) = ~$550M/year $55B x 0.1% (year 1 to 2, realistic) = ~$55M/year ``` -US-only cross-check: roughly 100M US knowledge workers, of whom SMBs employ about 46% (US Small Business Administration data), gives a US SMB SAM near $5.5B; a 1% capture is $55M per year. The honest framing: market size is not the risk. Distribution is the risk, which is why Sections 6 and 7 carry the load in this document. +US (United States)-only cross-check: roughly 100M US knowledge workers, of whom SMBs employ about 46% (US Small Business Administration data), gives a US SMB SAM near $5.5B; a 1% capture is $55M per year. The honest framing: market size is not the risk. Distribution is the risk, which is why Sections 6 and 7 carry the load in this document. ### 4.2 The category is real, funded, and consolidating @@ -88,8 +88,8 @@ Replaces the v1 table; two v1 claims that were factually wrong are corrected in | Competitor | Price | Deployment | White-label? | Real gap Scirium exploits | |---|---|---|---|---| -| Glean | ~$50-75/seat, minimums commonly near 100 seats, floor near $60K/yr (third-party) | Glean Hosted (SaaS on GCP) or Customer Hosted, a Glean-operated managed tenant in the customer's AWS/GCP account (vendor-confirmed) | No white-label found; partner material reads "Powered by Glean" | Price and seat floor, plus true self-hosting: Glean's docs state Customer Hosted "is not a traditional self-hosted model," runs only in GCP/AWS | -| Moveworks | Not published; third-party estimates near six figures/yr | ServiceNow platform | No white-label found | IT/HR ticket deflection tied to a ServiceNow estate, not general internal knowledge | +| Glean | ~$50-75/seat, minimums commonly near 100 seats, floor near $60K/yr (third-party) | Glean Hosted (software as a service (SaaS) on Google Cloud Platform (GCP)) or Customer Hosted, a Glean-operated managed tenant in the customer's AWS (Amazon Web Services)/GCP account (vendor-confirmed) | No white-label found; partner material reads "Powered by Glean" | Price and seat floor, plus true self-hosting: Glean's docs state Customer Hosted "is not a traditional self-hosted model," runs only in GCP/AWS | +| Moveworks | Not published; third-party estimates near six figures/yr | ServiceNow platform | No white-label found | IT/HR (human resources) ticket deflection tied to a ServiceNow estate, not general internal knowledge | | Guru | No public per-seat price as of Aug 2026 (vendor-confirmed); third-party trackers cite ~$25/seat, 10-seat min | Vendor cloud only | No white-label found | No self-hosting, no rebrand, no channel-level scope isolation; moving upmarket | | Notion AI | Bundled into Business and Enterprise plans with unlimited Notion AI (vendor-confirmed) | Vendor cloud only | No white-label found | Vendor-cloud-only hosting, no rebrand, no hard per-channel scope isolation. Notion does connect to Microsoft 365 (M365; 4.4) | | Microsoft 365 Copilot | $30/seat/mo add-on, annual commitment; SMB bundle $23.50 (vendor-confirmed) | Microsoft cloud only | No white-label found; Copilot Studio permits name/icon changes but runs on Microsoft infra | Per-seat cost forever, Microsoft-cloud lock-in, no rebrandable resale, no self-hosting | @@ -110,7 +110,7 @@ For document-driven small and mid-sized organizations in compliance-sensitive wo The four differentiators, in order of durability. **1. White-label, as a purchasable product.** Verified in Section 4 as unmatched by any of the five incumbents checked; the wedge and the entire reason the MSP channel can exist. **2. The one-channel-one-agent-one-scope invariant.** Enforced in the schema, not with prompt instructions; competitors do broad permission-aware search across the whole corpus, which is genuinely useful for a 5,000-person enterprise and a liability for a 30-person firm. **3. The never-fabricate rail.** Mandatory citations and the explicit fallback; hallucination risk is an acknowledged limitation of the incumbents too, and Scirium's difference is that the fallback is a hard product behavior rather than a recommended configuration. **4. Economics that permit SMB pricing.** Marginal cost of roughly $0.42 to $0.50 per 1,000 queries against a $199 to $2,000 per month band; real and durable, but a supply-side advantage only. v1's error was treating a cost advantage as if it were a distribution advantage. -**The white-label wedge, re-verified, with honest caveats.** The greenlight condition was to confirm the wedge rather than assume it. Live check across Glean, Guru, Notion, Moveworks, and Microsoft Copilot: **no vendor among the five publishes, documents, or markets a white-label or OEM rebranding program for its knowledge assistant.** Each ships as a named, vendor-branded product; Glean's partner material reads "Powered by Glean," which is co-branding and the opposite of white-label; Copilot Studio permits per-agent name/icon changes and a custom chat canvas, the closest any incumbent gets, but the agent still runs on Microsoft infrastructure with per-seat Microsoft licensing. Two caveats: this is a **negative finding from public sources** - the defensible claim is "no major incumbent offers white-label branding as a purchasable product"; and **the wedge is a go-to-market moat, not a technical one** - any vendor could add a branding layer, but none is likely to restructure per-seat enterprise pricing to make a 20-seat reseller deal worth closing. +**The white-label wedge, re-verified, with honest caveats.** The greenlight condition was to confirm the wedge rather than assume it. Live check across Glean, Guru, Notion, Moveworks, and Microsoft Copilot: **no vendor among the five publishes, documents, or markets a white-label or OEM (original equipment manufacturer) rebranding program for its knowledge assistant.