GO
Overall Score
HireVault
1. One-liner
Captures every AI screening decision the moment it happens and keeps it for the four years California demands.
2. Trend signal — why now?
Three things collided in the last twelve months, and the collision is what makes this a business rather than a feature.
The retention duty doubled and grew teeth. The California Civil Rights Council’s employment regulations regarding automated-decision systems took effect 1 October 2025. They extended the employment-records retention period from two years to four, and — this is the part nobody built for — they explicitly pulled a new category into scope: “ADS data – defined as any data used in or resulting from an ADS and/or any data used to develop or customize an ADS.” That covers the screening criteria, the model outputs, and the customization you did to the tool. Not the hiring outcome. The machinery behind it.
The tools that produce that data delete it in 30 days. OpenAI “automatically deletes ChatGPT conversations and API inputs and outputs from its systems within 30 days.” ATS vendors ship configurable auto-delete — “90-day auto-delete for non-fits” is a common default, and GDPR-driven vendor guidance actively pushes employers toward shorter retention. So the employer’s compliance stack is pulling in one direction and their privacy stack in the other, and the AI layer in the middle keeps nothing. As one litigation analysis put it: “the window between trigger of the preservation obligation and irreversible data loss is dangerously narrow.”
The absence of records is now the plaintiff’s best weapon. Courts have held that when an employer destroys hiring-process documents, plaintiffs may be entitled to an adverse inference — the jury is told the missing records would have proved discrimination. Federal Rule 37(e) permits adverse-inference instructions, dismissal, or default judgment. And in May 2025 a federal magistrate in SDNY ordered OpenAI to “preserve and segregate all output log data that would otherwise be deleted” (In re: OpenAI, Inc., No. 25-md-3143), holding that routine data-management practice does not excuse a preservation failure.
Meanwhile the regulation makes testing evidence load-bearing: “evidence, or the lack thereof, of anti-bias testing or other proactive effort to avoid any unlawful discrimination is relevant to any claim or defense.” Lack thereof. The regulation is explicitly telling you that having nothing counts against you.
Money is already moving. iTutorGroup paid $365,000 to settle an EEOC suit after its recruiting software auto-rejected women 55+ and men 60+. SHRM puts median legal cost at $200,000 per discrimination case, excluding settlement. And a bias-audit industry already exists and charges — Holistic AI, BABL AI, Warden AI — proving employers will write cheques in this category.
Provenance:
- Signal 1 (Demand): California Civil Rights Council ADS regulations effective 1 Oct 2025 extend employment record retention to four years and newly define "ADS data" as a retained category, applying to employers regardless of size — https://www.fisherphillips.com/en/news-insights/california-regulators-adopt-new-discrimination-rules-for-automated-decision-systems.html — observed 2026-08-29
- Signal 2 (Feasibility): AI platforms default-delete inputs/outputs within 30 days; SDNY ordered OpenAI to preserve output logs (In re: OpenAI, No. 25-md-3143, 13 May 2025); spoliation now yields adverse-inference instructions in hiring cases — https://www.subjecttoinquiry.com/2026/08/new-frontiers-in-spoliation-preserving-ai-records-in-litigation/ — observed 2026-08-29
- Signal 3 (Economic): A paid third-party bias-audit market already exists (Holistic AI ~1/5 of published reports, BABL AI ~1/6); iTutorGroup settled an EEOC AI-screening claim for $365K; SHRM median discrimination legal cost $200K/case — https://siftfirst.com/compliance/ai-bias-audit-providers — observed 2026-08-29
Category: Regulatory arbitrage
3. The opportunity
The compliance market here has organised itself around the wrong artifact.
Every vendor in the AI-hiring-compliance category sells the audit: an annual statistical bias analysis, a scored report, a public disclosure page. Warden AI, Holistic AI, BABL AI all sell versions of this, driven by NYC Local Law 144’s annual-audit mandate. It’s a good business. It is also a snapshot of the tool, produced once a year, in aggregate, about the model.
