softwerkdirect-to-consumer · regulated industriesStart a discovery sprint →Sign in

AI-first software consultancy for direct-to-consumer in regulated industries

A goal goes in.
Provable software comes out.

Softwerk designs, builds, and runs patient- and customer-facing software for regulated direct-to-consumer programs. We run your engagement with the verification gate enforced, so every release carries a certificate that proves how it was built.

Each engagement is scoped and priced before work starts, and the discovery sprint ends with working software, not a slide deck. Role-typed agents do the building. The reviewer is pinned to a different model family from the generator, and a same-family review is refused. Your compliance profile runs on the output. What clears a merge is a content-addressed certificate: the exact source tree, the commit, the verdict. The release goes out without anyone assembling the evidence by hand afterward. With the gate enforced, no green certificate means no merge.

independent reviewimmutable audit trailcompliance-profiledfail-closed when enforced
fail-closed
the gate

With the gate enforced, a merge without a valid certificate for that exact tree is refused. The safe state is stop.

independent
the review

The reviewer is pinned to a model family distinct from the generator. A same-family review is refused, not allowed through.

write-once
the record

A certificate is a sha256 of the exact source tree, archived write-once. Audit-ready evidence.

Direct-to-consumer is now standing infrastructure in regulated industries.

Manufacturer programs put telehealth intake, benefit verification, and cash-pay fulfillment behind the manufacturer's own brand: LillyDirect, PfizerForAll (launched 2024-08-27), NovoCare Pharmacy (2025-03-05). A federal pricing push that began with letters to 17 manufacturers in July 2025 added AstraZeneca Direct and Boehringer Ingelheim Access within months, and the federal TrumpRx.gov platform launched on 2026-02-05. Enforcement moved with the market. The FTC took action against GoodRx, BetterHelp, and Premom in 2023 and Cerebral in 2024 over health data shared with ad platforms. On 2026-07-29 the FTC, the State of Utah, and California, through Los Angeles County, sued Hims & Hers over billing, cancellation, and data-sharing practices. Building DTC software here means building the proof alongside the product, not after a regulator asks for it.

Programs and companies named above are reference points and market evidence. None is a Softwerk client.

Three industries. One gate. Your proof.

The same verification gate serves every regulated market. It carries your controls. Here is the compliance pain in each, and what the factory does about it.

Healthcare DTC

HIPAAHITRUSTSOC 2ISO 27001PCI-DSSnot live

A HIPAA audit never asks whether the app works. It asks you to prove no patient data ever leaked and every access was controlled, for every release.

Softwerk builds the patient-facing surface with the HIPAA and HITRUST profiles loaded, and a dedicated PHI-guard service scans every generated write for identifiers. Analytics are consent-gated by design, and no ad or analytics tag is placed on a surface that carries health data.

See the healthcare build →

Life science / pharma DTC

HIPAASOC 2ISO 27001GxPnot live21 CFR Part 11not live

Computer-system validation means evidencing, in writing, exactly how a system was built and that nothing was altered afterward. Every release, kept forever.

A certificate is a content-addressed record of one build: the sha256 of the exact source tree, written once. There is no GxP or 21 CFR Part 11 profile in the gate. The write-once certificate is what the factory offers a validation team, and it is usable evidence for the patient-access surface between a telehealth partner and a pharmacy.

See the life-science build →

Regulated consumer brands

SOC 2ISO 27001HIPAAPCI-DSSnot live

A cash-pay checkout, a consent flow, and a subscription-billing model each carry their own regulator. Supplements, OTC, device brands, and health-adjacent fintech answer to several at once.

SOC 2 runs as a dedicated module and ISO 27001 through the shared security-control set; access control, encryption, session management, and audit trail checks run on every scan. PCI-DSS is not live in the gate. Cardholder data goes through a tokenized processor so card numbers never reach your servers or ours.

See the brands build →

Nine stations. One direction. No hand-offs.

Work moves down the line the way it would on a factory floor: each station has a single owner, a single job, and a single output the next station can trust. Ten role-typed agents own the line, one per station plus an Observer role defined in the roster (its automation is not live). Two stations are gates. With the gate enforced, a failed gate refuses the merge rather than passing the work forward.

