Choose which optional cookies and similar storage we may use. Strictly necessary storage is always on, because the site cannot work without it.

Draft: awaiting the Clinical Safety Officer's review before publication

Startup DNA: run lean, build your pipeline and prepare for audit

Run your startup with a small team from day one: AI agents for the routine work, a marketing pipeline built around the questions your buyers ask, and the controls and records a large customer will ask to see.

We map your work and give the routine parts to AI agents, each with one job and a named person in charge. We build a marketing pipeline that puts what you know in front of your buyers and tracks every enquiry. We help you put in place the controls and records that security reviews, NHS buyers and insurers ask for. And we can be your fractional CTO while you grow. It is built for health and insurtech startups first, and we also work with startups in other regulated sectors. Health startups can build on Gateway Global's infrastructure, with our Clinical Safety Officer supporting their clinical risk management.

Last updated

What is Startup DNA?

A way of running a company with a small team, in three parts that work together. We set it up in your company, hand it over, and can run it for you. Startup DNA is the operating method we use at Gateway Global, adapted for your company.

  1. Run lean

    A lean operations plan, your handbook, and your first agents running.

  2. Marketing pipelines

    Your question map, your first pages, and a pipeline from first enquiry to signed customer, tracked in your CRM.

  3. Audit readiness

    A readiness plan, the policies and controls in place, and an evidence pack you can share with buyers.

01 Run lean

How can a small team run a whole company?

By deciding which work needs a person and which does not, then giving the routine work to software and AI agents with clear rules. People keep the judgement: customers, money, hiring, and every clinical or regulated decision.

  • A map of your work. Each recurring task, who owns it, how often it happens and what it costs, so you can see what to automate first and what to leave alone.
  • Agents with one job each. Enquiries, scheduling, document intake, invoice and receipt processing for your accountant, and IT requests, each handled by an agent that logs what it did and hands over to a named person at the points you set. How we keep agents in control
  • Processes written down once. A short operating handbook for how you sell, deliver, invoice, handle a complaint and release software, so a new colleague and an agent follow the same steps.
  • One source for your company facts. Company details, product claims and prices kept in one place that your website, proposals and agents all read from, so they stay consistent.
  • Costs you can see. Fewer tools, each with an owner, and cloud, AI and software costs reviewed every month.
  • Hiring when it counts. Help deciding which work needs a person, and when to hire for it.

You get A lean operations plan, your handbook, and your first agents running.

02 Marketing pipelines

How do you build a marketing pipeline around your buyers' questions?

Start from the questions your buyers ask, answer each one plainly on your own site, and connect every enquiry to a CRM that shows where it came from and what happens next.

  • Who you sell to, and what they ask. Your buyers, the problem you solve, and the questions they put to search engines and AI assistants, each mapped to one page.
  • A content engine with a person in charge. An agent drafts from your approved facts and your team's expertise, and a person approves every piece before it is published. Marketing content agent
  • Pages that search engines and AI assistants can read. Fast pages, the same content for people and for crawlers, structured data that matches what each page shows, and a regular check of how AI assistants describe you. AI search visibility agent
  • Enquiries that go somewhere. Forms, calls and chat routed to the right person, qualified against rules you set, and recorded in your CRM with their source. Lead qualification agent
  • A CRM you can rely on. Duplicates merged, missing details flagged, and a pipeline report that shows each stage. CRM data quality agent
  • Marketing checks built in. The right basis for each email, call and text under PECR and UK GDPR, with consent where the law needs it and screening against the TPS and CTPS for calls; telling people when they are talking to an AI; and only claims you hold evidence for. Your data protection lead and legal advisers sign the rules off.

You get Your question map, your first pages, and a pipeline from first enquiry to signed customer, tracked in your CRM.

Nobody can promise a ranking, a place in an AI answer or a number of leads, and we do not. We report what happens and change what does not work.

Our own website is built this way: pages written to answer a buyer's question first, company facts kept in one register, and automated checks that stop a release if it uses a fact that has not been approved.

03 Audit readiness

What does preparing for audit mean?

It means we help you put in place, and keep current, the controls, policies and records that a buyer or an auditor checks, so most of the evidence is ready before someone asks for it. It does not mean certified: certificates come from independent certification bodies, SOC 2 reports from independent auditors, and approvals from regulators and buyers.

  • The basics buyers check. Firewalls, secure settings, controlled access with multi-factor sign-in, malware protection and prompt security updates: the five Cyber Essentials controls, which central government requires on in-scope contracts and NHS buyers may ask for.
  • The technical side of data protection. A map of the personal data your systems hold and why, technical input to your data protection impact assessments, and retention rules built into your systems. Your data protection lead and legal advisers own the privacy notice and your contracts with processors.
  • Security management that fits your size. Readiness for ISO/IEC 27001 for UK and European buyers, or for a SOC 2 examination for US buyers, set up so one set of records serves both where the controls overlap.
  • AI you can account for. Telling people when they are dealing with an AI, measures that build AI literacy in your team, and readiness for the EU AI Act and ISO/IEC 42001 where they apply. EU AI Act readiness
  • Security built into your software. Secure development, checks on the code you depend on, and preparation for your penetration test.
  • Answers written once. A trust page and a security questionnaire pack covering security, privacy and AI, so you answer the next questionnaire from records you already hold, and keep them current with each release.

