Strategy — Positioning
- Date: 2026-04-16
- Status: Proposed (post-research revision)
- Update (2026-07-04, ADR-0168): multi-vertical + progressively-agentic assistance — grounded guided flows, bounded and hand-off-first — is now a first-class direction (the “v2” this doc anticipated). The compliance-first v1 discipline below stands unchanged. Moat + future-proofing:
moat.md.
Why this document exists
Section titled “Why this document exists”Market research (2026-04-16) surfaced a category-defining problem: “RAG chat over your docs” is being absorbed into hyperscaler bundles (ChatGPT Business Company Knowledge, Google Agentspace, Notion AI) and commoditized by OSS alternatives (Onyx, ex-Danswer — MIT, 40+ connectors, deployable in 30 min). Any generic KM+AI SaaS launching in 2026 without a defensible wedge is DOA within 18 months.
Puccha’s wedge is not “better RAG.” It is regulatory fit + Thai localization + compliance deliverables that a self-hosted Onyx can’t produce and a US hyperscaler can’t localize.
One-line positioning
Section titled “One-line positioning”Puccha is the compliance knowledge worker for PDPA/BOT/SEC/OIC-regulated Thai enterprises — Thai-first, audit-ready, and delivered with a Thai-language SI partner.
Wedge (why customers pick Puccha over alternatives)
Section titled “Wedge (why customers pick Puccha over alternatives)”| Alternative | Why they lose to Puccha (for our ICP) |
|---|---|
| Onyx / self-hosted OSS | Requires in-house ML/infra team + 6-month cert program; no Thai SCC templates; no DPO deliverable; no Thai-trained embeddings; no Thai-language support contract |
| ChatGPT Business Company Knowledge | US processor, no Thai SCC addendum, no PDPA 72h-breach SLA, no Thai UI/support, no role-gated ACL, $25–30/seat × 50 seats = ฿40k/mo — more expensive than Puccha Business |
| Google Agentspace / Gemini Enterprise | Tied to Workspace seat, $25–45/seat, generic retrieval, no compliance deliverables, no Thai partner channel |
| Notion AI | AI bundled but retrieval is weak, no per-doc ACL gates, no PDPA posture, Notion content only (Thai enterprises use Word/PDF/SharePoint) |
| Glean | 100-seat minimum, ~$50–60k ACV floor, enterprise sales cycle, no Thai presence, no PDPA DPO deliverable |
| Credal.ai / Dust.tt | US/EU-centric, no Thai SCCs, no Thai language, no local support |
| Amity Solutions | Horizontal GenAI + chatbot focus, not compliance-KM; adjacent not direct |
Puccha does not win on “better retrieval” or “cheaper tokens.” It wins on “the Thai compliance officer can point at Puccha in her SEC / BOT / OIC / PDPC audit and it satisfies the controls.”
Messaging pillars (v1)
Section titled “Messaging pillars (v1)”Pillar 1 — Audit-ready by design
Section titled “Pillar 1 — Audit-ready by design”Every feature serves a documented regulatory control:
- BOT FPG 19/2599 (outsourced IT, ISO 27001-aligned) → Puccha ships ISO 27001 SoA + annual surveillance evidence pack
- SEC Chapter 2 (data + app security, IAM) → per-doc ACL + audit log export + SSO
- OIC IT-risk framework (72h cyber-incident reporting) → tenant-facing 72h breach SLA, Thai SCC addendum included
- PDPA §28/29 (cross-border transfer) → Thai-overlay SCCs with Anthropic, data-residency toggle (Anthropic EU region or AWS ap-southeast-1)
- HA accreditation (private hospitals) → patient-data-aware ACL guardrails, DPO deliverable included
Pillar 2 — Thai-first, not Thai-translated
Section titled “Pillar 2 — Thai-first, not Thai-translated”- UI default language: Thai. English is a toggle.
- Thai-tuned retrieval (PyThaiNLP
newmm+ bge-m3 multilingual + contextual retrieval). - Thai-native contract (ฉบับภาษาไทย), invoice, WHT certificate flow.
- Thai-speaking support with SLA.
- Sources cited in the asker’s locale; bilingual doc cross-links.
Pillar 3 — Delivered by a Thai SI channel, not shipped over a website
Section titled “Pillar 3 — Delivered by a Thai SI channel, not shipped over a website”Self-serve exists for top-of-funnel (Free tier). The paid motion is consultative, delivered by Certogo directly and by named channel partners (G-Able tier-1, Big-4 tier-2, depa-listed provider tier-3). We sell outcomes, not software.