PRD
Intake
Plan
Planner
Architect
Architect
Design
Designer / UX
Execute
Fleet
Verify
Verifier
Comply
Compliance
Merge
Merger
Deploy
Deployer
Intake

PRD

A plain-language goal becomes a structured spec and a prioritized task breakdown.

Planner

Plan

The spec is broken into phases and a dependency-ordered build plan, each step with clear acceptance criteria.

Architect

Architect

Requirements resolve to a stack, a project type, a scaffold, and the infrastructure.

Designer / UX

Design

A design system and the UI are drawn to best practice, then checked against renders.

Fleet

Execute

Each task is built by its own executor, with many running in parallel.

Verifiergate

Verify

A model from a distinct family reviews the diff; the running app is exercised by the UX gate. A same-family review is refused.

Compliancegate

Comply

Your compliance profile runs on the output, and the PHI guard scans what was written.

Merger

Merge

Default-deny: with the gate enforced, a task lands only on a valid green certificate for that exact tree.

Deployer

Deploy

The build ships through the pipeline its project type defines. No hand-offs.

With the gate enforced, nothing ships without a green certificate.

The gate is the whole point. When it is enforced, a build lands only on a certificate that is content-addressed to the exact source tree, written once, and carrying the verdict for each framework in your profile. Missing, expired, or minted for a different tree, and the merge is refused. Fail-closed: the safe state is stop. Enforcement is a setting, off until an operator turns it on, and we turn it on for the workspace that builds your software.

  • Independent-model review. A review by the same model family that generated the work is refused, not allowed through.
  • A configurable compliance profile. HIPAA, HITRUST, and SOC 2 run as dedicated modules; ISO 27001 through the shared security-control set.
  • A dedicated PHI-guard service scans every generated write for identifiers. In enforcing mode it blocks the write.
  • sha256(tree), write-once. A certificate that does not match the tree it claims is rejected.
THE VERIFICATION GATE
verdict pass
certificatesha256(tree)
storagewrite-once (WORM)
complianceyour profile · pass
gate stepsrun before the certificate
reviewerdistinct model family
phi-guardclear
missing / expired / tampered → merge refused

Four stages. One gate on every change.

Discovery, build, verification, and operate are services. Softwerk's own factory, role-typed agents behind a verification gate, is what delivers them. You are not buying a bench.

  1. 1

    Discovery sprint

    Fixed length, fixed price, agreed in writing before it starts. We work against one real integration surface, a sandbox EHR, a pharmacy partner's intake format, a payment processor sandbox, using your sandbox or de-identified data. You leave with working software, a fixed-price build proposal with acceptance criteria, and a certificate for every build the sprint produced.

  2. 2

    Fixed-scope build

    Agreed acceptance criteria and priced milestones. The factory builds it: PRD, Plan, Architect, Design, Execute, with many tasks running in parallel. One accountable Softwerk lead owns the engagement end to end.

  3. 3

    Verification gate

    We run your engagement workspace with the gate enforced, so a task merges only on a valid certificate for that exact tree. On the way there, every diff is reviewed by a model from a different family than the one that generated it, your compliance profile runs on the output, and the PHI guard scans every generated write. This is not a project phase. It runs on every change, for as long as the software ships through the factory.

  4. 4

    Operate

    Post-launch changes ship through the same gate, so release 50 carries the same kind of certificate as release 1. Support and monitoring are a separately scoped service tier, and the scope names what a human reviews and when.

What a regulated buyer asks first.

Ten questions, answered against what the product does today and what Softwerk commits to as a service. Where something is not live, or is a setting rather than a fact, it says so.

Are you a HIPAA covered entity? Do you sign a BAA?

Softwerk is a business associate when a build touches protected health information, and we sign a Business Associate Agreement before that happens. A discovery sprint runs on sandbox or de-identified data and needs no BAA. Once a BAA is in place, we run the engagement with the HIPAA profile enforced in the gate, and the certificate records the per-framework verdict. The certificate, not a badge, is what an auditor can check.

We're not a hospital or a health plan. Does any of this apply to us?

Probably yes. The FTC's Health Breach Notification Rule covers personal health record vendors and related apps outside HIPAA. The FTC used it against GoodRx (2023-02, $1.5 million) and Premom (2023-05, $100,000) under the original rule, and the amendment in effect since 2024-07-29 codified the reach: health apps, a 60-day notice duty, FTC notice at 500 or more affected people, and disclosure of any third party, ad platforms included, that received the data. BetterHelp (2023) and Cerebral (2024) were pursued under Section 5 of the FTC Act for the same pattern. Not being a HIPAA covered entity is not a safe harbor.

