I don't know if there's a market for this, but I'd be interested in exploring it. You or your friend can get in touch with me, my email is in my profile.
I don't know either, but I've definitely seen software projects that had "538 compliance" as a requirement that people worked on, so it might come from that budget. My recollection is this was required for certain government sales.