California’s ADS rules ask a different question. They ask about the decision — this candidate, this requisition, this date, these criteria, this output — and they ask you to still have it four years later. When a charge lands in month 30, the employer cannot answer with a bias audit. The audit says “the tool scored fairly across groups in aggregate in Q1.” The charge says “you rejected me in March, why?” Those are different artifacts, and only one of them is being sold.
I checked Warden AI’s own product page. The scope is bias auditing and public disclosure reporting: no record retention, no evidence archiving of individual hiring decisions, no decision logging. That’s not an oversight, it’s positioning — they sell to HR-tech vendors as much as employers, and a vendor wants pooled aggregate audits, not per-employer per-candidate archives.
So the gap is structural, not lazy. The audit vendors sell the number. The ATS vendors sell the workflow and are actively engineered to delete (their GDPR story requires it). The AI vendors delete by default in 30 days. Four separate parties each have a good reason not to own the four-year per-decision trail, and the employer — who is the one legally holding the bag, because “the entity making the hiring decision holds ultimate responsibility” — owns it by default and doesn’t know it.
The 10× is not analytical. It’s custodial and it’s about timing. The evidence has to be captured at the moment of the decision, when it’s free, because by the time you need it, it is gone and no amount of money reconstructs it.
4. Target market
Primary customer: The HR lead, People Ops manager, or owner-operator at a California employer with 5–250 employees who has adopted an AI screening or ranking tool in the last 18 months. Titles: Head of People, HR Manager, Director of Talent, or at the small end the COO/founder who also runs hiring. Concentrated in tech, healthcare services, logistics, hospitality, staffing agencies, and professional services.
Why they buy: Not because they want compliance software. Because someone told them — their employment counsel, their EPLI broker, a webinar — that the record duty is now four years and includes the AI’s outputs, and they went to check and discovered their ATS purges non-fits at 90 days and their screening vendor’s API logs are gone in 30. The pain is the realisation, and it arrives via an advisor, which is exactly why this sells through advisors. The honest customer sentence is: “I have no idea what I’d hand a lawyer if someone filed against us for a rejection last spring.”
Rough TAM reasoning: California has on the order of hundreds of thousands of employers in the 5–250 band. SHRM 2026 data puts AI-in-hiring adoption at ~33% for companies under 100 employees and ~35% at 100–499, and 82% of companies using AI in hiring apply it to resume review. So roughly a third of the band is in scope today and the share is climbing. I don’t need a big number: at $200/mo I need ~420 customers for $1M ARR. That’s a rounding error against the eligible pool, which is what makes this comfortable rather than heroic.
Why now for them: The duty started 1 October 2025. The four-year clock means the first records that will actually matter in litigation are being created right now and destroyed on a 30–90 day schedule. Every month of delay is a permanently unrecoverable month. And a second wave is queued — Colorado SB 26-189 (1 Jan 2027, 3-year retention of versions and changelogs), Connecticut’s CART Act (1 Oct 2027), Illinois HB 3773 — so a California-first product has a mapped expansion path rather than a dead end.
5. Product sketch (MVP)
- Capture at the moment of decision — connects to the ATS and the screening/LLM tool and snapshots each screening event: candidate ref, requisition, criteria applied, model output and score, tool name and version, timestamp, and who reviewed it.
- The four-year vault — write-once, tamper-evident storage on a retention clock that ignores the ATS’s purge schedule. Records survive vendor churn, tool switches, and the 30-day API delete.
- Human-review marker — one-click record that a person actually looked at the output before the adverse action, with who and when. This is the single most valuable line in a defence file and nobody is capturing it.
- Pre-use notice log — stores the notice text served to each applicant and the version in force on that date, so “we disclosed” becomes provable rather than asserted.
- Litigation hold — a switch that freezes a requisition, candidate, or date range the instant a charge or demand letter arrives, with an audit log of who set it. Directly answers the Rule 37(e) “reasonable steps” question.
- Defence packet export — select a candidate or a date range and get a dated, indexed PDF-plus-source bundle: criteria, outputs, review markers, notice version, retention chain of custody.
- Adverse-impact snapshot — periodic disparity check across the retained decisions, stored as a dated record, so “proactive effort” has evidence attached. Complements a formal audit, doesn’t pretend to replace it.