What about tracking pixels and sharing data with Meta or Google for ads?

This is where FTC enforcement in DTC health has concentrated: GoodRx, BetterHelp, and Premom in 2023, Cerebral in 2024, the 2026 suit against Hims & Hers, and an aggregator tally of more than $100 million in pixel-tracking penalties and settlements against US hospitals, telehealth platforms, and health apps since 2023. What we commit to as a service: analytics are consent-gated, no third-party ad or analytics tag is placed on a surface that carries health data, and that rule is written into the build spec and checked at review before merge. Separately, a dedicated PHI-guard service scans every generated write for identifiers and, in enforcing mode, blocks a write that carries one. Those are two different checks. We do not claim the PHI guard detects ad tags.

Do you handle PCI-DSS for checkout and subscription billing?

Not as a live module in the gate, and we say so rather than claim a checklist that does not exist. What we do in a build: route cardholder data through a PCI DSS-certified, tokenized payment processor so card numbers never reach your servers or ours. That is how a PCI-DSS scope is kept small. It is a design commitment we make as a service, not a gate module, and your own attestation process stays yours. PCI DSS 4.0's future-dated requirements have been mandatory since 2025-03-31.

What about FDA rules on DTC drug advertising?

The gate does not run an FDA promotional-review profile, and we do not claim it does. On 2025-09-09 FDA and HHS sent roughly 100 cease-and-desist letters over DTC drug advertising and warning letters to about 30 telehealth companies, and FDA has proposed removing the “adequate provision” option for broadcast ads. What we build is the infrastructure that makes your MLR or legal review fast to do and easy to prove: versioned content, an audit trail of what shipped when, and a review step your team sits inside. The promotional judgment stays with you.

Do you validate to GxP or 21 CFR Part 11?

Not as a coded profile in the gate. It is flagged not live wherever it appears. What the engagement gives you instead: a write-once, content-addressed certificate, a sha256 of the exact source tree, for every build. FDA's Computer Software Assurance guidance (2025-09-24) favors risk-proportionate evidence, and the certificate is usable evidence in that framing. It is not a substitute for a GxP checklist, and we do not sell it as one.

Who owns the code, and who is responsible if AI-generated code is wrong?

You own the delivered work product under the engagement terms. A certificate carries the sha256 of the exact source tree, the commit it was minted for, and the compliance verdict. The certificate does not record which model reviewed the build. Independence is enforced where the review runs: a review from the same model family that generated the work is refused. It is a build attestation of the kind buyers now ask for alongside a Software Bill of Materials; the factory does not produce an SBOM. On responsibility: model vendors disclaim broadly in their terms of service, Softwerk is responsible for delivering to the agreed acceptance criteria, and operating what we build is yours, as in any services engagement.

How independent is the review, and where does a human fit in?

The reviewer is pinned to a model family distinct from the one that generated the work, and a review from the same family is refused rather than allowed through. The same agent never signs off on its own work. That is the change-approval separation SOC 2 auditors test under CC8.1, applied to models. We do not claim “human-in-the-loop” as a safety guarantee on its own. A human reviewer is only as good as what they can see and how much time they have, so an Operate scope names exactly what a human reviews, when, and what they are shown.

Can we use the factory ourselves, without an engagement?

Not today. Sign-in at app.softwerk.io is limited to workspaces Softwerk sets up during an engagement. The Sign in link (in the header on larger screens, in the footer on phones) is for those workspaces.

Is the gate switched on for our project, or is it a setting?

It is a setting, and the engagement scope names it. The verification gate, the compliance veto, and the PHI guard each carry their own enforcement flag in the factory, and each is off until an operator turns it on. Off, the checks still run and their findings are still recorded, but nothing is withheld. On, they refuse the merge or the write, and the safe state is stop. We turn all three on for the workspace that builds your software, we put that in writing in the scope, and you can ask to see the setting on your workspace at any point in the engagement.

A goal goes in. Provable software comes out.

Bring the goal and the compliance regime. The engagement brings the spec, the build, the independent review, and the certificate.

Start a discovery sprint →