A marketplace builder that assumes the sale, a review widget that mines the reviewer, or a compliance tool that audits a business it can't become. This is the fourth option.
Independent data domains live as separate database schemas whose roles hold zero grants across the wall. A cross-domain foreign key doesn't get caught in code review — it fails at apply time. The advertising side is severed from behaviour by construction: the roles that write analytics have no read access to review or vote data.
So no targeting pipeline can ever be wired to your users' behaviour — not even by a future developer who wants to. That is the sentence no marketplace builder, review widget, or compliance tool can say.
Everything about your category is configuration. The enforcement underneath never changes.
A new deployment is a vocabulary map, a vendor binding, and a ruleset — not a rebuild.
Written as configuration from day one — the white-label seam was never retrofitted.
The isolation wall is the moat.
Every operator in a restricted category fears the same thing: behavioural data read as ad-targeting fuel, and the whole business sunk under platform or regulatory review.
Cross-domain joins fail at apply time, not at code review
Sensitive domains are separate schemas whose roles hold zero grants across the wall. The database refuses the join — which means the guarantee survives staff turnover, deadline pressure, and every future developer.
Behaviour cannot become an ad-targeting pipeline
The roles that write and roll up analytics have no read access to review or vote data. The severance is structural, so "we don't target on behaviour" is a fact about the schema rather than a policy commitment.
Compliance is proven on every change, not claimed once
Four regression suites run as required status checks: the grant audit, the conflict-of-interest trigger, the projection test, and the structural guard. A merge that breaks any guarantee is blocked. This is what holds up the day an acquirer's diligence team asks to watch a breach attempt fail.
No transaction on the platform — which is why it stays listed
Discovery and review without the sale is the listable path in a restricted category. Marketplace builders assume the transaction, which is the single thing that gets a restricted-category app removed.
Three categories, three structural failures.
No wall, and they assume the sale lives on-platform
Fast, cheap, brandable — and structurally wrong here. Sensitive domains share one database by default, and their whole model is facilitating the transaction that gets a restricted-category app rejected.
They collect reviews to feed conversion, not to protect the reviewer
The review is a marketing asset wired straight into behavioural targeting — the exact inverse of a category where linking a person to their opinion is the liability. No anonymous-plus-verified model, no minimum-N gate.
They help you prove you're compliant — they aren't the product you run
They map internal controls to audit frameworks and sit beside your business. They cannot make compliance a structural property of the app you ship. Complements, not competitors.
Any category where behavioural data is a liability, not an asset.
Anonymous opinion, verified businesses, and a transaction that legally or practically cannot happen on-platform.
Cannabis product & dispensary discovery
The live reference build. Incumbents have already trained operators to pay four-figure monthly platform rent — and the state-by-state ruleset is a configuration swap.
Firearms & ammunition reviews
Platform policy forbids the transaction, so a discovery-and-review layer with no sale is the listable path incumbents structurally can't offer.
Alcohol & DTC spirits discovery
The age gate and no-transaction posture transfer directly; only the verification vendor changes.
Gambling-adjacent review
Discovery without the wager — in a category where behavioural targeting is exactly the exposure the wall answers.
Telehealth & sensitive-service directories
The anonymous-reviewer / verified-provider split is the whole proposition where the subject matter is private by nature.
The scoping audit reads your regulatory ruleset, tests verification-vendor feasibility, and gives you a pre-submission store-policy read — before anyone commits to a build.
The method is part of what you're buying.
Regulatory-ruleset review
Your category's rules become configuration — reviewed and signed off before any code is written.
Vendor & store-policy read
Verification-vendor feasibility and a pre-submission policy read on the promotions surface — the closest call in any restricted category.
Fixed scope, fixed fee
The quote from scoping is the price. One deployable unit per change, every decision recorded.
A diligence-ready paper trail
The same discipline that keeps you oriented during the build is the record an acquirer's diligence expects to find afterwards.
Three stages, one sequence. Start at the first.
Only the scoping fee is charged today — and it is credited in full toward your build if you proceed.
Scoping engagement
A go/no-go feasibility verdict and a fixed build quote. Standalone value if you walk.
Scoping + full build
The finished, compliance-enforced, store-listable network — yours outright.
Charges the $3,500 scoping fee and holds your build slot.
Build + retainer
Keeping the compliance guarantee true — not "hosting and bug fixes".
Get the AI Project Scoping Kit.
The first step we take with every client is scoping the problem before touching the build. We've packaged that step as the AI Project Scoping Kit — a working system you can run yourself, useful even if you never hire us.
Get the Scoping Kit — $49A scoping conversation takes thirty minutes: your category, your vendors, your store-policy exposure.
Book thirty minutes