AI that ships.
Software everyone can use.
Fixed-price engagements for government, healthcare, and regulated industries.
What you receive
Fixed price
Section 508 Audit + ACR
$9,500
- ACR / VPAT 2.5
- procurement-ready
- Findings report
- evidence per item
- Remediation roadmap
- mapped to your codebase
- Findings briefing
- coordinator and system owner
Scope and price agreed before work starts. Every finding is verified by a human before it reaches you.
Two-week engagement
See full scopeTrusted Tester
DHS certified, 2026
508 / WCAG
Mobile and web accessibility
10+
Years in the founder's engineering career
SDB
Small disadvantaged business
NNMXAM3K7U25
UEI · CAGE 18UT2
Two practices, one standard of proof
Both ship fixed-price. Every finding is verified by a human before it reaches you.
Practice 01
Accessibility Engineering
Section 508 and WCAG conformance for native iOS, Android, and web, by an engineer who fixes the code rather than a tester who hands you a spreadsheet. The people on the other end are veterans checking benefits and patients booking care.
- VoiceOver and TalkBack testing on real devices
- ACR/VPAT authoring for procurement
- Testing by a DHS Certified Trusted Tester
- ADA Title II, HHS 504, and EAA compliance
Practice 02
AI Delivery
Evaluation baselines built from your own records, then production agents that ship when they pass that baseline rather than when a demo looks good. Built on the systems you already run.
- Client-owned evaluation harnesses
- Audit trails and human approval gates
- Legacy rescue and migration
- HIPAA-aware governance for healthcare
Live demonstration
What a screen reader announces
A benefits claim form has five stops in its focus order. Step through them and read what VoiceOver says at each one. This is the layer that automated scanners cannot check and that we test by hand on real devices.
VoiceOver announces
Step through the focus order to hear what is announced at each stop.
5 stops in this form
Mobile and Cross-Platform
Ship accessible iOS and Android apps, native or cross-platform. One codebase where that fits, native where it does not, accessibility built in from the first screen.
- React Native and Flutter (iOS and Android)
- Native Android (Kotlin, Jetpack Compose)
- Native iOS (Swift, SwiftUI)
- CI/CD and release automation
Web Applications
Build web applications designed against Section 508 and WCAG. React, Next.js, and TypeScript, with keyboard and screen reader support designed in, not retrofitted.
- React, Next.js, TypeScript
- Node.js, Spring Boot backends
- Enterprise portals and dashboards
Technical Advisory
Architecture reviews and technical due diligence for acquisitions.
- Architecture audit and review
- Technical due diligence
- Team training and mentorship
Fixed-Price Offers
Fixed scope and fixed price, agreed before work starts. AI-accelerated analysis, every finding verified by a human before it reaches you. Audit prices are per application or system; portfolio, multi-system, and program-scale work is priced to scope.
| Offer | Scope | Term | Fixed price | Document |
|---|---|---|---|---|
| FederalSection 508 Audit + ACR | Section 508 conformance assessment of one system, priced below the federal micro-purchase threshold. Fixed two-week engagement, tested by a DHS Certified Trusted Tester.
| fixed, purchase-card eligible | $9,500 | Full scope and deliverables |
| MobileMobile App Accessibility Audit | WCAG 2.1 AA conformance audit of one mobile app (native iOS/Android, React Native, or Flutter) by a DHS Certified Trusted Tester who builds mobile apps. Covers ADA Title II, Section 508, HHS Section 504, and the European Accessibility Act.
| fixed, per app | $7,500 to $15,000 | Full scope and deliverables |
| WebWeb Accessibility Audit + VPAT | Manual audit plus automated sweep of one web application, with an Accessibility Conformance Report written for procurement review.
| fixed, per application | $5,000 to $10,000 | Full scope and deliverables |
| AIAI Delivery Readiness Assessment | A fixed-scope assessment of how AI can work in your software delivery: modernization candidates, ranked agent and automation use cases, and the governance to do it safely.
| fixed | $5,000 to $10,000 | Full scope and deliverables |
| AIAI Evaluation Baseline | Measure whether your AI works before it touches production. A golden evaluation dataset built from your own historical data, a repeatable eval harness you own, and a report on what passes, what fails, and why.
| fixed | $5,000 to $12,000 | Full scope and deliverables |
| AIAgent Deployment Sprint | One workflow, one production AI agent, built on the systems you already run. Ships when it passes your evaluation baseline, not when a demo looks good. No migrations, no rip-and-replace.
| fixed | $25,000 to $50,000 | Full scope and deliverables |
Section 508 Audit + ACR
- Category
- Federal
- Price
- $9,500
- Term
- fixed, purchase-card eligible
Section 508 conformance assessment of one system, priced below the federal micro-purchase threshold. Fixed two-week engagement, tested by a DHS Certified Trusted Tester.
- No solicitation or proposal cycle required
- ACR (VPAT 2.5) for your 508 program office
- Findings briefing for coordinator and system owner
Mobile App Accessibility Audit
- Category
- Mobile
- Price
- $7,500 to $15,000
- Term
- fixed, per app
WCAG 2.1 AA conformance audit of one mobile app (native iOS/Android, React Native, or Flutter) by a DHS Certified Trusted Tester who builds mobile apps. Covers ADA Title II, Section 508, HHS Section 504, and the European Accessibility Act.
- VoiceOver and TalkBack manual testing
- Procurement-ready ACR/VPAT
- Remediation roadmap mapped to your codebase
Web Accessibility Audit + VPAT
- Category
- Web
- Price
- $5,000 to $10,000
- Term
- fixed, per application
Manual audit plus automated sweep of one web application, with an Accessibility Conformance Report written for procurement review.