** Each ships as a named, vendor-branded product; Glean's partner material reads "Powered by Glean," which is co-branding and the opposite of white-label; Copilot Studio permits per-agent name/icon changes and a custom chat canvas, the closest any incumbent gets, but the agent still runs on Microsoft infrastructure with per-seat Microsoft licensing. Two caveats: this is a **negative finding from public sources** - the defensible claim is "no major incumbent offers white-label branding as a purchasable product"; and **the wedge is a go-to-market moat, not a technical one** - any vendor could add a branding layer, but none is likely to restructure per-seat enterprise pricing to make a 20-seat reseller deal worth closing. **Where a competitor genuinely beats us**, stated plainly because a proposal that claims no weaknesses gets discounted entirely: breadth of connectors (Glean and Notion connect to dozens of systems; Scirium v1 connects to SharePoint and OneDrive, so a prospect with critical knowledge in Salesforce, Zendesk, or Jira is not our buyer yet); brand safety of the incumbent choice (nobody was ever fired for buying Microsoft); company-wide discovery (if the customer's actual need is "search everything at once," the scope invariant is a constraint they will resent); and roadmap velocity (we will not out-feature Glean; we compete on segment, price, brand ownership, and isolation). @@ -128,7 +128,7 @@ Scirium is a **sales-led motion at an SMB price point**; bottom-up CAC lands at Working backwards from 4 closes per month: 7 pilots (60% pilot-to-paid), 20 qualified discovery calls (35%), 29 booked calls (70%), 115 engaged leads (25%), roughly **950 to 1,000 top-of-funnel touches** (12% engagement). That is the honest headline. The demand is real, but the **supply side binds first** (3.4 wins per month); both constraints have to hold, and v1 satisfied neither. -**Motion A: founder-led direct sales.** Target: 2 of the monthly closes in months 1 through 6, dropping to 1 to 2 as the channel scales; the founder closes the first fifteen to twenty deals personally. Lead sources in priority order: the ITPP managed-services base (highest trust, strictly finite, realistically 5 to 10 closes in total); vertical association and peer networks (bar associations, CPA societies, dental and orthodontic study clubs); targeted outbound to a built list (sequenced email plus phone, with the compliance hook that tests best: "your staff are pasting client documents into ChatGPT"); narrow vertical content; and trigger-based outreach (firms that just posted five or more job openings). Five sales assets are required before outbound opens, including a demo tenant that can show a cited answer and a deliberate "I could not find an answer" response, and an objection-handling sheet opening with the now-correct objection: "we already have Copilot." Cadence: 40 touches per day, 8 discovery calls per week, 5 pilots. +**Motion A: founder-led direct sales.** Target: 2 of the monthly closes in months 1 through 6, dropping to 1 to 2 as the channel scales; the founder closes the first fifteen to twenty deals personally. Lead sources in priority order: the ITPP (IT Pro Partner) managed-services base (highest trust, strictly finite, realistically 5 to 10 closes in total); vertical association and peer networks (bar associations, CPA (certified public accountant) societies, dental and orthodontic study clubs); targeted outbound to a built list (sequenced email plus phone, with the compliance hook that tests best: "your staff are pasting client documents into ChatGPT"); narrow vertical content; and trigger-based outreach (firms that just posted five or more job openings). Five sales assets are required before outbound opens, including a demo tenant that can show a cited answer and a deliberate "I could not find an answer" response, and an objection-handling sheet opening with the now-correct objection: "we already have Copilot." Cadence: 40 touches per day, 8 discovery calls per week, 5 pilots. **Motion B: the MSP and reseller white-label channel.** Target contribution: 2 of 4 monthly closes by month 6, and 3 to 4 by month 12 as partners mature. The pitch takes one sentence: the MSP is asked for an AI offering by its clients and has nothing to sell; reselling Glean or Copilot means putting a vendor's brand in front of a client the MSP has spent years owning; Scirium is the only option checked here that lets the MSP put its own name on a working knowledge assistant. @@ -159,14 +159,14 @@ What is required to start: Gate 1 complete (beachhead pilot live, closed loop pr | Tier | Price | Includes | |---|---|---| | Starter | $199/tenant/mo (up to 10 users, +$15/user beyond) | 1 M365 connector (SharePoint + OneDrive), Rocket.Chat, 50K docs, 1 channel scope set | -| Business | $499/tenant/mo (up to 25 users, +$25/user beyond) | Teams connectors, unlimited channel scoping, SSO (OIDC/SAML), 250K docs, SLA support, monthly DLP report | -| Enterprise | $2,000/tenant/mo (annual contract) | Dedicated instance, unlimited seats, custom connectors, SCIM (System for Cross-domain Identity Management), signed DPA, custom retention, white-glove onboarding, 99.9% SLA | +| Business | $499/tenant/mo (up to 25 users, +$25/user beyond) | Teams connectors, unlimited channel scoping, single sign-on (SSO; OpenID Connect (OIDC)/Security Assertion Markup Language (SAML)), 250K docs, SLA (service-level agreement)-backed support, monthly DLP report | +| Enterprise | $2,000/tenant/mo (annual contract) | Dedicated instance, unlimited seats, custom connectors, SCIM (System for Cross-domain Identity Management), signed DPA (data processing agreement), custom retention, white-glove onboarding, 99.9% SLA | Every tier includes the core grounded Q&A engine, the channel-scoped isolation invariant, citations, audit logs, and the no-PHI guardrail; higher tiers unlock more v2 capabilities and white-glove onboarding, not better core answer quality. The legal and compliance package is advisory-only and available at every tier (Section 10). **Enterprise tier benchmark.** $2,000 per tenant per month is priced against what the incumbents charge for comparable scope: a 100-seat Microsoft 365 Copilot deployment costs about $3,000 per month ($30/seat) on top of required base licenses, and Glean's commonly cited ~100-seat minimum lands near $5,000 to $7,500 per month (Section 4.3). The gap is deliberate: the Enterprise tier funds its own dedicated infrastructure (Section 8.7, Option B), unlimited seats, white-glove onboarding, a signed DPA, and a 99.9% SLA, none of which the lower tiers carry. -**Base case.** The base financial case uses the conservative 60/30/10 tier mix, which blends to **$469.10 per tenant per month** (0.60 x 199 + 0.30 x 499 + 0.10 x 2,000). The v1 practice of modeling a $450 safety haircut is dropped because ARPU is not the fragile assumption; churn and CAC are. All revenue figures in Section 9 use $469.10. +**Base case.** The base financial case uses the conservative 60/30/10 tier mix, which blends to **$469.10 per tenant per month** (0.60 x 199 + 0.30 x 499 + 0.10 x 2,000). The v1 practice of modeling a $450 safety haircut is dropped because ARPU (average revenue per user) is not the fragile assumption; churn and CAC are. All revenue figures in Section 9 use $469.10. **Strategic pricing lever (explicitly not in the base model).