SB StartupBasket
All ideas
76 /100 GO Medium complexity

ScanSweep — ID-document purge for AU Tranche 2 firms

Finds every passport and licence scan buried in a firm's email and drives, then proves it was destroyed.

— views
Evaluation Scores
76/100

GO

Overall Score

16
Problem
12
Demand
11
Build
13
Distrib.
12
Revenue
8
Time
4
Defense

ScanSweep

1. One-liner

Finds every passport and licence scan buried in a firm’s email and drives, then proves it was destroyed.

2. Trend signal — why now?

Three things happened in the space of four months, and they collide badly.

First, on 1 July 2026 the AML/CTF Tranche 2 reforms switched on. Real estate professionals, lawyers, conveyancers, accountants, trust and company service providers, and dealers in precious metals and stones became AUSTRAC reporting entities. Roughly 100,000 small businesses in named professions, covered regardless of turnover.

Second — and this is the part almost nobody has internalised — becoming a reporting entity strips the Privacy Act small business exemption. The OAIC’s guidance is explicit: “the small business exemption in the Privacy Act will not apply to reporting entities” for their AML/CTF activities. A three-partner conveyancing firm turning over $900K, which had zero federal privacy obligations on 30 June, woke up on 1 July owing the Australian Privacy Principles.

Third, the OAIC updated its AML/CTF privacy guidance in February 2026 and revised it in March after industry pushback. The headline instruction: stop storing copies of identification documents. From 31 March 2026 (Tranche 1) and 1 July 2026 (Tranche 2), firms should not keep full copies of passports and drivers’ licences for AML record-keeping. The obligation is to retain evidence that verification occurred — name, date of birth, document number, issuing country, expiry, method, date, outcome — not the document image itself.

That leaves the historic pile. The OAIC did not demand immediate destruction of documents collected before the cutover; it demanded “reasonable steps,” which it defined as committing to destroy or de-identify copies of identification documents as soon as this practically becomes possible, backed by a documented plan with realistic timelines proportionate to the size and complexity of the business.

A documented plan. With timelines. Produced by a four-person real estate agency whose ID scans are in Outlook attachments, a shared Dropbox, three staff members’ Downloads folders, and the CRM.

The practical shape of the problem is already being described in the market: smaller firms “often store ID documents in shared drives or email folders, retain full scans as a default safeguard, and operate without formalised data retention schedules.”

Provenance:

3. The opportunity

The AML vendors sell capture. ScanSweep sells cleanup.

Every platform aimed at Tranche 2 — ClearAML, AMLTranche, First AML, AMLHUB, FreeAML — solves the same forward-looking problem: a new client walks in, verify them, screen them against sanctions and PEP lists, store a structured record, file SMRs and TTRs. That market is competitive and priced.

Not one of them looks backwards. I checked ClearAML’s own product surface: KYC/KYB verification, risk scoring, sanctions and PEP screening, transaction monitoring, AUSTRAC reporting, compliance dashboard. No capability to scan existing file storage — email, SharePoint, Dropbox, the practice management system — for historic identity documents, and no remediation of what it finds.

So the firm buys ClearAML, feels compliant, and remains in breach of APP 11 on ten years of passport scans sitting in Outlook. Worse, those scans are exactly the payload that turns an ordinary phishing compromise into a notifiable data breach with identity-theft consequences — which is the whole reason the OAIC wants them gone.

The incumbent I’m displacing isn’t a software vendor. It’s a $300/hour privacy consultant doing a manual data audit, or more commonly nobody at all. The 10× is straightforward: a human cannot open 400,000 files. A vision model can, for about the cost of a coffee, and can tell you which 2,300 of them are identity documents, whose they are, and which client matter they attach to.

The defensible artefact is not the deletion. It’s the destruction register — the dated, itemised, exportable record that the firm searched N locations, found M documents, destroyed them on date D, and retained the structured verification record instead. That register is what a firm hands the OAIC to prove “reasonable steps.” Nobody can produce it retrospectively. If you didn’t log the sweep, you can’t prove you did it.

