Back to Leaderboard
Overseas MarketID: #66

Micro SaaS / API Wrapper / Bot

NCII/Deepfake Takedown Compliance Tracker

A $9-15/month subscription that sits on top of the free TAKE IT DOWN Act takedown-letter step: it keeps scanning the web for re-uploads of a victim's nonconsensual intimate image or deepfake, runs a live 48-hour countdown per platform, and auto-builds an FTC complaint packet the moment any platform misses its legal deadline.

Research Stage Progress

① Demand Scan
② Market Research
③ Feasibility Analysis
Triage ScoreTotal Score: 25/35
Demand Pull: 4Acquisition Feasibility: 3Agent Advantage: 4Low Volume Economics: 4Operator Lightness: 3Market Trend: 4Policy Redline: 3Demand Pull(4/5)Acquisition Feasibility(3/5)Agent Advantage(4/5)Low Volume Economics(4/5)Operator Lightness(3/5)Market Trend(4/5)Policy Redline(3/5)
Market Research Evaluation
6.3/10
Assessment Rationale

Scoring basis (0-10, blends demand-side and competition-side):

Demand side (strong, pulls the score up): A freshly enforced federal law (TAKE IT DOWN Act, platform deadline live May 19, 2026) plus an FTC complaint portal that opened the same week create a concrete, legally-grounded reason to buy that did not exist seven weeks before this research. Victim population is real and converging across three independent 2026 surveys (roughly 90% women/girls among deepfake victims). Bottom-up sizing (US adults 276.8M x 2.2-6% victimization-rate range, both global/multi-country rates since no US-specific study was found) puts TAM near $620-915M/year, narrowing to a SAM of $62-137M/year and a realistic year-3 SOM of $1.5-3.3M ARR. All rate inputs and the SAM/SOM capture-rate assumptions are explicitly flagged medium-to-low confidence since they are extrapolated, not directly measured for this category.

Competition side (real but incomplete gap, moderates the score): Confirmed via direct fetch that the two closest paid comparables (Ceartas $69-1,200/month, Rulta $109-324/month) both serve professional creators exclusively and neither mentions the TAKE IT DOWN Act; the two free comparables (Chayn, StopNCII) both stop before ongoing monitoring or deadline escalation. No player combines re-upload monitoring with automatic FTC-complaint assembly for an ordinary individual at a $9-15/month price point. This is a genuine unclaimed position, not a crowded field.

What holds the score below 7: (1) the $9-15/month target price sits below the entry tier of the cheapest plausible detection-API vendor found (PimEyes, $29.99/month), a real unit-economics risk feasibility must resolve; (2) both existing paid competitors independently converged on a $69-110/month price floor built around human-agent labor, suggesting the $9-15/month segment may not sustain the same cost structure without a materially more automated build; (3) acquisition channels are relationship-dependent (nonprofit/advocate referrals) rather than standard paid-search, since ad platforms restrict NCII/deepfake-adjacent keywords; (4) SAM/SOM narrowing assumptions (10-15% actively seeking, 2-4% three-year capture) are analyst estimates by analogy, not sourced data, and should be treated as the least certain numbers in the whole model.

Feasibility Evaluation
Infeasible
Feasibility Score2.8/10
Assessment Rationale

Scoring basis (0-10, blends technical/financial/compliance/competitive feasibility; a fatal high risk on any axis caps the score low regardless of demand strength):

Financial model does not clear the bar (dominant factor holding score down): The only detection-vendor price this research could confirm with a real quote (PimEyes consumer face-search tier, $29.99/month) already exceeds the entire proposed $9-15/month retail subscription, making the buy path unconditionally loss-making at any customer volume and any CAC (LTV/CAC negative in every combination modeled). The build path only turns marginally positive under an unverified wholesale-cost assumption (~$3.50/user/month, roughly one-ninth of the only confirmed retail price, not sourced from any vendor quote); even in that optimistic case, best-case LTV/CAC is 1.13x, well under the conventional 3x health threshold, and break-even (~3,650 subscribers, ~$525K ARR) requires capturing 15-30% of research's own Year-3 total addressable market just to cover a lean $31K/month fixed-cost base. Two independent professional competitors (Ceartas, Rulta) converged on a $69-110/month price floor built around a materially different, more labor-intensive cost structure, which is real evidence against the $9-15/month price point sustaining comparable economics without an unproven technical shortcut.