** The technical team's cost analysis (Section 8.6) shows that a $199 Starter tier cannot carry the fully-loaded per-tenant cost of a managed self-hosted fleet. Their recommendation is a **strategic lever, labeled as such and kept out of the base model**: retire the $199 Starter tier and enforce a $499 floor. That lifts blended ARPU toward $700 to $800 per tenant per month, raises fully-loaded contribution to roughly **$202 per tenant per month** at the current operations model, and pulls operating breakeven back to **22 to 23 tenants** on the fully-loaded basis (fleet engineering included: ~$202 contribution per tenant per month against $4,500 per month fleet-wide engineering; 15 to 16 once support hours are automated down toward 1.0 per tenant per month). On the COGS (cost of goods sold)/opex basis the steady-state breakeven stays at 12 tenants (Section 9.8); the two bases are deliberately separate. The base case deliberately keeps the conservative $469.10 mix; the $499 floor is the lever a decision-maker can pull if the support-hours KPI does not converge. @@ -178,28 +178,28 @@ Every tier includes the core grounded Q&A engine, the channel-scoped isolation i | Layer | Responsibility | Owns | |---|---|---| -| Rocket.Chat | Chat transport only | One workspace per tenant, MIT `fossify` build with EE stripped; rooms, users, messages; plus the chat-layer DLP app. Zero intelligence | +| Rocket.Chat | Chat transport only | One workspace per tenant, MIT `fossify` build with EE (Enterprise Edition) stripped; rooms, users, messages; plus the chat-layer DLP app. Zero intelligence | | Orchestrator | All intelligence | Multi-tenant FastAPI service: tenancy, agents, kb_scope, M365 connector, retrieval, DLP, LLM routing, posting | | Presidio analyzer/anonymizer | DLP verdicts | Self-hosted, loopback only, no external calls | | Postgres + pgvector | State and vectors | Tenants, channels, agents, scopes, documents, chunks, messages, dlp_events | | admin-ai (LiteLLM) | LLM routing | Lane-aware routing with in-lane fallback chains only | -| Wasabi S3 | Object storage | M365 sync staging, backups, agent assets, audit exports | +| Wasabi S3 (Simple Storage Service) | Object storage | M365 sync staging, backups, agent assets, audit exports | The intelligence never lives in the chat layer. That split is what makes multi-tenancy clean and white-labeling a server-side concern instead of a per-tenant code fork. ### 8.2 Runtime PHI/PII DLP, failing closed -v1's ingestion-only filter caught PHI in documents but missed PHI typed into chat messages, DMs, attachments, or REST-API injections, and retrieved chunks could carry PHI into the prompt. v2 adds two enforcement points that fail closed: chat-layer DLP (pre-persistence) and orchestrator-boundary DLP (pre-LLM). The orchestrator is the only component that talks to the LLM, so it cannot be bypassed. +v1's ingestion-only filter caught PHI in documents but missed PHI typed into chat messages, DMs (direct messages), attachments, or REST (Representational State Transfer) API (application programming interface) injections, and retrieved chunks could carry PHI into the prompt. v2 adds two enforcement points that fail closed: chat-layer DLP (pre-persistence) and orchestrator-boundary DLP (pre-LLM). The orchestrator is the only component that talks to the LLM, so it cannot be bypassed. -**Layer 1: chat-layer DLP (pre-persistence).** A Rocket.Chat Apps-Engine app shipped with each tenant's provisioning bundle implements pre-send hooks (`IPreMessageSentPrevent` to block, `IPreMessageSentModify` to redact, `IPreMessageUpdatedPrevent`, `IPreFileUpload`). It calls the orchestrator DLP endpoint over HTTPS (HMAC-signed) and receives `allow`/`redact`/`block`; block prevents the send, redact rewrites the body before persistence so raw PHI is never written to MongoDB. Layer 1 stops PHI from ever landing in the tenant's chat database. +**Layer 1: chat-layer DLP (pre-persistence).** A Rocket.Chat Apps-Engine app shipped with each tenant's provisioning bundle implements pre-send hooks (`IPreMessageSentPrevent` to block, `IPreMessageSentModify` to redact, `IPreMessageUpdatedPrevent`, `IPreFileUpload`). It calls the orchestrator DLP endpoint over HTTPS (Hypertext Transfer Protocol Secure), HMAC (hash-based message authentication code)-signed, and receives `allow`/`redact`/`block`; block prevents the send, redact rewrites the body before persistence so raw PHI is never written to MongoDB. Layer 1 stops PHI from ever landing in the tenant's chat database. **Layer 2: orchestrator-boundary DLP (pre-LLM).** The orchestrator independently inspects the inbound question, the retrieved chunks, and conversation history immediately before the prompt is built. On BLOCK the LLM call is **not made at all**, a refusal is posted, a `dlp_events` row is written, and the audit record confirms zero tokens were sent. This layer is not optional and not tenant-disableable. -**How it fails closed**: DLP unreachable, timeout, 5xx, or malformed body all deny; an unhandled exception denies (the verdict defaults to `block`, reassigned only on an explicit `allow`); a tenant admin disabling the Rocket.Chat app leaves Layer 2 enforcing with a `dlp_degraded` flag and ITPP alert; DLP failing at startup means the application refuses to start; missing Presidio models fail startup. There is **no fail-open toggle in code**, and a CI test kills the DLP dependency and asserts both layers deny, gating deployment. +**How it fails closed**: DLP unreachable, timeout, 5xx, or malformed body all deny; an unhandled exception denies (the verdict defaults to `block`, reassigned only on an explicit `allow`); a tenant admin disabling the Rocket.Chat app leaves Layer 2 enforcing with a `dlp_degraded` flag and ITPP alert; DLP failing at startup means the application refuses to start; missing Presidio models fail startup. There is **no fail-open toggle in code**, and a CI (continuous integration) test kills the DLP dependency and asserts both layers deny, gating deployment. -**The detection engine.** Microsoft Presidio, Apache-2.0, self-hosted on loopback, three stages: regex and checksum recognizers for structured identifiers (SSN, MRN patterns, member and group numbers, NPI (National Provider Identifier), CPT and ICD-10 codes, account numbers, phone, email, full dates of birth) plus per-tenant patterns; NER recognizers (PERSON, LOCATION, DATE_TIME, US_SSN, MEDICAL_LICENSE); and contextual co-occurrence rules (a name plus DOB, member id, or clinical term is PHI; a name alone is not). BLOCK: SSN, MRN, member id, NPI, account, card, name-plus-clinical-context, full DOB in isolation [to verify with counsel]; REDACT: email, phone, address; ALLOW and log: name alone. An identical guardrail at the admin-ai (LiteLLM) proxy is defense-in-depth only [to verify against the deployed version]. +**The detection engine.