4. Target market

Primary customer: The principal or practice manager of a 2–20 person Australian firm in a Tranche 2 profession — real estate agencies (sales and property management), small law practices doing conveyancing and property, accounting firms providing designated services, standalone conveyancers, and trust and company service providers. Turnover $500K–$8M. No IT staff; an outsourced MSP at best. Almost certainly Microsoft 365, possibly Dropbox, plus a vertical system (PropertyMe, Console, LEAP, Actionstep, Xero Practice Manager).

Why they buy: Not because they love privacy law. Because from 1 July 2026 they carry a new, personal, unfamiliar exposure with no in-house expertise. The penalty band that bites this segment is up to $66,000 for a contravention such as operating without a compliant privacy policy — not the headline $50M, which is for serious breaches, but still enough to end a small partnership’s year. Layered on top: since 10 June 2025 individuals can sue under the new statutory tort for serious invasions of privacy, with no need to prove financial loss, and damages available for emotional distress. A leaked cache of client passports is exactly the fact pattern that tort was written for.

Rough TAM reasoning: Reported figures put over 100,000 small businesses in the named professions entering the Privacy Act from 1 July 2026 regardless of turnover. That is the beachhead. Behind it sits the far larger 10 December 2026 event, when the general small business exemption is removed and an estimated 2.3–2.5 million additional Australian businesses — about 95% of all Australian businesses — come under the full Act. I am not underwriting the idea on 2.5 million; I am underwriting it on the 100,000 who are already obligated, already buying compliance software, and already have a named regulator telling them specifically to delete identity documents. The December cohort is the expansion story.

Why now for them: The obligation started two months ago. The OAIC’s phrasing — destroy “as soon as this practically becomes possible,” on a documented plan with realistic timelines — means the clock is running and every month of inaction makes the plan look less reasonable. There is no version of this where waiting improves the firm’s position.

5. Product sketch (MVP)

  • Connect and sweep. Read-only OAuth into Microsoft 365 (Outlook, OneDrive, SharePoint), Google Workspace, and Dropbox. Enumerate every file and mail attachment in scope.
  • Identify the documents. Classify each image and PDF: is this a passport, drivers licence, Medicare card, birth certificate, bank statement, utility bill? Extract whose it is and the document number, so the firm can tie it to a client matter.
  • Sweep report. “We searched 6 locations and 412,000 objects. We found 2,340 identity documents covering 890 individuals, the oldest from March 2014, spread across these 7 folders and 3 mailboxes.” This alone is the thing they cannot currently produce.
  • Destruction plan generator. Turns the findings into the documented plan the OAIC asks for — categories, locations, volumes, proposed timelines proportionate to firm size, sign-off block for the principal.
  • Structured record conversion. Before deleting, capture the compliant residue: name, date of birth, document number, issuing country, expiry, verification method, date, outcome. The firm keeps the evidence that verification happened, and loses the image.
  • Guided destruction with proof. Delete or redact in place, with confirmation, exclusions for anything under a live legal hold or still inside its 7-year AML retention window.
  • Destruction register. Immutable, dated, itemised, exportable to PDF. The artefact you hand a regulator, an insurer, or a buyer doing due diligence.
  • Recurring re-sweep. Monthly re-scan catching new ID documents that staff email in anyway, because they will. This is what converts a one-off cleanup into a subscription.

6. AI angle — what’s load-bearing

Remove the AI and this product does not exist.

The entire job is: look at 400,000 unlabelled, badly-named files — IMG_4471.jpg, scan0093.pdf, Client docs FINAL.pdf, an eight-page PDF with a licence photocopy on page 6 — and decide which ones contain a government identity document, and whose. That is not a filename rule, not a regex, and not a keyword search. Firms name files arbitrarily and scan documents into mixed bundles. Traditional DLP tools match patterns in text; these are photographs.

Vision-model classification is the product. Cheap multimodal inference is precisely what makes sweeping a whole tenancy economically sane — at fractions of a cent per image, a 400,000-object sweep costs single-digit dollars in inference. Two years ago this was a custom-trained CV project with a data-labelling budget, which is exactly why nobody built it for four-person conveyancers.