- Keyboard, screen reader, focus, contrast, ARIA
- ACR/VPAT plus EN 301 549 addendum available
- Per-page remediation menu ($250 to $450/page)
AI Delivery Readiness Assessment
- Category
- AI
- Price
- $5,000 to $10,000
- Term
- fixed
A fixed-scope assessment of how AI can work in your software delivery: modernization candidates, ranked agent and automation use cases, and the governance to do it safely.
- System and codebase review (read-only access)
- Governance baseline, HIPAA-aware for healthcare
- Fixed-price implementation roadmap
AI Evaluation Baseline
- Category
- AI
- Price
- $5,000 to $12,000
- Term
- fixed
Measure whether your AI works before it touches production. A golden evaluation dataset built from your own historical data, a repeatable eval harness you own, and a report on what passes, what fails, and why.
- Client-owned evaluation harness, rerunnable on every model change
- Failure taxonomy and model cost right-sizing
- Go/no-go call per workflow
Agent Deployment Sprint
- Category
- AI
- Price
- $25,000 to $50,000
- Term
- fixed
One workflow, one production AI agent, built on the systems you already run. Ships when it passes your evaluation baseline, not when a demo looks good. No migrations, no rip-and-replace.
- Audit trail and human approval gates on every action
- Shadow mode to supervised autonomy to production
- Handover package: docs, runbooks, eval harness
Small business · Self-certified SDB · SAM.gov registered · UEI NNMXAM3K7U25 · CAGE 18UT2 · NAICS 541511 / 541512 / 541519 · Book a call
Findings we closed, and proved closed
Two things on this page a buyer can check without taking our word for it: an assessment run end to end and verified shut, and this site’s own conformance.
Case study
Agentic Systems Security Assessment
- Exploit payloads blocked on re-test
- 14 / 14Exploit payloads blocked on re-test
- Endpoint authentication tests pass
- 8 / 8Endpoint authentication tests pass
- Socket authentication tests pass
- 5 / 5Socket authentication tests pass
- Independent breaks in the exploit chain
- 4Independent breaks in the exploit chain
Eight assessment domains applied to a production AI agent holding shell access, device control, and a live credential store. Eleven findings, a six-step exploit chain, and a remediation sequenced by dependency. Each finding was closed by re-running the original attack and watching it fail, not by reading a configuration file.
The subject was our own production agent. We hold the methodology to our own systems before we point it at a client’s.
Read the full assessmentThis site
Held to the standard we sell
Accessibility engineering is our core service, so lotusinnovations.io is tested the way a client system is. Automated axe-core testing runs on every deploy, with manual keyboard and screen reader review on a periodic full-site pass.
0
axe-core violations on the last deploy. Automated testing only
How an engagement runs
Two practices, two shapes of work, one starting point. Both begin with a scoping call and a number you can take to your finance team before anything else happens.
Accessibility engagement
Fixed two-week clock, fixed deliverable
Week 0
Scoping call
You tell us the system. We come back with a fixed scope and a fixed price.
Week 1
Testing
Manual VoiceOver and TalkBack passes on real devices, plus an automated sweep.
Week 2
ACR / VPAT
Procurement-ready conformance report, every finding verified by a human.
After
Remediation
A roadmap mapped to your codebase, or we fix it, priced per page or per screen.
AI engagement
Phased to the workflow, gated on your own evaluation baseline
Phase 0
Scoping call
Same starting point. One workflow, named, with a fixed scope and a fixed price.
Phase 1
Baseline
A golden evaluation set built from your own historical records, and the harness that reruns it. You own both.
Phase 2
Build
The agent, on the systems you already run, with an audit trail and a human approval gate on every action.
Phase 3
Shadow to production
Shadow mode, then supervised autonomy, then production. It ships when it passes your baseline, not when a demo looks good.
Public Sector Experience
Before founding Lotus, the founder built and shipped software for federal and state government agencies across a 10+ year career. These are prior-career engagements, not Lotus client engagements.
Key personnel experience
- Federal Reserve Bank
- Enterprise systems integration
- Department of Transportation (PHMSA)
- Portal modernization
- Office of Personnel Management
- System integration
- State of Hawaii DHS
- Benefits portal development
- City of Oakland
- Citizen services platform
- RTD Denver
- Transit systems integration
Capabilities
Section 508 / WCAG Engineering
Audits, remediation, ACR/VPAT; testing by a DHS Certified Trusted Tester
Portal Modernization
Legacy portal migration, responsive redesign
System Integration
Enterprise middleware, API development
Compliance-Ready
Experience with government security requirements
- NAICS codes
- 541511, 541512, 541519
- Business type
- Small Business, Self-Certified SDB
- UEI / CAGE
- NNMXAM3K7U25 / 18UT2
About Lotus Innovations
Lotus Innovations is a California-based small business specializing in digital accessibility engineering for mobile and web, delivered by the founder, an engineer who builds mobile software rather than a tester running checklists.
Accessibility testing and remediation is the weakest area of Section 508 implementation across the federal enterprise (GSA FY2025 assessment). We close that gap where it is hardest, inside native iOS, Android, React Native, and Flutter apps, at the code level. The people on the other end are veterans checking benefits, patients booking care, and residents applying for services on a phone.
Our second practice modernizes legacy systems and builds production AI delivery capability for healthcare, government, and regulated industries, where compliance and reliability are non-negotiable.
California-based small business
Self-certified SDB
Book a call
Tell us which app or system you need audited or built. We come back with a fixed scope and a fixed price.
- Phone
- (818) 648-6791