softwerkdirect-to-consumer · regulated industriesStart a discovery sprint →Sign in

Regulated consumer brands

Commerce software for supplements, OTC, device brands, and health-adjacent fintech.

Cash-pay checkout, subscription billing, and consent flows, each answering to a different regulator. Built on the same gate as our healthcare and life-science work.

What this market has to prove.

01

A cash-pay checkout, a consent flow, and a subscription-billing model each carry their own regulator. A cancellation flow that is hard to find is now a named pattern in FTC complaints: Cerebral (2024) and Hims & Hers (2026).

02

PCI DSS 4.0's future-dated requirements, including MFA for anyone with access to cardholder data, have been mandatory since 2025-03-31.

03

Subscription and auto-renewal practices draw private class actions as well as FTC action. Noom's $62 million settlement (2021 to 2022) required a persistent, easy-to-find cancel button; the 2026 Hims & Hers complaint pleads the same pattern under ROSCA.

What a brands discovery sprint looks like

A sample scope, written the way an engagement is written. It is what Softwerk sells, not a case study of a past build.

What you bring
Your checkout and subscription flow as it runs today, in staging. The payment processor sandbox. Your cancellation policy and consent language. Your HSA/FSA eligibility position, if the product has one.
The one surface
Checkout, subscription billing, and cancellation on a tokenized processor sandbox, with every consent and billing event logged.
What you leave with
A running flow against the sandbox. A fixed-price build proposal with acceptance criteria. A certificate for every build produced in the sprint: sha256 of the tree, the commit it was minted for, and the SOC 2 verdict. A written statement of the PCI-DSS scope the design leaves you with. That statement is a service deliverable, not a certification.
Out of scope
PCI-DSS attestation: not live in the gate, and your QSA or SAQ process stays yours. Device software. Health-claims substantiation.
Terms
Fixed length and fixed price, agreed in writing before it starts.

The regime, live and not live.

Every framework below is labelled with whether it runs in the gate today. Nothing is described as live unless a checklist is live.

What the gate does, and what it does not.

SOC 2 runs as a dedicated module and ISO 27001 through the shared security-control set. Access-control, encryption, session, and audit-trail checks run on every scan. PCI-DSS is not live in the gate. Cardholder data goes through a PCI DSS-certified, tokenized processor so card numbers never reach your servers or ours.

How the engagement runs.

Four stages, one gate on every change. Priced and agreed before work starts.

  1. 1

    Discovery sprint

    Fixed length, fixed price, against your real checkout and billing flow on a processor sandbox.

  2. 2

    Fixed-scope build

    The factory builds the commerce surface with SOC 2 and ISO 27001 loaded from the first task.

  3. 3

    Verification gate

    We run your workspace with the gate enforced. Every diff gets an independent-model review, your compliance profile runs on the output, and a merge needs a valid certificate for that exact tree.

  4. 4

    Operate

    Every pricing, billing, or consent change ships through the same gate, and the scope names what a human reviews and when.

Asked before every first call.

Do you handle PCI-DSS for checkout and subscription billing?

Not as a live module in the gate, and we say so rather than claim a checklist that does not exist. What we do in a build: route cardholder data through a PCI DSS-certified, tokenized payment processor so card numbers never reach your servers or ours. That is how a PCI-DSS scope is kept small. It is a design commitment we make as a service, not a gate module, and your own attestation process stays yours. PCI DSS 4.0's future-dated requirements have been mandatory since 2025-03-31.

What about tracking pixels and sharing data with Meta or Google for ads?

This is where FTC enforcement in DTC health has concentrated: GoodRx, BetterHelp, and Premom in 2023, Cerebral in 2024, the 2026 suit against Hims & Hers, and an aggregator tally of more than $100 million in pixel-tracking penalties and settlements against US hospitals, telehealth platforms, and health apps since 2023. What we commit to as a service: analytics are consent-gated, no third-party ad or analytics tag is placed on a surface that carries health data, and that rule is written into the build spec and checked at review before merge. Separately, a dedicated PHI-guard service scans every generated write for identifiers and, in enforcing mode, blocks a write that carries one. Those are two different checks. We do not claim the PHI guard detects ad tags.

How independent is the review, and where does a human fit in?

The reviewer is pinned to a model family distinct from the one that generated the work, and a review from the same family is refused rather than allowed through. The same agent never signs off on its own work. That is the change-approval separation SOC 2 auditors test under CC8.1, applied to models. We do not claim “human-in-the-loop” as a safety guarantee on its own. A human reviewer is only as good as what they can see and how much time they have, so an Operate scope names exactly what a human reviews, when, and what they are shown.

Is the gate switched on for our project, or is it a setting?

It is a setting, and the engagement scope names it. The verification gate, the compliance veto, and the PHI guard each carry their own enforcement flag in the factory, and each is off until an operator turns it on. Off, the checks still run and their findings are still recorded, but nothing is withheld. On, they refuse the merge or the write, and the safe state is stop. We turn all three on for the workspace that builds your software, we put that in writing in the scope, and you can ask to see the setting on your workspace at any point in the engagement.

Full FAQ →

A goal goes in. Provable software comes out.

Bring the goal and the compliance regime. The engagement brings the spec, the build, the independent review, and the certificate.

Start a brands discovery sprint →