- Gap alarm — flags requisitions where AI-assisted decisions were made but no records reached the vault, i.e. where you are silently accruing exposure.
6. AI angle — what’s load-bearing
Two places, both real.
Normalising heterogeneous decision exhaust. Every screening tool emits a different shape — a JSON score, a ranked list, a chat completion, a free-text rationale in a recruiter note. Turning that into a consistent, defensible per-decision record means reading unstructured output and extracting which criteria drove this outcome. That’s an LLM extraction job, and it’s the difference between an archive of blobs and an archive you can answer a charge with.
Drafting the defence narrative. When the packet is pulled, the product assembles a plain-language account of what happened to this candidate on this date under these criteria, cited to the stored records. This is the paralegal work that currently costs billable hours, and it’s the bit that turns a data dump into something counsel can actually use.
Remove the AI and you have a compliance-flavoured S3 bucket — real but weak, and hard to charge $200/mo for. The AI is what makes an unstructured pile into evidence. It is not doing anything decisional: it never scores candidates, never recommends, never touches the hiring outcome. That separation is deliberate, because a compliance product that itself becomes a regulated ADS is a product that sells its customer a new problem.
7. Localization angle (if any)
N/A as a language play — this is US-English. But it is aggressively jurisdiction-localised, and that’s the same wedge by another name. California’s ADS rules (4-year retention, ADS data definition), Colorado SB 26-189 (3-year, versions and changelogs, 30-day adverse-outcome disclosure), Connecticut CART, Illinois HB 3773 and NYC LL 144 all demand overlapping-but-different artifacts on different clocks. A multi-state employer cannot satisfy them with one policy; they need per-state retention rules applied to the same decision stream. Encoding that matrix is the localisation, and it’s the part a generic e-discovery tool will not do.
8. Business model — path to $1M–$5M ARR
- Pricing: three tiers by headcount and hiring volume. $149/mo (5–50 employees), $349/mo (51–150), $699/mo (151–250 or multi-state). Annual billing at ~2 months free. Add-on: $1,500 per litigation-hold defence packet with narrative drafting — priced against the paralegal hours it replaces, and this is the line that spikes when something goes wrong.
- ACV: ~$2,900 blended, assuming mix skews to the middle tier. Rising with multi-state expansion.
- Rough math to $1M ARR: ~345 customers at $2,900 ACV. Against a California pool where a third of 5–250-employee firms already use AI in hiring, that’s a very small share.
- Rough math to $5M ARR: ~1,400 customers, which requires the multi-state build (CO and CT live for their 2027 dates) and a real channel through EPLI brokers and employment-law firms rather than direct-only. Achievable in 24–30 months; I would not promise it in 18.
- Expansion path: headcount tier creep → additional states → defence packets → retention for adjacent ADS uses the same regs cover (promotion, work allocation, discipline), which is where the record duty quietly extends well past hiring.
The margin story is fine. Storage is trivially cheap; the LLM extraction runs once per decision, not per query. The cost driver is support during onboarding, which is why the ATS integrations have to be genuinely one-click.
9. Go-to-market wedge — first 100 customers
The buyer doesn’t wake up wanting this. An advisor tells them. So I sell to the advisor first — and my memory of this pattern is unambiguous: when a market’s demand is advisor-mediated, going direct is the slow road.
- California employment-law firms (the primary channel). There are hundreds of CA-side employment boutiques who have all published a client alert about the ADS regs — Fisher Phillips, Littler, CDF and dozens of smaller shops did exactly this. Every one of those alerts ends with “review your record retention.” None of them can implement it. I approach the 150 firms that published such an alert with a co-branded client resource and a referral arrangement. A firm with 200 employer clients that refers 5% delivers 10 customers. Twelve firms gets me to 100.
- EPLI brokers and PEOs. Employment Practices Liability carriers are already asking harder AI questions at renewal. Brokers want something to offer when the questionnaire exposes a gap. Target the 200 CA-focused EPLI brokers; a broker who mentions it in 30 renewal conversations converts a handful. This channel also gives me the renewal calendar as a natural trigger.
