A clinic group cut referral-to-appointment from 11 days to 4
4 days median referral to first appointment, down from eleven, over two quarters
A Series A equipment lender had a signed pilot conditional on passing a bank partner's security review, seven months of runway, and a quote from someone else that ran eighteen weeks and did not mention SOC 2 anywhere.
weeks from kickoff to the first paying pilot customer
pass on the bank partner's security questionnaire — three clarifications, no remediation project
of 96 backlog items deferred in writing before the build started, none of which blocked the pilot
Figures are as reported by the client over the period named in the body below, and were not independently audited by us.
Working on something like this?
Get an estimateUnderwriting ran on a spreadsheet and a shared mailbox. That is not unusual at Series A and it was not, by itself, the thing that needed fixing — the business was writing deals and the spreadsheet was keeping up.
What needed fixing was a sequencing problem. They had a signed pilot with a bank partner, and the pilot was conditional on passing that partner's security review. The review would ask where customer data lived, who could reach it, and what record existed of who had looked at what. None of those questions have a good answer that can be produced in the fortnight before the review.
Not a proposal deck. An architecture diagram, a ticket-level backlog with an estimate per item, a written assumptions list, and a fixed number. Ninety-six items went into that backlog. Forty-one came straight back out, deferred in writing with the reason attached, so the decision could be revisited later rather than re-argued weekly.
Single sign-on, per-record audit logging, encryption at rest with keys held in their own account, and least-privilege access all landed in weeks one to three. The evidence for each — the configuration, the policy, the screenshot an auditor asks for — was captured as it was built rather than reconstructed afterwards.
The specification described four user types. Two of them had a single real user each on day one, and both could be served by an admin flag. Building the full permission matrix would have cost about three weeks and would have been rebuilt once real usage arrived, which is the most expensive order to do things in.
Eleven reports were requested. For the first fifty deals, a well-shaped export into the spreadsheet they already knew how to use answered every question the reports would have. Reporting is worth building once you know which numbers people actually look at twice.
We committed to their GitHub organisation and built in their AWS account, under their bank partner's data residency requirement. That is a security answer as much as a commercial one: the review asked who could reach production, and the answer was their staff and a named list of ours, revocable by them.
It was the largest single item in the backlog and the most confidently specified, which is usually a warning rather than a reassurance. Confidence in a feature nobody has used yet is a description of an assumption, not of a requirement. The pilot involved one bank partner and no brokers, so the portal could not have been validated during the pilot even if it had shipped — it would have been three weeks of work reviewed by nobody.
kickoff to the first paying pilot customer
on the bank partner's security questionnaire
backlog items deferred before the build started
The twelve weeks are the headline, but the mechanism is the forty-one deferrals. A twelve-week build is not a faster team; it is a smaller build, agreed in advance, with the reasons written down so nobody had to relitigate them in week seven.
The security questionnaire came back with three clarifications and no remediation work. That is the direct consequence of weeks one to three: the controls existed, and so did the evidence that they existed. Retrofitting the same controls after a failed review is the same work plus a rewrite plus a lost quarter.
The SOC 2 Type I observation window opened four months after launch, which was possible because the control set was already running rather than being designed. The window opening is a fact about a date. Certification is issued by auditors, not by us, and nothing here claims it.
A twelve-week fixed-scope build is a good fit for a narrow, well-understood problem with a hard external date. It is a bad fit in several situations we would name before quoting.
The engagement shape is described on the MVP development page, and the control work is cybersecurity services for finance. If the question you actually have is what it costs, what an MVP costs gives ranges with the assumptions attached, and the SOC 2 readiness timeline covers the sequencing this project turned on.
The features you defer in writing are cheaper than the features you defer by running out of weeks.
“The part we did not expect was how much got cut. We went in with a feature list and came out with a shorter one and a date we actually hit.”
Tell us what is not working. You will get a scoped estimate and an architecture you own, not a capability deck.
4 days median referral to first appointment, down from eleven, over two quarters
89% correct-and-cited on a 400-ticket evaluation set, from 61% at the start
99.9% service availability across the port-in weekend