Compounding fatal risk, not merely additive: The product is structurally adjacent to CSAM. Any tool that scans the open web for sexual imagery of a specific identified person will, by the nature of the underlying problem, eventually surface cases involving a minor. That requires mandatory-reporting infrastructure (NCMEC CyberTipline), specialized legal counsel, and a hard zero-tolerance stop-and-refer workflow before the first paying customer, not as a later iteration. This exposure is very likely to make most seed-stage investors, several payment processors, and some insurers decline involvement on category grounds alone, which directly undermines the ability to raise the $432K-$618K in estimated upfront capital the financial model requires. A weak financial model that could otherwise be fixed with more capital is much harder to fix when the same weakness also narrows the pool of capital willing to fund the fix.

What is genuinely strong, and why it is not enough to rescue the score: The regulatory trigger (TAKE IT DOWN Act, live FTC enforcement, a brand-new complaint portal) is real and freshly confirmed via primary sources, and the competitive gap (no existing player combines ongoing monitoring with FTC-escalation for an ordinary consumer) is genuine and verified by direct fetch of the closest comparables. Neither of those addresses the core problem: the unit economics do not work at the stated price with the only cost data actually obtained, and the content category carries a single-incident, business-ending legal and reputational risk that most capital sources will not underwrite. A path may exist through a nonprofit partnership or grant-funded structure rather than a standalone venture-backed consumer subscription, but that is a different business model than the one this analysis was asked to evaluate, and was not credited toward this score since it was not what was proposed.

Verdict: INFEASIBLE at the proposed $9-15/month price point and consumer-subscription business structure. The single biggest killer is the combination of unverified, likely-negative unit economics on the detection engine plus CSAM-adjacent legal and fundraising exposure, either one of which alone would be a serious concern, and together are close to disqualifying.

NCII/Deepfake Takedown Compliance Tracker

Track: Micro SaaS / API Wrapper / Bot | Market: overseas (United States, individual consumer) | status: PENDING_RESEARCH | Created: 2026-07-09T00:00:00Z | Updated: 2026-07-09T00:00:00Z

Scout output, for downstream research/feasibility. Full metadata in meta.json in this directory.

One-liner

A $9-15/month subscription that sits on top of the free TAKE IT DOWN Act takedown-letter step: it keeps scanning the web for re-uploads of a victim's nonconsensual intimate image or deepfake after the first request goes out, runs a live 48-hour countdown per platform, and auto-builds an FTC complaint packet the moment any platform misses its legal deadline.

Opportunity source (how it was found)

  • Method: Trend Sniffer + Pain-point Extractor combined into an Idea Generator synthesis.
  • Signal (Trend Sniffer): The TAKE IT DOWN Act's Section 3 compliance deadline landed May 19, 2026, and the FTC moved fast: warning letters to at least 15 major platforms the same week, a separate round of warnings to 12 unnamed "nudify" AI-image sites (civil penalties up to $53,088 per violation), and a brand-new public complaint portal at TakeItDown.ftc.gov for victims to report platforms that blow the 48-hour window. This is a live regulatory event roughly seven weeks old at scan time, not a stale, already-picked-over topic.
  • Signal (Pain-point Extractor): Two tools already exist in this exact space, and both stop at the same point. Chayn's free Survivor AI (checked directly) generates one takedown letter and then stops; no monitoring, no tracking of whether the platform actually complied, no re-upload detection. Ceartas, the leading paid competitor (checked directly), charges $69-1,200/month but only sells to professional creators and "A-list talent": nowhere does it mention TAKE IT DOWN Act workflows or serve an ordinary private individual. StopNCII.org only works if the victim already has the exact file to hash and only on platforms that opted into the program. A documented victim anecdote captures the actual pain: content "kept reappearing on mirror sites" for weeks after a successful takedown elsewhere. The tool that exists today helps you write one letter, but nobody is watching for what happens next.
  • Idea Generator synthesis: the market has split into "free one-time letter generator for anyone" (Chayn) and "expensive ongoing protection for professional creators" (Ceartas), with nothing built for the much larger population of ordinary people, mostly women per every survey found, who get hit once, send one letter, and then have no way to know if new copies pop up or if a platform quietly ignores its legal deadline. The product is narrow on purpose: don't compete with the free letter generator, sit on top of it as the ongoing monitoring and enforcement layer that turns a new federal right into something a normal person can actually use without checking ten websites a week by hand.