- Reverse-engineer the adopters. AI screening vendors publish customer logos and case studies; ATS marketplaces list which employers run which tools. Scrape CA employers in the 5–250 band who publicly use an AI screening tool, then send a specific message: named tool, its documented retention default, and the four-year duty it doesn’t meet. Not a generic pitch — a factual mismatch about their actual stack. That specificity is what earns replies.
- The SHRM chapter circuit. California has active local SHRM chapters that run monthly programming and are perpetually short of speakers. A 30-minute “what the ADS regs actually require you to keep” talk, delivered to 20 chapters, puts the mismatch in front of exactly the job title that buys, with an implied endorsement.
- Free retention gap check. A form where an HR lead picks their ATS and screening tool and gets a one-page dated assessment of what their stack retains versus what CA requires. Genuinely useful standalone, and it identifies the exposed accounts. I’m deliberately not giving away the vault — my notes are clear that giving away the diagnostic kills the paid number in advisory markets, so this stays a scoped gap check, not a free archive.
10. Build complexity — justification
Medium. The storage, retention-clock, tamper-evidence, and export machinery is standard engineering — nothing here needs research. The AI extraction runs on off-the-shelf models against a well-defined schema. The real work is integrations: Greenhouse, Lever, Ashby, Workable, BambooHR, plus the screening tools, each with its own auth, webhook model, and data shape — and several with retention defaults actively working against you. Call it 14–18 weeks to a v1 covering three ATS integrations and generic API/CSV capture, for two people. The legal-schema design (what exactly constitutes a defensible record per state) needs an employment lawyer’s input, which is a cost line, not a build risk.
11. Gating checklist
| Gate | Pass? | Note |
|---|---|---|
| Legal in target market | ✅ | Retention and evidence tooling; the product helps meet an existing duty. Handles personal data, so DPA and security posture are table stakes. |
| Ethical — no harm / dark patterns | ✅ | Genuinely pro-applicant: preserves exactly the evidence a discriminated-against candidate would need, and never touches the hiring decision. |
| Market exists (evidence above) | ✅ | Paid bias-audit vendors, $365K EEOC settlement, $200K median case cost, ~33% AI-hiring adoption below 100 employees. |
| 1–5 person team can build this | ✅ | Two people, 14–18 weeks, off-the-shelf models and standard storage. |
| Launchable with <$50K / ₹40L | ✅ | Main costs are legal schema review and integration work. Well under $50K. |
All five pass.
12. Feasibility score
| Axis | Weight | Score | Notes |
|---|---|---|---|
| Problem intensity | 20 | 16/20 | Real and expensive — adverse inference plus $200K median defence cost. Docked because it’s latent: the pain is felt on the day a charge lands, not weekly. Latent pain sells slower than bleeding pain, and I won’t pretend otherwise. |
| Demand evidence | 15 | 11/15 | Strong indirect evidence — a funded audit-vendor market, real settlements, a dated statutory duty, measured adoption. Docked because I could not source verbatim employer complaints about this specific retention gap. The market is inferred from the duty, not yet from voices. |
| Build feasibility | 15 | 12/15 | Standard stack; the ATS integration surface is the honest drag. |
| Distribution clarity | 15 | 12/15 | Named channels with countable lists — law firms that published alerts, EPLI brokers, SHRM chapters. Docked because advisor channels are slow to warm even when they’re the right channel. |
| Revenue mechanics | 15 | 11/15 | Pricing is benchmarked and 345 customers to $1M is modest. Docked because willingness-to-pay for insurance-shaped software at the small end is genuinely unproven — the 5–50 band may balk at $149/mo for something that does nothing visible. |
| Time to first revenue | 10 | 8/10 | The gap check plus a law-firm referral can close a paying customer inside 8 weeks; no procurement cycle at this size. |
| Defensibility | 10 | 6/10 | Soft but real: accumulating records create the strongest lock-in there is — you cannot switch away from four years of custody you’d have to abandon. The per-state legal schema compounds. But month 3 is copyable by any competent team. |
| Total | 100 | 76/100 |
13. Qualitative modifiers
Founder-fit tags
technical-heavy · domain-expertise-required
Integration engineering plus genuine employment-law literacy. This needs a lawyer as a co-founder or a well-paid, deeply involved advisor. Building the wrong record schema means shipping a product that fails at the only moment it matters — and you’d never find out until a customer lost a case.