The secondary AI job is extraction: pulling the structured verification record off the document before destroying it, so the firm retains what AUSTRAC requires and drops what the OAIC forbids. Doing that by hand across 2,340 documents is the reason firms would otherwise just keep everything.

7. Localization angle (if any)

Australia-first, deliberately and narrowly.

The wedge is a specific regulator’s specific guidance (OAIC), a specific statute (Privacy Act 1988 APP 11.2), a specific commencement (Tranche 2, 1 July 2026), and a specific retention rule (7 years from the end of the business relationship or last transaction). The destruction plan template, the hold logic, and the register format are all shaped by Australian requirements. A generic global “find PII in your files” tool loses to this on exactly the ground that matters: it cannot tell the firm what to keep, and it cannot produce a plan a Australian regulator recognises.

The same shape ports later. The UK, Canada, and the EU all run AML regimes with ID-retention rules colliding against data-minimisation duties, and the UK in particular has an established estate-agent and solicitor AML population. But porting means re-doing the retention logic per jurisdiction, and I would not do it until Australia is at $1M.

8. Business model — path to $1M–$5M ARR

Pricing:

  • Sweep (one-off): $1,500–$4,000 depending on tenancy size and connector count. This is the wedge purchase, priced against a privacy consultant’s manual audit, and deliberately easy to approve as a one-line professional expense.
  • Watch (subscription): $199/mo solo–small, $399/mo for 6–20 staff. Monthly re-sweep, destruction register upkeep, new-document alerts, access-request assist.

ACV: Realistically $2,400–$4,800 for a converted customer in year one (sweep plus part-year subscription), settling to $2,400–$4,800 recurring.

Rough math to $1M ARR: 300 firms on $279/mo blended = $1.0M recurring, plus one-off sweep revenue on top. Out of a beachhead of 100,000 obligated firms, that is 0.3% penetration.

Rough math to $5M ARR: ~1,400 subscribed firms at the same blended rate, which needs either the December 2026 general cohort opening up (2.3M+ businesses, though with a weaker AML-specific hook) or a channel — the AML platforms and MSPs reselling ScanSweep as the remediation module they don’t have. I would pursue the channel before the mass market.

Expansion path: Start at cleanup, expand into the adjacent APP obligations these firms also just acquired and equally cannot do — APP 12 access requests (find everything you hold on this person, in 30 days, across the same connectors — the sweep index already answers this), breach-scope assessment when they do get compromised, and the APP 5 collection-notice trail. The connector graph is the asset; each new obligation is a new product on the same plumbing.

9. Go-to-market wedge — first 100 customers

  • Sell through the professional bodies’ compliance panic, not around it. Every state Law Society, the REIA and state REIs, CPA Australia, CA ANZ, and the Australian Institute of Conveyancers is running Tranche 2 briefings right now, and they are all telling members to “audit what data you hold.” Nobody in the room can actually do it. Offer to run a free live sweep on one volunteer member firm during the session and read the number out loud. “This agency had 2,340 identity documents going back to 2014” is the only sales pitch this product needs. Target 15 sessions in six months.
  • Reseller deal with the AML platforms. ClearAML, AMLTranche, AMLHUB and similar have the exact customer list, an existing billing relationship, and a hole in their product they know about. Offer white-label or 25% referral. They are not going to build backwards-looking file remediation — it is a different engineering problem from KYC — and it makes their compliance story complete. Three signed resellers is a plausible quarter.
  • MSPs and IT providers serving legal and real estate. Australian MSPs are already publishing Tranche 2 content to their client bases because it drives IT work. They hold the Microsoft 365 admin credentials, which is the hardest part of onboarding. Partner-led delivery at a margin: they run the sweep, we power it.
  • Direct outbound to real estate principals with a free exposure estimate. Real estate agencies are the most listable Tranche 2 segment — every state has a public licensed-agent register, plus REI membership directories. Scrape, then send a one-pager: “You’ve been a reporting entity since 1 July. The OAIC says stop storing ID copies and destroy the old ones on a documented plan. Here’s a template plan, and here’s what a sweep found at an agency your size.” Cold outbound to compliance-deadline audiences converts when the deadline is real and named; this one is both.
  • Write the destruction plan template everyone Googles for. “OAIC identification document destruction plan template” is a query that will be typed by every one of these firms and currently returns law-firm articles telling them to have one, not one they can use. Give the template away, gated on a sweep.