Demand detail

Who wants this: individual adults in the United States who have discovered, or reasonably suspect, that intimate images or AI-generated sexual deepfakes of themselves are circulating online without consent. Every study located points to a heavily female-skewed victim population. One 2026 estimate puts women and girls at roughly 90% of nonconsensual-deepfake victims, and a separate 2026 survey found 6% of women reporting deepfake/manipulated-image victimization specifically, against a broader 57% reporting any form of image-based abuse. A ten-country academic survey found 2.2% of 16,000+ respondents self-reporting personal deepfake-porn victimization. Applied cautiously to the US adult population as a rough order-of-magnitude estimate (not a confirmed US-specific figure, flagged as an estimate in assets/evidence.md), that points to a total addressable pool in the low millions, with a much smaller but very real "actively searching for help this week" segment driving near-term demand.

What they are expressing: not confusion about whether deepfakes are wrong (that ground is well covered by news coverage and advocacy groups) but a much narrower, sharper frustration: "I sent the letter, now what." The free tool stops at letter number one. Nobody tells a victim whether platform two of five actually deleted the content, whether a mirror site re-uploaded it a week later, or what to do when a platform just doesn't respond inside 48 hours. That last gap is not hypothetical: the FTC only just opened a formal complaint channel for exactly this failure mode in May 2026, which means until seven weeks before this scan, there was no official escalation path at all, and today there is one but no consumer tool that watches the clock and fills out the complaint automatically when it runs out.

Strength and breadth of pull: this is a brand-new, government-created enforcement mechanism (the FTC portal) layered onto a brand-new legal deadline (the 48-hour window), both less than two months old at scan time, sitting on top of a large and apparently growing underlying problem. Deepfake generation volume is enormous: one documented case shows a single chatbot producing roughly 3 million sexualized images in 11 days. Regulatory-trigger opportunities in this portfolio (see Singapore compliance lanes) have consistently shown that a fresh legal deadline plus fear-driven urgency produces above-average willingness to pay for a tool that removes the burden of tracking compliance manually. The same dynamic applies here, just transplanted into a consumer-protection context instead of a B2B compliance context.

7-dimension triage score (detail in meta.json.triage)

Demand pull 4 / Acquisition feasibility 3 / Agent advantage 4 / Low-volume economics 4 / Operator hand lightness 3 / Market trend 4 / Policy redline 3 -> Total 25/35

Rationale summary:

  • Demand pull (4, not 5): multiple independent 2026 surveys (UN-cited, academic, industry) converge on a large, real, women-skewed victim population, and the specific gap (no monitoring/escalation layer on top of the free letter generator) is confirmed by directly fetching both existing tools rather than assumed. Not a 5 because a hard US-specific victim-count figure was not found (the estimate leans on global survey percentages applied to US population, explicitly flagged), and no direct forum/review text from actual victims describing this specific frustration could be retrieved through available public search tools.
  • Acquisition feasibility (3): paid search advertising on deepfake/NCII-related keywords carries real platform-policy risk (ad platforms are cautious around adult-content-adjacent and abuse-related keywords, and this product must avoid ever appearing to associate itself with the harmful content it fights). The strongest available channels are partnership/referral routes through nonprofits already trusted in this space (CCRI's 24/7 hotline has supported 32,000+ people; Chayn itself; RAINN), SEO content around "TAKE IT DOWN Act next steps," and legal-aid/domestic-violence-advocate referral networks. All of these are real but slower-building and more relationship-dependent than a typical paid-acquisition SMB funnel, which is why this scores below the compliance-SaaS lanes elsewhere in this portfolio.
  • Agent advantage (4): the core loop, continuously re-scanning the web and known platforms for matches to a reported image/deepfake, tracking a 48-hour countdown per platform, auto-assembling an FTC complaint packet from structured case data, is squarely the kind of always-on, tedious, deadline-tracking work an agent pipeline does better and cheaper than a human checking manually. Not a 5 because the underlying image-matching/re-upload-detection technology (perceptual hashing plus reverse-image and face-search techniques) is a genuine engineering lift with real false-positive/false-negative risk that downstream research and feasibility must scope carefully, not a trivial wrapper.
  • Low-volume economics (4): subscription SaaS with no per-case marginal cost beyond compute for scanning and API calls to reverse-image/face-search providers; no human case managers required at low volume (unlike Ceartas's "WIPO-certified account manager" tiers). Not a 5 because ongoing image/video scanning against face-search APIs carries a real, scaling COGS line that must be modeled before assuming SaaS-grade margins hold at volume.
  • Operator hand lightness (3): this product touches genuinely sensitive personal content (intimate imagery, sexual abuse material) and a vulnerable user base. It requires careful handling from day one: never storing the actual images/videos unless absolutely necessary for hash-matching, clear non-legal-advice disclaimers, and a defensible policy on how uploaded reference material is stored, encrypted, and deleted. This is meaningfully heavier than a typical SMB compliance tool's "operator hand," hence a 3, not higher.
  • Market trend (4): the regulatory window is freshly opened (May 2026) and enforcement is visibly ramping (FTC warning letters within days of the deadline, a new complaint portal live now), a rising, not saturated, signal. Not a 5 because the Act's ultimate enforcement teeth and whether the FTC actually pursues cases at volume remain to be seen over the next 12 months, a real, if likely favorable, outcome uncertainty.
  • Policy redline (3, not 5): this space sits directly adjacent to some of the most sensitive content categories that exist (nonconsensual intimate imagery, sexual abuse material, and by definition proximity to CSAM risk if any reported case involves a minor). The product must have a hard, non-negotiable policy to immediately refuse service and refer to CCRI/NCMEC/law enforcement for any case involving a minor, must never store or process the actual explicit image/video files beyond what a privacy-preserving hash-matching architecture strictly requires, and must carry an unambiguous "not legal advice, does not guarantee removal or any legal outcome" disclaimer throughout (the same discipline the Chayn/Ceartas comparables already practice). None of this is a hard blocker. The core service (monitoring plus procedural/administrative assistance, not legal representation) is legal and already has direct free and paid comparables operating in the US today, but the redline-management burden is real enough that this cannot score a 5.