** Microsoft Presidio, Apache-2.0, self-hosted on loopback, three stages: regex and checksum recognizers for structured identifiers (SSN (Social Security number), MRN (medical record number) patterns, member and group numbers, NPI (National Provider Identifier), CPT (Current Procedural Terminology) and ICD (International Classification of Diseases)-10 codes, account numbers, phone, email, full dates of birth) plus per-tenant patterns; NER (named entity recognition) recognizers (PERSON, LOCATION, DATE_TIME, US_SSN, MEDICAL_LICENSE); and contextual co-occurrence rules (a name plus DOB (date of birth), member id, or clinical term is PHI; a name alone is not). BLOCK: SSN, MRN, member id, NPI, account, card, name-plus-clinical-context, full DOB in isolation [to verify with counsel]; REDACT: email, phone, address; ALLOW and log: name alone. An identical guardrail at the admin-ai (LiteLLM) proxy is defense-in-depth only [to verify against the deployed version]. -**Honest limitations, stated in the proposal and in the customer contract.** Presidio's own documentation states there is no guarantee it will find all sensitive information. Recall is not 100%; false positives will annoy staff (per-tenant thresholds starting at 0.7 plus an allow-list); a determined insider can obfuscate data through (DLP is a guardrail against accident and habit, not against a motivated malicious insider); detection is English-only at launch [to verify: Spanish]. DLP adds ~300 to 650 ms per query (250 ms Layer 1, 400 ms Layer 2, both deny on expiry); the NER model adds 1.5 to 2.5 GB RAM per analyzer [to verify under load]. `dlp_events` stores entity types (never matched values), counts, confidence, a salted hash, and failure mode; raw values are never written, logged, or sent externally. A monthly DLP report is a Business-tier deliverable. +**Honest limitations, stated in the proposal and in the customer contract.** Presidio's own documentation states there is no guarantee it will find all sensitive information. Recall is not 100%; false positives will annoy staff (per-tenant thresholds starting at 0.7 plus an allow-list); a determined insider can obfuscate data through (DLP is a guardrail against accident and habit, not against a motivated malicious insider); detection is English-only at launch [to verify: Spanish]. DLP adds ~300 to 650 ms per query (250 ms Layer 1, 400 ms Layer 2, both deny on expiry); the NER model adds 1.5 to 2.5 GB RAM (random access memory) per analyzer [to verify under load]. `dlp_events` stores entity types (never matched values), counts, confidence, a salted hash, and failure mode; raw values are never written, logged, or sent externally. A monthly DLP report is a Business-tier deliverable. ### 8.3 Three-lane LLM routing and the data-control promise @@ -209,7 +209,7 @@ The corrected statement that ships: chat, documents, vectors, audit logs, and DL - **Lane A: cost-optimized** (default for non-sensitive tenants). DeepSeek V4 Flash or Pro via admin-ai/LiteLLM, ~$0.42 to $0.50 per 1,000 queries. Third-party processing, possible out-of-jurisdiction storage, no contractual retention or training posture. Sold to non-regulated SMB only; **not sold to** healthcare-adjacent, legal, or accounting tenants (hard sales gate). - **Lane B: compliance-routed** (recommended for regulated-adjacent tenants). Enterprise-contracted hosted model with contractual data controls; reference target Azure OpenAI pinned to a US region (no-training committed, region pinning, modified-abuse-monitoring path removes the 30-day retention window [to verify: eligibility, pricing]). Cost ~$5 to $20 per 1,000 queries [to verify]; at $20, 3,000 queries per month costs $60 against a $499 subscription, so the tier still holds. -- **Lane C: fully on-premise** (open-weight, nothing leaves). Open-weight instruct model served locally with vLLM or llama.cpp on a dedicated GPU host (reference: Hetzner GEX44, RTX 4000 SFF Ada, ~EUR 184 to 234 per month [to verify pricing and VAT]). Fixed infrastructure, not per-token; one host can serve multiple Lane C tenants. The only lane where "data never leaves" is literally true. Tradeoff: below frontier quality on complex reasoning, but much smaller on grounded extractive Q&A; must be demonstrated on prospect documents during the pilot [to verify: Phase 0 evaluation set]. +- **Lane C: fully on-premise** (open-weight, nothing leaves). Open-weight instruct model served locally with vLLM or llama.cpp on a dedicated GPU (graphics processing unit) host (reference: Hetzner GEX44, RTX 4000 SFF (small form factor) Ada, ~EUR 184 to 234 per month [to verify pricing and VAT (value-added tax)]). Fixed infrastructure, not per-token; one host can serve multiple Lane C tenants. The only lane where "data never leaves" is literally true. Tradeoff: below frontier quality on complex reasoning, but much smaller on grounded extractive Q&A; must be demonstrated on prospect documents during the pilot [to verify: Phase 0 evaluation set]. Gating requirements: a Data Processing Addendum with the model vendor (ITPP holds it as controller-side counterparty; no DPA, no Lane B); no-training and no-retention settings evidenced quarterly; regional routing pinned to a named US region or the tenant's jurisdiction (verified by endpoint inspection); and subprocessor disclosure with a right to object. Legal counterpart: the LLM vendor DPA (Section 10.6); contract exhibits update before any vendor or fallback change ships. Payload minimization regardless of lane: sends the question, retrieved chunks, persona, and citation instructions (all post-DLP); never sends tenant identity beyond an opaque id, user identity, email, document paths, URLs, or credentials (citations re-attached locally); sends nothing at all on DLP block. @@ -220,7 +220,7 @@ Isolation, in order of trust: schema-level `tenant_id` with unique constraints o ### 8.5 The M365 connector spike -The v1 estimate of 145 hours ("authenticate, crawl, chunk, index") treated the connector as trivial. The design doc specifies far more: multi-tenant Entra registration with per-tenant admin consent and re-consent; the `Sites.Selected` grant workflow; token management with per-tenant caching and rotation; batched crawling with paging; delta sync with deltaLink persistence, 410 recovery, and delete reconciliation; change-notification subscriptions with a 6-hour renewal cron against a 3-day expiry; 429 throttling discipline; **ACL mapping from SharePoint permissions onto kb_scope** (the genuinely hard part); file format and OCR handling; Graph search fallback with a staleness gate; sync observability; and DLP on the ingestion path with block-and-quarantine. The