10. Build complexity — justification

Medium. The AI is off-the-shelf — vision-model classification and extraction via API, no training, no labelled dataset needed. The real work is connectors and correctness: Microsoft Graph, Google Drive, and Dropbox each with their own auth, throttling, delta-sync and permissions model, running reliably across a tenancy with hundreds of thousands of objects without blowing rate limits or timing out.

The genuinely careful part is the destruction path. This product deletes client records at a regulated firm. Hold logic (live matters, 7-year AML windows, litigation holds), a mandatory human approval gate, dry-run-by-default, and an append-only register are not features — they are the reason the product is trustworthy enough to buy. Get that wrong once and the company is over.

Two people, 4–5 months to a v1 that sweeps Microsoft 365 and produces a register. Google Drive and Dropbox in month 6.

11. Gating checklist

GatePass?Note
Legal in target market✅Helps firms comply with the Privacy Act and OAIC guidance. Read-only until an explicitly approved destruction run.
Ethical — no harm / dark patterns✅The product’s entire purpose is deleting identity documents that shouldn’t be retained. Reduces breach harm to consumers.
Market exists (evidence above)✅~100k firms obligated since 1 July 2026; a live AML software market at $49–$149/mo proves budget and buying behaviour.
1–5 person team can build this✅Two engineers. Off-the-shelf vision APIs, standard cloud connectors.
Launchable with <$50K / ₹40L✅Inference is cents per sweep. Main costs are two salaries and a privacy lawyer to review the plan templates.

12. Feasibility score

AxisWeightScoreNotes
Problem intensity2016/20Live legal obligation on a named population with a regulator instruction to destroy, plus $66K contravention exposure and a new privacy tort. Docked because it’s a risk-avoidance pain, not daily cash bleed — no invoice is stuck, so it competes with procrastination.
Demand evidence1512/15Strong indirect evidence: priced AML market for this exact buyer, professional bodies actively briefing, explicit regulator guidance. Docked because I have no verbatim customer quotes asking for this product — the obligation is two months old.
Build feasibility1511/15AI is an API call. Connectors at scale plus safe destruction logic is real engineering. 4–5 months for a pair, not 6 weeks.
Distribution clarity1513/15Listable population (state agent registers, professional directories), three named reseller categories with the customer list already, and a live briefing circuit to piggyback.
Revenue mechanics1512/15Two-part pricing benchmarked against an existing $49–$149/mo category and consultant day rates. $1M needs only 300 firms. Docked: the one-off sweep is the easy sale, the recurring subscription is the assumption.
Time to first revenue108/10The sweep can be sold and part-delivered as a paid pilot on a single connector. Weeks, not quarters — but there is a build before the first invoice.
Defensibility104/10The honest weak axis. No moat at month 3 beyond execution. By month 12 the destruction registers and connector history create switching cost, and being the name the Law Societies recommend is worth something. But an AML incumbent could bolt this on.
Total10076/100

13. Qualitative modifiers

Founder-fit tags

technical-heavy · domain-expertise-required

You need someone who can build reliable cloud connectors at tenancy scale and someone who genuinely understands the APP 11.2 / AML retention interaction well enough to defend the hold logic to a suspicious principal. A privacy lawyer on retainer covers the second if the founder can’t.

Key assumptions to validate (3–5)

  1. Assumption: A typical Tranche 2 firm actually holds a large, surprising volume of historic ID documents — hundreds to thousands, not a tidy dozen. How to test: Run free manual-assist sweeps on 5 friendly firms (one agency, two law practices, two accountants). The finding count is the entire pitch. If the median is under 100 documents, the shock value evaporates and so does the sale.
  2. Assumption: Principals will pay $1,500–$4,000 for a one-off sweep rather than assign it to a junior with a search bar. How to test: Take the sweep report from test #1 to 20 principals with a price attached. Measure signed orders, not enthusiasm.
  3. Assumption: The one-off converts to a subscription — that firms accept re-sweeping is necessary because staff keep emailing ID scans. How to test: In the pilot cohort, re-sweep at day 60 and count newly-arrived ID documents. If new documents accumulate meaningfully, the subscription sells itself. If not, this is a services business with a ceiling.
  4. Assumption: Firms will grant OAuth access to their entire mail and file estate to a new vendor. How to test: Track drop-off at the consent screen in pilots. Have the read-only-until-approval story, security posture, and an MSP-delivered option ready as the fallback.
  5. Assumption: AML platforms will partner rather than build. How to test: Pitch three of them in month one. Their response also tells you how fast the copy risk arrives.