Key assumptions to validate (3–5)
- Assumption: CA employers in the 5–250 band, once shown their actual stack retention versus the four-year duty, treat it as urgent rather than as a someday item. How to test: run the gap check with 40 CA HR leads sourced through two SHRM chapters; measure how many ask “how do I fix this” unprompted versus nod and move on. That ratio is the whole business.
- Assumption: employment-law firms will refer rather than build a manual service or ignore it. How to test: pitch 15 CA employment boutiques that published an ADS client alert; look for 3+ signing a referral arrangement inside 4 weeks.
- Assumption: $149–699/mo clears for insurance-shaped software at this size. How to test: take pre-orders at real prices during validation. Stated interest is worthless here; a card is the only signal.
- Assumption: the major ATS platforms expose enough decision-level data via API to build a defensible record. How to test: build against Greenhouse and Lever sandboxes in week one and confirm criteria and outputs are actually retrievable — not just candidate status.
Risk flags
- Platform dependency: if the major ATS vendors ship native four-year ADS retention, the wedge narrows sharply. Mitigation is multi-tool capture across the whole stack — including screening tools outside the ATS — plus the litigation-hold and packet layer, which ATS vendors have no incentive to build.
- Regulatory risk (in both directions): the ADS regs could be softened, or a court could clarify “reasonable steps” in a way that makes lighter retention adequate. Conversely, the pending No Robo Bosses Act would strengthen the thesis. Asymmetric, and the downside is a real kill scenario.
- Market timing: the duty is live but enforcement is early, and buyers may not move until a visible California employer gets hurt publicly. This is the single most likely reason the product is right but 18 months early.
- Latent-pain sales drag: nobody has a bad day because of this until they have a very bad day. Expect longer cycles than the pricing implies and budget for advisor-led selling from day one.
14. Structured verdict
Score: 76/100
Verdict: GO
Confidence: Medium
Best-fit builder: Technical founder who ships integrations fast, paired with a
California employment lawyer as co-founder or equity advisor
Time to revenue: 8–12 weeks
Capital to launch: $12–18K (legal schema review, integration dev, minimal infra)
Top 3 assumptions to validate first:
1. Urgency is real — run gap checks with 40 CA HR leads via SHRM chapters;
measure unprompted "how do I fix this" rate
2. Advisors will refer — pitch 15 CA employment boutiques that published an ADS
alert; target 3+ referral arrangements in 4 weeks
3. Price clears — take real pre-orders at $149–699/mo, not letters of intent
Kill criteria:
- Abandon if <15% of 40 gap-check recipients ask about remediation unprompted
- Abandon if 0 of 15 employment-law firms will refer after a full pitch cycle
- Abandon if Greenhouse/Lever/Ashby APIs cannot yield decision-level criteria and
outputs, leaving only manual upload — that kills the capture-at-the-moment wedge
- Abandon if two or more major ATS vendors ship native multi-year ADS retention
before v1 launches
15. Next step — 1-week validation sprint
- Day 1–2: Build the retention gap check by hand — no product, just research. Document the actual default retention of the top 8 ATS platforms and top 6 AI screening tools against the four-year CA duty. This artifact is the entire sales asset and it’s also the honest answer to “is the gap even real?” If half those vendors already retain four years, I’ve killed the idea in two days for free.
- Day 3–4: Take it to 40 California HR leads via two SHRM chapters and direct outreach to firms publicly using AI screening tools. Show them their own stack’s numbers. Say nothing about a product. Count how many ask, unprompted, what to do about it.
- Day 5: Pitch 15 CA employment boutiques that published an ADS client alert. Offer co-branded gap checks for their clients plus a referral arrangement.
- Decide: go if ≥15% of the 40 ask about remediation unprompted and ≥3 of 15 firms agree to refer. Both gates, not either — one without the other means I have a real problem with no channel, or a channel with no urgency behind it. Neither is a business.
Interested in a detailed proposal?
Get a deep-dive with market research, competitive analysis, and implementation roadmap.
Contact usinfo@startupbasket.ai