01The distinction

Evidence is judged by someone who was not there.

A system that produces the right answer but cannot show how it got there has failed the job.

In an unregulated workflow, software is judged on whether the work gets done. In a regulated one it is judged again months later, by an inspector, an auditor, a customer disputing an invoice, or a colleague inheriting the file. That changes the build. Permissions become part of the data model rather than a UI concern. Calculations record their inputs and their version alongside their output. Documents are generated from the record instead of assembled by hand afterwards. None of this retrofits cheaply, which is why it belongs in the first architecture conversation.

02Where it applies

Different regulators create the same structural problem.

Roles, evidence, and a record that holds up without its author in the room. Three operating shapes hit that hardest.

Regulated cultivation

Cannabis and produce facilities operating under state, provincial, and federal track-and-trace, where every plant movement, batch, and destruction event has to reconcile with a regulator’s system.

Marine survey & certification

Draft surveys and cargo certificates that decide what a customer is invoiced. The number has to be reproducible from the recorded readings months after the vessel has sailed.

Multi-entity regulated services

Case management across several legal entities under one roof, where an applicant’s file, its documents, and its history must stay separated by entity and defensible on review.

03What goes into the build

Access, audit trail, and evidence belong in the first migration.

Each of these is an engineering decision with a cost. Each costs several times more after launch than before it.

  • 01Roles and permissions that mean something. Trazo OS runs nine operational roles with more than 50 distinct permissions, enforced on every endpoint rather than by hiding buttons in the interface.
  • 02Controlled data, isolated at the database. A live audit of Trazo OS confirmed row-level security enabled on 117 of 117 tables — tenant separation the application layer cannot accidentally leak.
  • 03Audit trails as a first-class record. Who entered a reading, who changed it, who approved it, and what the values were at each point — recorded as data, not reconstructed from logs.
  • 04Evidence generated by the system. The marine survey platform issues branded, signed PDF survey certificates and daily production reports straight from the same records the calculation used.
  • 05Controlled access, not open signup. Public signup disabled, the first administrator bootstrapped by an operator, and every account traceable to a person.

04Compliance integrations

Risk concentrates where your system meets the regulator’s.

Compliance APIs are the least forgiving integrations in operational software: strict schemas, per-jurisdiction differences, and a regulator on the other end.

Trazo OS — built by Aptixx under contract for Trazo Global Inc. — carries a 60,000-line Metrc compliance integration module configured for 26 US jurisdictions, alongside a separate Health Canada CTLS module. Signed Metrc API agreements are held in multiple states.

Configured for 26 US jurisdictions. One Metrc integration module of roughly 60,000 lines carries the rules, endpoints, and payload contracts for each jurisdiction, with signed Metrc API agreements held in multiple states.

The same platform runs a sensor telemetry and alarm pipeline on 11 scheduled jobs, which is the other half of regulated multi-site work: the conditions a facility has to prove it maintained, captured continuously rather than recalled at inspection time.

Counts verified in August 2026 against the codebase and a live database audit.

05Discovery

Ambiguity costs less on paper than in production.

In regulated builds the risk sits in discovery, and the way out is a specification precise enough for a compliance officer and an engineer to sign the same page.

Discovery on regulated work quotes the governing rule next to the requirement it creates, then takes that requirement down to the exact field that will satisfy it. Every question settled there is a question that does not become a change order once the build is running.

That work happens in a paid discovery sprint, which also produces the integration plan, the prototype, and the scoped build definition.

See what a discovery sprint delivers →

Fixed fee, agreed before the sprint starts and credited toward the build. The specification is yours to keep whether or not Aptixx builds the system.

06Proof

The controls above are running in production today.

Trazo OS enforces permissions on every endpoint and isolates tenants at the database; the marine survey platform ships role-aware access with public signup disabled. Both generate their documents straight from the record.

If your regulated work happens on vessels, docks, or sites rather than in an office, start with field and marine operations software. For the underlying approach, see how Aptixx builds operational software.

Next step

Bring the audit, the inspection, or the certificate in dispute.

Twenty minutes on the record you have to defend: where the evidence gap sits, what closing it involves, and whether Aptixx is the right firm for it.