← All white-label solutions
White-label solution 03 Isolation-enforced two-sided network Reference build feature-complete

The Restricted-Category Review Network — where the data can't be joined.

Anonymous reviewers, verified businesses, and no transaction on the platform — with the sensitive data domains held apart in the database rather than in a policy. It clears store review, and your business owns it outright.

Schema isolation Anonymous + verified identity CI-enforced compliance No on-platform transaction You own the instance
Grant-audit
Live permissions asserted against a checked-in manifest
Conflict-of-interest
Enforced at the API and again by database triggers
Projection
Analytics payloads carry no user or session identifier
Structural guard
"Precise location: not collected" true by construction
Four regression suites run as required status checks — a merge is blocked if any fails
The thesis in one sentence

A marketplace builder that assumes the sale, a review widget that mines the reviewer, or a compliance tool that audits a business it can't become. This is the fourth option.

Independent data domains live as separate database schemas whose roles hold zero grants across the wall. A cross-domain foreign key doesn't get caught in code review — it fails at apply time. The advertising side is severed from behaviour by construction: the roles that write analytics have no read access to review or vote data.

So no targeting pipeline can ever be wired to your users' behaviour — not even by a future developer who wants to. That is the sentence no marketplace builder, review widget, or compliance tool can say.

What you get

Everything about your category is configuration. The enforcement underneath never changes.

Yours — configured at scoping
The reviewed object — a SKU, a provider, a listing
Your vocabulary and review dimensions
The verification vendor — age, licence, KYC, credential
Your regulatory warning strings and ruleset
Your branding, end to end

A new deployment is a vocabulary map, a vendor binding, and a ruleset — not a rebuild.

The system — built, tested on every commit
The two-domain isolation engine
Anonymous-plus-verified identity model
Structured review corpus with minimum-N aggregation gating
Moderation queues and business-approval chain
Conflict-of-interest enforcement, API and database

Written as configuration from day one — the white-label seam was never retrofitted.

Why it holds up

The isolation wall is the moat.

Every operator in a restricted category fears the same thing: behavioural data read as ad-targeting fuel, and the whole business sunk under platform or regulatory review.

Cross-domain joins fail at apply time, not at code review

Sensitive domains are separate schemas whose roles hold zero grants across the wall. The database refuses the join — which means the guarantee survives staff turnover, deadline pressure, and every future developer.

Behaviour cannot become an ad-targeting pipeline

The roles that write and roll up analytics have no read access to review or vote data. The severance is structural, so "we don't target on behaviour" is a fact about the schema rather than a policy commitment.

Compliance is proven on every change, not claimed once

Four regression suites run as required status checks: the grant audit, the conflict-of-interest trigger, the projection test, and the structural guard. A merge that breaks any guarantee is blocked. This is what holds up the day an acquirer's diligence team asks to watch a breach attempt fail.

No transaction on the platform — which is why it stays listed

Discovery and review without the sale is the listable path in a restricted category. Marketplace builders assume the transaction, which is the single thing that gets a restricted-category app removed.

How incumbents fail this market

Three categories, three structural failures.

Marketplace & community builders

No wall, and they assume the sale lives on-platform

Fast, cheap, brandable — and structurally wrong here. Sensitive domains share one database by default, and their whole model is facilitating the transaction that gets a restricted-category app rejected.

Answered by: the isolation wall and the no-transaction posture that make the app listable at all.
Review-widget & reputation SaaS

They collect reviews to feed conversion, not to protect the reviewer

The review is a marketing asset wired straight into behavioural targeting — the exact inverse of a category where linking a person to their opinion is the liability. No anonymous-plus-verified model, no minimum-N gate.

Answered by: a structured corpus provably severed from targeting, anonymity enforced in the schema.
Compliance-automation software

They help you prove you're compliant — they aren't the product you run

They map internal controls to audit frameworks and sit beside your business. They cannot make compliance a structural property of the app you ship. Complements, not competitors.

Answered by: compliance in the schema and the CI suite as the foundation, not an audit layer bolted alongside.
Where it fits

Any category where behavioural data is a liability, not an asset.