Risk flags

  1. Incumbent absorption: This is a feature an AML platform could ship. My defence is being 12 months earlier and owning the register as the artefact of record. If ClearAML or First AML announces file remediation before v1 ships, the economics change badly.
  2. Trust barrier at the consent screen: Asking a law firm for read access to every client file is the highest-trust ask in SMB software. Expect a long trust cycle, and expect MSP and professional-body endorsement to be load-bearing rather than optional.
  3. Destruction liability: If the tool deletes something under a legal hold or inside its AML retention window, the firm has a serious problem and so do you. Mitigation is dry-run default, mandatory human approval, conservative hold logic, and insurance — but the risk never goes to zero.
  4. Regulatory softening: The OAIC already retreated once, softening the February 2026 position to “reasonable steps” after industry pushback. Further softening, or an extended transition, drains the urgency that makes this sellable.
  5. Deadline decay: Regulatory-urgency products sell hardest near the date. 1 July has passed and 10 December is coming; after that the pitch shifts from “you’re exposed now” to ongoing hygiene, which is a harder, slower sale.

14. Structured verdict

Score:                  76/100
Verdict:                GO
Confidence:             Medium
Best-fit builder:       Technical pair — one on cloud connectors at scale, one on
                        Australian privacy/AML domain (or a privacy lawyer on retainer).
                        Distribution runs through professional bodies and MSPs, so
                        someone must be comfortable presenting to a room of principals.
Time to revenue:        10–14 weeks to first paid sweep (single connector, manual assist)
Capital to launch:      A$25–40K (two part-time salaries, legal review of plan templates,
                        inference and infra are trivial)
Top 3 assumptions to validate first:
  1. Median ID-document count at a real Tranche 2 firm is in the hundreds+ —
     run 5 free assisted sweeps and count
  2. Principals pay $1,500–$4,000 for the sweep — take the report to 20 firms with
     a price on it, measure signed orders
  3. New ID documents keep arriving after cleanup — re-sweep pilots at day 60;
     this is what makes it SaaS instead of consulting
Kill criteria:
  - Abandon if median finding count across 5 pilot firms is under 100 documents
    (the shock value is the product)
  - Abandon if fewer than 3 of 20 priced pitches convert to a paid sweep
  - Abandon if a major AML platform ships historic file remediation before v1
  - Abandon if the OAIC extends the transition or drops the destruction expectation

15. Next step — 1-week validation sprint

  • Day 1–2: Line up 5 firms — one real estate agency, two small law practices, two accounting firms — through a state Law Society or REI contact. Offer a free “privacy exposure sweep” in exchange for an hour and read-only access to one mailbox and one shared drive. Getting the fifth yes is itself a signal about the trust barrier.
  • Day 3–4: Run the sweeps semi-manually — a script over the connector plus a vision API, no product. Count identity documents, date the oldest, map the locations. Produce a one-page report per firm with the raw number at the top.
  • Day 5: Sit with each principal, hand over the report, and quote $2,500 for a full sweep and destruction register. Ask for the order on the spot.

Falsifiable outcome: Go if the median finding count is ≥100 identity documents and at least 2 of 5 principals sign or verbally commit to a $2,500 sweep. No-go if firms turn out to be tidier than assumed, or if the reaction to a report showing 2,000 exposed passport scans is “we’ll get to it” — because that answer means the obligation isn’t yet urgent enough to beat procrastination, and no amount of product fixes that.

Interested in a detailed proposal?

Get a deep-dive with market research, competitive analysis, and implementation roadmap.

Contact us

info@startupbasket.ai