You get A readiness plan, the policies and controls in place, and an evidence pack you can share with buyers.

Building for healthcare or insurers?

Both check a supplier closely before they sign. We help you prepare what each one asks for.

Healthcare

Health startups can build on Gateway Global's infrastructure, with our Clinical Safety Officer supporting their clinical risk management.

  • Clinical safety from the first sprint, with the hazard log kept up to date as the product is built.
  • Help preparing the evidence NHS buyers ask for: DTAC, the Data Security and Protection Toolkit and Cyber Essentials.
  • Early work on whether your product is likely to be a medical device, with your regulatory advisers making the call.

Who is responsible for what

You remain the manufacturer of your product, and our contract with you sets out who does what. Our Clinical Safety Officer reviews your safety case; that review is not a certificate that the product is safe.

Approval decisions stay with regulators and buyers, and we work alongside your legal advisers rather than giving legal advice.

Insurers and health payers

Insurers check security, where data is held, resilience, exit plans and how customers are treated. We help you prepare those answers before your first procurement call.

  • The security review insurers run: ISO/IEC 27001 or SOC 2 readiness, preparation for your penetration test, and a completed questionnaire pack.
  • The contract questions regulated buyers ask: audit rights, service levels, help during an incident, where data is held, and an exit plan. DORA requires EU insurers to include terms like these in their ICT contracts, with more of them when the service supports a critical or important function. We prepare the technical side, and your legal advisers own the contract.
  • Agents in claims and service that work within limits you set, with a named person at each decision that matters.

How it works

Clear steps, each with a fixed scope, so you know what you get before you commit. Stop after any step.

  1. Startup DNA call

    Thirty minutes with an engineer about what you are building, for whom, and where.

    Free

  2. Startup DNA check

    How you run, your marketing pipeline, and your security and data protection, reviewed against what your buyers will ask, with a 90-day plan.

    Fixed fee

  3. Build sprints

    A fixed scope, built in short sprints you can see and steer. Our team, yours or both.

    Fixed price per sprint

  4. Run

    We host, monitor, support and improve what we built or set up, keep your agents in check, and keep your evidence current as you grow.

    Monthly

Running an accelerator, a fund or a free zone? We offer a Startup DNA check for each company in your cohort, with scorecards you can compare, and code review with Gateway Assay before demo day. Talk to us about your programme

Why Gateway Global

  • We have launched a health product. Prime Assist. Launched publicly on 16 May 2025 at Dentistry Show UK, NEC Birmingham. In trials with UK private dental practices and a multi-site private GP group.
  • Clinicians and engineers in one team. Health products are designed with clinical safety from the start.
  • Omid Arbab, our founder. Technology entrepreneur since 2014; his first company grew into a Microsoft partner.
  • Written evidence to the House of Lords. In 2026 Gateway Global submitted written evidence (reference PMA0121) to the House of Lords Science and Technology Committee on why UK small businesses find it hard to deploy technology into the NHS.
  • Our own technology. Gateway Global has filed three UK patent applications.

Questions people ask

What is Startup DNA?

It is how we set up a startup to run with a small team: lean operations with AI agents, a marketing pipeline built around your buyers' questions, and the controls and records buyers check.

Can a small team with AI agents really run a company?

For routine, rule-based work, often yes, with a person checking what matters. Agents make mistakes that are hard to predict, so each one has a named owner, a log of what it did and a point where it hands over. Judgement, relationships, and clinical and regulated decisions stay with people.

Can you promise us leads, or a place in AI answers?

No. Nobody controls how search engines and AI assistants rank and cite pages. We build pages that crawlers can read and that answer your buyers' questions, and we report what happens.

Will you make our product compliant?

We make it ready for audit and prepare the technical evidence. Certificates and approvals come from independent auditors, notified bodies, regulators and buyers. We work alongside your legal advisers rather than giving legal advice.

Do we own what you set up?

Your data, your accounts and the agents we set up sit in your own systems, and you keep them if you stop working with us. Our own products and tools are licensed to you, and our contract sets out who owns what.

Can you help us raise money?

We can help you prepare. FinPlan helps you build your financial plan and prepare the documents investors ask for. Gateway Assay (beta) reviews your code before investors do, so you can fix what it finds first. FinPlan helps you plan and prepare. It is not regulated financial or investment advice, and we do not arrange investment. Your accountant and legal advisers stay responsible for your accounts, tax and any offer of shares.

Can you build our product too?

Our focus is how your company runs. If you also need your product built, we can talk about it on your Startup DNA call, and our build sprints work beside your own developers.

Is Startup DNA only for startups?

No. It is built around what young companies need, and growing companies can use the same advice, team and products.

Who is responsible for a health product built on your infrastructure?

You remain the manufacturer of your product, and our contract with you sets out who does what. Our Clinical Safety Officer supports your clinical risk management and reviews the safety case. That review is not a certificate that the product is safe.

Where do you work?

We are based in London, and we plan for the rules in the UK, the EU, the US and the UAE.

How is it priced?

The first call is free. After that, each step has a fixed scope and a fixed fee, agreed before it starts, and running your product is a monthly service. Products are priced per product, by subscription or licence.

Tell us how your startup runs today.