Notes for downstream stages

  • Key assumption to stress-test first: how reliably re-upload/mirror-site detection can actually work for altered/composited deepfake images and videos, as opposed to exact-file hash matching (which StopNCII already does well). Standard reverse-image search is documented as unreliable once a face is composited onto a different body; research must scope whether a face-search API (several exist per the assets evidence) can be used compliantly and cost-effectively at consumer subscription price points, or whether the honest MVP is closer to "hash-match known files plus scheduled re-search of victim-supplied identifying details" rather than true always-on autonomous web crawling.
  • Competitor/comparable leads for research: Chayn's Survivor AI (free, one-time letter generator: the floor this product must clearly exceed, not duplicate); Ceartas (paid, $69-1,200/month, professional-creator-only: the ceiling/anchor for pricing a "does more" product, but a different buyer segment); StopNCII.org (free, hash-matching, participating-platforms-only, Meta-backed: check partnership feasibility rather than treating as pure competition); reverse-image/face-search API vendors as a build-vs-buy question for the core detection engine.
  • Redline/compliance notes: mandatory zero-tolerance policy and workflow for any case appearing to involve a minor (immediate stop, referral to NCMEC/CCRI/law enforcement, no further processing); must not store raw explicit media beyond the minimum required for a privacy-preserving hash-matching pipeline (research should evaluate whether an on-device or client-side hashing approach, similar to StopNCII's model, can avoid the company ever holding the actual files); must carry a prominent "not legal advice, does not guarantee removal" disclaimer on every generated document and every dashboard screen; must verify state-by-state and federal rules on operating any tool that touches CSAM-adjacent content categories before writing a single line of code, ideally with dedicated legal counsel experienced in this specific space (this is a heavier compliance lift than a typical SMB SaaS and should be budgeted for explicitly in feasibility).

assets/ evidence list

  • evidence.md: full raw source list covering (1) the TAKE IT DOWN Act's May 19, 2026 compliance deadline and the FTC's enforcement rollout including the new TakeItDown.ftc.gov complaint portal, (2) direct-fetch findings on Chayn's Survivor AI and Ceartas confirming the specific product gap (monitoring/escalation layer, non-creator consumer segment), (3) documented technical limits of reverse image search against deepfakes plus a named re-upload/mirror-site victim anecdote, (4) multiple independent 2026 victim-scale surveys, (5) adjacent-category pricing benchmarks (identity-theft-monitoring subscriptions, Ceartas tiers), and (6) explicitly flagged "not obtained" items (direct victim forum/review text, exact US-specific victim count, names of the 12 FTC-warned nudify companies) excluded from claims rather than fabricated.