revised estimate is **250 to 300 hours, with 275 as the planning midpoint**, the riskiest engineering line in the project. A 40-hour timeboxed spike, drawn from the 275, must answer four questions before the full build is committed: does `Sites.Selected` consent work end to end against a real client tenant; does ACL mapping hold for the pilot's actual permission structure; what proportion of real documents parse cleanly and how many need OCR; and what is the real delta-sync throughput and throttling ceiling. The exit criterion is a written go or no-go on the 275-hour figure, with library-level scoping as the documented fallback. +The v1 estimate of 145 hours ("authenticate, crawl, chunk, index") treated the connector as trivial. The design doc specifies far more: multi-tenant Entra registration with per-tenant admin consent and re-consent; the `Sites.Selected` grant workflow; token management with per-tenant caching and rotation; batched crawling with paging; delta sync with deltaLink persistence, 410 recovery, and delete reconciliation; change-notification subscriptions with a 6-hour renewal cron against a 3-day expiry; 429 throttling discipline; **ACL (access control list) mapping from SharePoint permissions onto kb_scope** (the genuinely hard part); file format and OCR (optical character recognition) handling; Graph search fallback with a staleness gate; sync observability; and DLP on the ingestion path with block-and-quarantine. The revised estimate is **250 to 300 hours, with 275 as the planning midpoint**, the riskiest engineering line in the project. A 40-hour timeboxed spike, drawn from the 275, must answer four questions before the full build is committed: does `Sites.Selected` consent work end to end against a real client tenant; does ACL mapping hold for the pilot's actual permission structure; what proportion of real documents parse cleanly and how many need OCR; and what is the real delta-sync throughput and throttling ceiling. The exit criterion is a written go or no-go on the 275-hour figure, with library-level scoping as the documented fallback. ### 8.6 Per-tenant operations model and honest cost @@ -239,7 +239,7 @@ Exactly two standard deployment paths are offered, both fully managed by IT Pro - **Option A - ITPP-INFRA Shared.** Scirium runs on the existing netcup RS 4000/2000 servers alongside IT Pro Partner's own operations, backed by the same Wasabi S3 backup pipeline that powers ITPP production. Lowest cost and fastest start; the standard choice for the multi-tenant fleet and for most SMB tenants. - **Option B - Dedicated.** Dedicated netcup or Hetzner instances with a dedicated S3 bucket, fully managed by ITPP. For tenants that demand physical separation (compliance-sensitive buyers, Enterprise tier, or Lane C GPU hosting) or for the fleet at scale. -Shared responsibility is explicit and identical in both paths: **ITPP manages everything below the application layer** (servers, Docker, TLS, Postgres, backups and restore verification, monitoring, DLP infrastructure); the customer owns their documents and how they use the assistant. +Shared responsibility is explicit and identical in both paths: **ITPP manages everything below the application layer** (servers, Docker, TLS (Transport Layer Security), Postgres, backups and restore verification, monitoring, DLP infrastructure); the customer owns their documents and how they use the assistant. --- @@ -249,7 +249,7 @@ Shared responsibility is explicit and identical in both paths: **ITPP manages ev Every figure in this section traces to one of these assumptions; items marked GUESS are estimates with no empirical basis yet and are the first things a pilot should measure. -| ID | Assumption | Value | Basis | +| ID (identifier) | Assumption | Value | Basis | |---|---|---|---| | A1 | Blended engineering rate, loaded | $100/hr | v1 figure, retained | | A2 | Principal/founder rate, loaded | $150/hr | GUESS. Opportunity cost of principal time on billable MSP work | @@ -266,7 +266,7 @@ Every figure in this section traces to one of these assumptions; items marked GU The financial remediation section originally computed $105,300 (780 rescoped hours at +35% contingency), but that corrected only the M365 connector and missed 360 hours of new v2 work itemized by the technical team. The technical build table is authoritative: 1,235 hours of component work plus 432 hours of contingency at +35% equals **1,667 hours at $100/hr = $166,700, approximately $167K**. The range reflects the M365 connector band (250 to 300 hours) and the contingency band (30% to 40%): **$157K to $176K** (low 1,210 hours at 30% = 1,573 hours = $157,300; high 1,260 hours at 40% = 1,764 hours = $176,400). -Component hours (v1 to v2): M365 connector 145 to 275; ingestion pipeline 70 to 80; RAG retrieval 90 unchanged; multi-tenancy 50 to 60; Rocket.Chat integration 70 unchanged; runtime DLP 0 to 90; Rocket.Chat DLP app 0 to 50; LLM lane routing 0 to 60; ops automation 0 to 160; auth/SSO 70 unchanged; admin UI 90 to 110; testing and deploy 90 to 120. Subtotal 675 to 1,235; contingency +432; total 1,667. +Component hours (v1 to v2): M365 connector 145 to 275; ingestion pipeline 70 to 80; RAG retrieval 90 unchanged; multi-tenancy 50 to 60; Rocket.Chat integration 70 unchanged; runtime DLP 0 to 90; Rocket.Chat DLP app 0 to 50; LLM lane routing 0 to 60; ops automation 0 to 160; auth/SSO 70 unchanged; admin UI (user interface) 90 to 110; testing and deploy 90 to 120. Subtotal 675 to 1,235; contingency +432; total 1,667. The contingency is justified: it carries ACL mapping against real SharePoint permission structures, DLP false-positive tuning, and the unverified Rocket.Chat Apps-Engine hook behavior under the MIT `fossify` build. The v1 range's $45K low end is struck. Every payback figure uses the $167K figure. @@ -377,13 +377,13 @@ The v1 proposal used the internal codename "Wall-O" as the product's working nam A basic, non-professional clearance search was run: no exact match for "Scirium" was found as an existing registered trademark, company brand, or software product; the **closest phonetic and spelling neighbor is "Cirium,"** an existing, actively operating aviation data and analytics company (part of LexisNexis Risk Solutions / RELX, rebranded from FlightGlobal in 2019) with AI-adjacent offerings; "Scirium" differs from "Cirium" by a single leading "S," close enough that a professional would want to assess likelihood-of-confusion risk, particularly in the software/data-services classes. One incidental mention of "SCirium" appeared in an academic paper on blockchain-based air traffic management, unclear whether entity, codename, or typo. No conflicting software company, SaaS product, or enterprise-AI brand named "Scirium" was identified. -**Honest statement of residual risk.