Anonymous opinion, verified businesses, and a transaction that legally or practically cannot happen on-platform.

The proven origin — highest ceiling

Cannabis product & dispensary discovery

The live reference build. Incumbents have already trained operators to pay four-figure monthly platform rent — and the state-by-state ruleset is a configuration swap.

Multi-state operators · cannabis media
Nearest adjacent fit

Firearms & ammunition reviews

Platform policy forbids the transaction, so a discovery-and-review layer with no sale is the listable path incumbents structurally can't offer.

Retailers · enthusiast media
Vendor binding is the only swap

Alcohol & DTC spirits discovery

The age gate and no-transaction posture transfer directly; only the verification vendor changes.

Craft producers · drinks media
Behavioural data is radioactive

Gambling-adjacent review

Discovery without the wager — in a category where behavioural targeting is exactly the exposure the wall answers.

Sportsbook-adjacent media · affiliates
Operator-blind posture is the value

Telehealth & sensitive-service directories

The anonymous-reviewer / verified-provider split is the whole proposition where the subject matter is private by nature.

Provider networks · patient-advocacy orgs
Not sure yours qualifies?

The scoping audit reads your regulatory ruleset, tests verification-vendor feasibility, and gives you a pre-submission store-policy read — before anyone commits to a build.

See the scoping tier
How the engagement runs

The method is part of what you're buying.

01 — Identify

Regulatory-ruleset review

Your category's rules become configuration — reviewed and signed off before any code is written.

02 — Investigate

Vendor & store-policy read

Verification-vendor feasibility and a pre-submission policy read on the promotions surface — the closest call in any restricted category.

03 — Intervene

Fixed scope, fixed fee

The quote from scoping is the price. One deployable unit per change, every decision recorded.

04 — Document

A diligence-ready paper trail

The same discipline that keeps you oriented during the build is the record an acquirer's diligence expects to find afterwards.

Purchase a deployment

Three stages, one sequence. Start at the first.

Only the scoping fee is charged today — and it is credited in full toward your build if you proceed.

Tier 01

Scoping engagement

A go/no-go feasibility verdict and a fixed build quote. Standalone value if you walk.

$3,500 fixed
Regulatory-ruleset review for your category and states
Verification-vendor feasibility — age, licence, KYC, credential
Pre-submission store-policy read on the promotions surface
Vocabulary and reviewed-object mapping
Credited in full toward the build
Tier 02
Most chosen

Scoping + full build

The finished, compliance-enforced, store-listable network — yours outright.

from $12,000
Fixed-quoted at scoping, against your ruleset and vendor requirements.
Everything in Tier 01
Your branded instance — consumer app, business side, moderation console
The isolation wall and analytics severance, configured to your domains
Verification-vendor binding and regulatory warning strings
The four CI compliance suites, wired to your repository
Thirty-day handover warranty — defects, including any architectural-guarantee regression, fixed at no charge from the day of transfer
Reserve a build — start scoping

Charges the $3,500 scoping fee and holds your build slot.

Tier 03

Build + retainer

Keeping the compliance guarantee true — not "hosting and bug fixes".

$750 / mo and up
Indexed to category, to $2,000/mo for multi-state and gambling-adjacent operators. Build priced as Tier 02.
Everything in Tier 02
Hosting on your infrastructure or ours
CI compliance suites kept green against changing regulations
Verification-vendor and store-policy maintenance
Ruleset updates as your category or footprint changes
Payment is processed by Stripe. Verification-vendor and payment-processor fees are category-specific and external: they are passed through as a separate line with a handling margin, quoted after the feasibility audit — never absorbed silently into the build or retainer.
Secure checkout · Stripe
Not ready to buy yet

Get the AI Project Scoping Kit.

The first step we take with every client is scoping the problem before touching the build. We've packaged that step as the AI Project Scoping Kit — a working system you can run yourself, useful even if you never hire us.

Get the Scoping Kit — $49
Prefer to talk it through?

A scoping conversation takes thirty minutes: your category, your vendors, your store-policy exposure.

Book thirty minutes