Pillar 4 — Compliance deliverables, not just a product
Section titled “Pillar 4 — Compliance deliverables, not just a product”Every paid tier includes artifacts a compliance officer can put in an audit binder:
- DPA with Thai SCC overlay (Section 29 safeguards, 72h breach notification).
- DPO appointment support (Certogo-backed if customer has no DPO).
- Evidence package: ISO 27001 SoA, SOC 2 Type II report (once achieved), penetration-test summary, uptime SLA attestation.
- Policy templates pre-seeded for PDPA, information security, acceptable use — customers can immediately ask their own KB “what’s our data-retention policy?” and get a grounded answer pulling from the Puccha-seeded policies.
Anti-positioning (what we actively are NOT)
Section titled “Anti-positioning (what we actively are NOT)”- ❌ Not a ChatGPT alternative. We do not train models; we do not play in the generic chat arena.
- ❌ Not a Notion replacement. We import from wherever content lives; we don’t try to host authoring.
- ❌ Not an autonomous agent platform. Our agents are grounded and bounded — they answer and run guided flows over your own KM, cite every fact, and hand off to a human at the edge of their knowledge or authority. They never act unsupervised, and they never bluff. (Grounded guided flows are the v2 depth layer — ADR-0168/0169.)
- ❌ Not a dev-docs tool. Kapa/Mintlify own that. Our users are compliance officers, policy owners, and ops managers — not engineers.
- ❌ Not “AI for everything.” We are explicitly a regulated-industry knowledge-and-compliance product and say so in every piece of marketing.
Competitive response playbook
Section titled “Competitive response playbook”If a prospect says: “We’re evaluating ChatGPT Business.” → Ask: “Who is your Thai sub-processor DPA counterparty? What’s your 72h PDPC breach notification path? Can your compliance officer point at ChatGPT controls in your next SEC / BOT / OIC audit?” Hand them the Puccha Audit Pack.
If a prospect says: “We’re considering self-hosting Onyx.” → Agree that Onyx is excellent tech. Ask: “Who owns the Thai SCC addendum with your LLM provider? Who appoints your DPO? Who owns the 72h-breach runbook and the annual ISO 27001 surveillance audit of the retrieval pipeline? If that’s an extra 1.5 FTE for you — that’s exactly what Puccha replaces.”
If a prospect says: “Amity Solutions already pitched us.” → Acknowledge Amity’s scale. Position: Amity is horizontal GenAI + chatbot. Puccha is compliance knowledge. Different buyer (compliance officer vs marketing/CX), different audit fit.
If a prospect says: “Your pricing is high vs Notion.” → Reframe: Notion is a collaboration tool with bundled AI. Puccha is a compliance deliverable with bundled software. Compare to OneTrust or TrustArc, not Notion.
Product choices that follow from positioning
Section titled “Product choices that follow from positioning”- Regulatory-template library (v1.0): PDPA, ISO 27001 Annex A, BOT FPG 19, SEC Chapter 2, OIC IT-risk, HA accreditation prompts — customers can seed their KB from these templates in one click.
- Audit export (v1.0): one-click export of “everything relevant to an audit” — access logs, ACL snapshots, DPA references, incident history.
- DPO workbench (v1.1): cross-tenant dashboard for DPOs managing multiple entities (many Thai corporates have shared DPO services).
- Sovereignty toggle (v1.1): route retrieval & generation via Anthropic EU region or AWS Bedrock ap-southeast-1 Claude for customers that require non-US processing.
- No features that dilute the positioning: agentic depth is limited to grounded guided flows (answer → draft → hand off); still no code-gen, no marketing-copy generation, and no ungrounded “AI for everything.”
Metrics that validate the positioning
Section titled “Metrics that validate the positioning”- ≥ 70% of paid tenants are in Insurance / FSI / Healthcare / regulated SEC-listed industries (rather than generic tech or marketing use cases).
- ≥ 50% of tenants cite “audit readiness” or “PDPA compliance” in their reason-to-buy survey.
- Win rate against Onyx in deals where both are evaluated: ≥ 60%.
- Churn on compliance-driven accounts after first audit cycle: ≤ 5% annually.
If these numbers don’t land within 12 months, the positioning is wrong, not the execution.