** This search is not a clearance opinion: it does not check USPTO TESS or equivalent registries, state registries, common-law use in commerce, domain and social-handle conflicts, or the goods/services classes that determine likelihood of confusion. Scirium is materially lower-risk than the retired codename was, but the proximity to Cirium, an existing, active, well-funded brand in an adjacent data/analytics space, is a real finding that should not be waved away; the risk is plausibly low but not zero, and it has not been professionally assessed. **Recommendation: obtain a professional trademark clearance search and opinion from qualified counsel before (1) filing any trademark application for Scirium, (2) executing any reseller, franchise, or white-label agreement that extends brand rights to third parties, or (3) any large-scale paid marketing launch under the Scirium name.** This is a go/no-go gate for irreversible brand commitments, not a blocker for continued internal development, pilot use with the first client, or this proposal's approval. +**Honest statement of residual risk.** This search is not a clearance opinion: it does not check USPTO (U.S. Patent and Trademark Office) TESS (Trademark Electronic Search System) or equivalent registries, state registries, common-law use in commerce, domain and social-handle conflicts, or the goods/services classes that determine likelihood of confusion. Scirium is materially lower-risk than the retired codename was, but the proximity to Cirium, an existing, active, well-funded brand in an adjacent data/analytics space, is a real finding that should not be waved away; the risk is plausibly low but not zero, and it has not been professionally assessed. **Recommendation: obtain a professional trademark clearance search and opinion from qualified counsel before (1) filing any trademark application for Scirium, (2) executing any reseller, franchise, or white-label agreement that extends brand rights to third parties, or (3) any large-scale paid marketing launch under the Scirium name.** This is a go/no-go gate for irreversible brand commitments, not a blocker for continued internal development, pilot use with the first client, or this proposal's approval. ### 10.2 Advisory-only posture, available at every tier -The legal and compliance package is **advisory-only** and is offered as guidance and template documentation across all pricing tiers; it is not gated behind the Enterprise tier, and no tier is sold as "compliant" or "certified" on the strength of a marketing claim. Every tenant receives the same baseline no-PHI acceptable-use policy, the same limitation-of-liability framing, and access to the same DPA template. Enterprise-tier customers additionally receive a signed, negotiated DPA and dedicated-instance options, but the underlying legal posture (no PHI, no BAA, self-hosted control, advisory-only terms) is identical across tiers. +The legal and compliance package is **advisory-only** and is offered as guidance and template documentation across all pricing tiers; it is not gated behind the Enterprise tier, and no tier is sold as "compliant" or "certified" on the strength of a marketing claim. Every tenant receives the same baseline no-PHI acceptable-use policy, the same limitation-of-liability framing, and access to the same DPA template. Enterprise-tier customers additionally receive a signed, negotiated DPA and dedicated-instance options, but the underlying legal posture (no PHI, no BAA (business associate agreement), self-hosted control, advisory-only terms) is identical across tiers. -### 10.3 ToS/MSA (master services agreement) and limitation of liability +### 10.3 ToS (terms of service)/MSA (master services agreement) and limitation of liability Scirium is offered under a ToS/MSA package that is explicitly advisory-only: proposed templates to be reviewed, finalized, and issued by qualified counsel before any customer signs a live agreement. Key terms the finalized ToS/MSA should address: scope of service (self-hosted, white-label, multi-tenant knowledge-assistant chat over customer-provided documents with grounded, cited answers); customer ownership of its documents, chat content, and outputs; explicit exclusion of PHI and other prohibited data categories; SLA terms by tier; term, termination, and data-return/deletion obligations on offboarding; and no unilateral material change to the no-PHI restriction or the DPA without customer notice. @@ -391,7 +391,7 @@ The MSA should include a standard limitation of liability structure, to be final ### 10.4 Acceptable Use Policy: no PHI -The AUP is a hard, contractual restriction, not just a technical guardrail, and it applies at every tier: customers may not ingest, upload, or otherwise introduce into Scirium any Protected Health Information as that term is understood under applicable health-privacy frameworks (patient records, diagnoses, treatment notes, medical record numbers, or similarly sensitive health identifiers), nor any other data category the customer is not permitted to disclose to a third-party processor. The AUP is the legal counterpart to the technical PHI controls: it puts the customer on contractual notice that the product is not designed, warranted, or licensed for PHI use, and that violation is a breach of the agreement independent of whether the technical filter catches every instance. The customer is responsible for configuring which document libraries are connected and for ensuring PHI is excluded before connection. Detected or reported PHI ingestion triggers immediate quarantine, customer notification, and remediation; repeated or willful violation is grounds for suspension or termination. This AUP is what allows Scirium to serve healthcare-adjacent verticals (a dental or orthodontic practice's non-clinical operational content, billing policy, HR and handbook material) without taking on the regulatory posture of a healthcare data processor. +The AUP (acceptable use policy) is a hard, contractual restriction, not just a technical guardrail, and it applies at every tier: customers may not ingest, upload, or otherwise introduce into Scirium any Protected Health Information as that term is understood under applicable health-privacy frameworks (patient records, diagnoses, treatment notes, medical record numbers, or similarly sensitive health identifiers), nor any other data category the customer is not permitted to disclose to a third-party processor. The AUP is the legal counterpart to the technical PHI controls: it puts the customer on contractual notice that the product is not designed, warranted, or licensed for PHI use, and that violation is a breach of the agreement independent of whether the technical filter catches every instance. The customer is responsible for configuring which document libraries are connected and for ensuring PHI is excluded before connection. Detected or reported PHI ingestion triggers immediate quarantine, customer notification, and remediation; repeated or willful violation is grounds for suspension or termination. This AUP is what allows Scirium to serve healthcare-adjacent verticals (a dental or orthodontic practice's non-clinical operational content, billing policy, HR and handbook material) without taking on the regulatory posture of a healthcare data processor. ### 10.5 Data Processing Addendum @@ -407,7 +407,7 @@ Deliberately explicit and not softened in customer-facing material: **Scirium is ### 10.8 Data protection, jurisdiction, and liability summary -Data location is known and disclosed at contracting time per deployment option; the only data flow that leaves the controlled estate is the LLM inference call itself, and the LLM vendor DPA is the mechanism that pins down where that hop occurs and under what retention terms. No claim of specific regulatory certification is made: this proposal does not claim SOC 2, ISO 27001, HIPAA, or GDPR adequacy has been obtained. Indemnity, to be finalized by counsel: Scirium indemnifies the customer against third-party claims that the core, unmodified platform infringes third-party IP, subject to standard exclusions; the customer indemnifies Scirium against claims arising from its own content, its breach of the AUP (in particular PHI ingestion), and misuse of AI-generated outputs; and because the Scirium brand itself is cleared only at the basic-search level, any reseller or white-label agreement executed before a professional trademark opinion is obtained should include a clear allocation of risk and, ideally, a right to rename or rebrand on notice. The operating entity should carry technology E&O and cyber liability coverage sized to the customer base. Because PHI is contractually and technically excluded, the liability and indemnity structure is deliberately not sized for HIPAA breach exposure. +Data location is known and disclosed at contracting time per deployment option; the only data flow that leaves the controlled estate is the LLM inference call itself, and the LLM vendor DPA is the mechanism that pins down where that hop occurs and under what retention terms. No claim of specific regulatory certification is made: this proposal does not claim SOC 2 (System and Organization Controls 2), ISO (International Organization for Standardization) 27001, HIPAA, or GDPR (General Data Protection Regulation) adequacy has been obtained. Indemnity, to be finalized by counsel: Scirium indemnifies the customer against third-party claims that the core, unmodified platform infringes third-party IP (intellectual property), subject to standard exclusions; the customer indemnifies Scirium against claims arising from its own content, its breach of the AUP (in particular PHI ingestion), and misuse of AI-generated outputs; and because the Scirium brand itself is cleared only at the basic-search level, any reseller or white-label agreement executed before a professional trademark opinion is obtained should include a clear allocation of risk and, ideally, a right to rename or rebrand on notice. The operating entity should carry technology E&O and cyber liability coverage sized to the customer base. Because PHI is contractually and technically excluded, the liability and indemnity structure is deliberately not sized for HIPAA breach exposure. --- @@ -419,7 +419,7 @@ The beachhead customer is **Wall Orthodontics**, the orthodontics and dental pra **The execution constraint and the dedicated-hire trigger.** Execution is rate-limited by the same hours that drive CAC: at 40 principal-hours plus 80 technician-hours per month, the ceiling is 3.4 warm wins per month. The plan therefore commits to the capacity-constrained ramp (26 gross adds in year one) as the base case, which requires no additional headcount. The Realistic ramp (48 adds) is explicitly conditional on a **dedicated sales and onboarding hire at roughly $6,000 to $9,000 per month, added to opex**; the trigger is Gate 2 passing (repeatable arms-length onboarding) plus two consecutive months of the Section 6 metrics clearing their thresholds with a pipeline that supports the higher add rate. Until then, signing faster than onboarding capacity is the most likely failure mode of the entire plan, and it is managed by capping monthly signings at proven capacity. -**Success definition.** Product v1 (the answer engine): a Wall Orthodontics staff member asks a policy question in a channel and gets a cited, correct answer, with zero fabricated answers across a week of real use, and the DLP fail-closed test passing before the proof slice is called complete. Business: 3 paying tenants with demonstrated ROI within 6 months of v1 launch, and Gate 2's four pass conditions met before any material sales or marketing spend. Technical: the MIT `fossify` white-label build produced in CI before the first non-pilot customer, no PHI ever ingested, isolation verified by an adversarial test, and automated backup restore verification proven on a scratch host. +**Success definition.** Product v1 (the answer engine): a Wall Orthodontics staff member asks a policy question in a channel and gets a cited, correct answer, with zero fabricated answers across a week of real use, and the DLP fail-closed test passing before the proof slice is called complete. Business: 3 paying tenants with demonstrated ROI (return on investment) within 6 months of v1 launch, and Gate 2's four pass conditions met before any material sales or marketing spend. Technical: the MIT `fossify` white-label build produced in CI before the first non-pilot customer, no PHI ever ingested, isolation verified by an adversarial test, and automated backup restore verification proven on a scratch host. --- @@ -436,12 +436,12 @@ Product v1 is the answer engine plus the safety rails, and nothing else. The mes | Product model and data architecture | Settled, 3 design docs committed | Done | | Data model (tenants, channels, agents, kb_scopes, documents, chunks, messages, users, dlp_events) | Spec'd, not built | Build | | Orchestrator (FastAPI, tenancy, retrieval, LLM client, lane routing) | Not built | Build | -| Postgres + pgvector schema plus RLS | Spec'd, not built | Build | +| Postgres + pgvector schema plus RLS (row-level security) | Spec'd, not built | Build | | Rocket.Chat workspace and bot integration | Phase 0 checklist spec'd, not built | Build | | Rocket.Chat DLP app (Apps-Engine) | New in v2, not spec'd | Build | | Presidio deployment, recognizer tuning, contextual rules | New in v2, not spec'd | Build | | M365 connector (Sites.Selected read) | Spec'd, not built | Build, re-estimated | -| White-label FOSS rebrand (fossify build) | Phase 1 gate, not started | Build | +| White-label FOSS (free and open source software) rebrand (fossify build) | Phase 1 gate, not started | Build | | Auth (Hexclave/Stack Auth, Entra OIDC) | Partially existing on app3 | Integrate | | IaC provisioning and fleet automation | New in v2, not spec'd | Build | | Lane C GPU inference host | New in v2 | Provision when the first Lane C tenant signs | @@ -456,7 +456,7 @@ The rule from Section 8.6: no per-tenant action may be manual, and all fleet aut ### 12.5 v2 risk-tiered capabilities -The v2 roadmap adds risk-tiered "do" capabilities, ordered by write risk, none of which ever unlock patient/PHI scope or autonomous destructive action: reporting (structured extraction, SQL aggregation, chart render; zero new write risk, auto-approved, the recommended first v2 ship); content generation (drafts, summaries, boilerplate; drafts only, with DLP applied to generated output too); housekeeping (move, rename, delete-to-recycle; destructive, propose-then-approve-then-audit, with a mandatory undo path); integrations (Graph delegated sendMail, calendar, webhooks; external side effects, approval required, with DLP inspecting outbound payloads because an integration is a new egress path); and design and brand (template render, image gen; template-driven only, because raw image generation garbles text). Reliable aggregation comes from structured extraction at index time plus a SQL tool, not from better prompting. **Permanently out of scope:** patient records, PHI as a system of record, HIPAA scope, clinical or radiographic image analysis (a separate FDA-regulated product class), and autonomous destructive actions. +The v2 roadmap adds risk-tiered "do" capabilities, ordered by write risk, none of which ever unlock patient/PHI scope or autonomous destructive action: reporting (structured extraction, SQL (Structured Query Language) aggregation, chart render; zero new write risk, auto-approved, the recommended first v2 ship); content generation (drafts, summaries, boilerplate; drafts only, with DLP applied to generated output too); housekeeping (move, rename, delete-to-recycle; destructive, propose-then-approve-then-audit, with a mandatory undo path); integrations (Graph delegated sendMail, calendar, webhooks; external side effects, approval required, with DLP inspecting outbound payloads because an integration is a new egress path); and design and brand (template render, image gen; template-driven only, because raw image generation garbles text). Reliable aggregation comes from structured extraction at index time plus a SQL tool, not from better prompting. **Permanently out of scope:** patient records, PHI as a system of record, HIPAA scope, clinical or radiographic image analysis (a separate FDA (Food and Drug Administration)-regulated product class), and autonomous destructive actions. ### 12.6 Gating items before the first non-pilot customer @@ -493,7 +493,7 @@ The v2 roadmap adds risk-tiered "do" capabilities, ordered by write risk, none o | 2 | M365 connector 145 hrs, no contingency | 275-hr planning midpoint (250-300 range), 40-hr de-risking spike, +35% contingency across all build hours | | 3 | CAC ~$1,000 | **$3,088 warm / $6,205 cold / $2,053 mature target** (CAC payback 7.0 / 14.0 / 4.6 months) | | 4 | LTV:CAC ~14:1 | **4.8:1 warm @3% churn**; 2.9:1 warm @5%; 7.2:1 at mature CAC @3%. The 14.8:1 headline is an arithmetic artifact of the fictional $1,000 CAC, labeled as such | -| 5 | Opex $4,000/mo | **$5,310/mo reconciled** (+32.8%; the gap was PM and admin/insurance valued at zero); annual $63,720 | +| 5 | Opex $4,000/mo | **$5,310/mo reconciled** (+32.8%; the gap was PM (product management) and admin/insurance valued at zero); annual $63,720 | | 6 | Breakeven ~9 tenants | **12 tenants** steady-state; **26 to 40 tenants** cash-neutral while growing | | 7 | 12-month revenue $52.7K / $107.6K / $198.9K (gross bookings, churn excluded) | **Net of churn @3%: $43.7K / $99.3K / $190.3K**; @5%: $41.4K / $94.1K / $180.1K. Recommended planning case: capacity-constrained, $72.2K net @3% with $123.9K year-one CAC spend | | 8 | Full payback ~10-13 months | **~20 months build-cost at Realistic @3% (extrapolated estimate)**; ~18-22 months at the $499 floor; ~29-37 months at v1 pricing; **38 to 64 months fully loaded** (CAC-dominated) | @@ -535,7 +535,7 @@ The v2 roadmap adds risk-tiered "do" capabilities, ordered by write risk, none o ### 15.2 Sources -- This document assembles: the marketing remediation section (market, competitors, positioning, white-label wedge, GTM), the technical remediation section (architecture, DLP, LLM routing, connector, ops, build cost), the financial remediation section (authoritative on revenue and unit economics), and the legal remediation section (trademark, ToS/MSA, AUP, DPA, BAA posture), all dated 2026-08-17; the v1 proposal (2026-08-16, team and product context; any v1 figure superseded by the remediation is replaced per Section 14); and the internal critical review (7 flaws, 7 conditions, CONDITIONAL GO). +- This document assembles: the marketing remediation section (market, competitors, positioning, white-label wedge, GTM (go-to-market)), the technical remediation section (architecture, DLP, LLM routing, connector, ops, build cost), the financial remediation section (authoritative on revenue and unit economics), and the legal remediation section (trademark, ToS/MSA, AUP, DPA, BAA posture), all dated 2026-08-17; the v1 proposal (2026-08-16, team and product context; any v1 figure superseded by the remediation is replaced per Section 14); and the internal critical review (7 flaws, 7 conditions, CONDITIONAL GO). - Vendor-confirmed sources cited in the market section: Notion SharePoint and OneDrive AI Connector documentation and 2.51 release notes; Glean deployment documentation and press releases (Series F, $200M ARR); ServiceNow and Moveworks acquisition announcements; Microsoft 365 Copilot pricing pages; Microsoft Copilot Studio customization documentation; Guru pricing page. - Third-party, directional only: Glean and Guru pricing estimates (GoSearch, Onyx cost calculator, Workativ, Featurebase, Docsie); CAC benchmarks (Factors.ai, Digital Applied, SaaS Mag); US MSP population (Span Global Services).