Professional Systems
Active development

TradeMind MX

A Mexico-focused customs review system that turns supported pedimento XML into traceable data, deterministic signals, reports, and audit evidence.

Category
Professional Systems
Platform
Web
Status
Active development

What if every customs review signal remained connected to its source and interpretation?

Governed ingestion, versioned parsing, canonical customs records, explicit rules, durable processing, tenant isolation, and human review preserve the evidence chain from file to finding.

User value

Turn pedimento XML into traceable review evidence.

Move from selected Mexican customs records to normalized facts, explainable signals, and exportable evidence without treating software output as a legal conclusion.

01

Preserve the source trail

Retain source bytes, checksums, parser versions, transformations, validation outcomes, and field provenance with the customs record.

02

Surface explicit review signals

Evaluate canonical data through constrained, versioned rules that identify the rule, context, and bounded evidence behind each finding.

03

Give people a reviewable output

Inspect runs and findings in the browser, render the current HTML report, and download an audit packet for further assessment.

Synthetic TradeFlow Advisory dashboard showing a completed analysis, finding counts, an estimated duty signal, HS concentration, and broker risk summaries.View full size
Synthetic white-label analysis dashboardThe values and entities shown are deterministic demo data, not customer results.

Features

A governed path from intake to review signal.

The current system connects protected workspaces, source lifecycle controls, customs normalization, deterministic analysis, and export.

  1. 01

    Secure document intake

    Accept individual, bounded archive, API, and SFTP-backed submissions with validation, malware quarantine, duplicate detection, provenance, retention, and legal holds.

  2. 02

    Versioned pedimento parsing

    Convert supported XML into canonical pedimento and line-item records while preserving decimal, date, missing, blank, invalid, and zero semantics.

  3. 03

    Customs data history

    Represent declaration families, versions, rectification relationships, effective views, controlled reprocessing, and evidence-derived official status.

  4. 04

    Constrained rule engine

    Run five versioned baseline rules without arbitrary supplied code, hidden network behavior, or authoritative binary floating-point calculations.

  5. 05

    Workspace and tenant controls

    Apply secure sessions, passkey MFA, roles, machine identities, support controls, audit events, and PostgreSQL row-level tenant isolation.

  6. 06

    Bilingual white-label workspace

    Use English or Spanish interface copy and configure product identity, support text, report copy, and selected capabilities for each tenant.

How it works

Receive, normalize, evaluate, review.

Each stage adds context while keeping the route back to the submitted source visible.

  1. 01

    Enter an authorized workspace

    Sign in, complete configured MFA, and select the importer or tenant context before accessing data.

  2. 02

    Submit supported records

    Upload pedimento XML or use an implemented machine intake path and follow durable processing status.

  3. 03

    Govern the source lifecycle

    Validate, quarantine, scan, store, deduplicate, retain, hold, or delete source material through explicit states.

  4. 04

    Build canonical customs records

    Parse supported fields, validate the domain model, connect declaration history, and preserve provenance.

  5. 05

    Run deterministic checks

    Evaluate a versioned ruleset against the importer-scoped population and store attributed findings.

  6. 06

    Inspect and export

    Review the run, findings, summaries, HTML report, and current audit packet before qualified human disposition.

In practice

The current browser journey uses synthetic evidence.

Synthetic TradeFlow Advisory dashboard before analysis with importer, tenant branding, operations, and empty signal cards.View full size

Start with importer context

The dashboard shows the active importer, tenant configuration, operations access, and empty analysis states before processing.

Synthetic uploads register showing many parsed pedimento XML fixtures and two malformed fixtures marked failed.View full size

Follow processing outcomes

The upload register distinguishes parsed records from deliberately malformed synthetic fixtures that reached a failed state.

Synthetic TradeMind MX analysis page showing one completed run, three findings, an audit-packet action, and an embedded report.View full size

Inspect findings and report

A completed run exposes finding counts, named signals, report viewing, and the current audit-packet download path.

Product concept

Evidence before assertion.

TradeMind MX treats customs review as a chain of source, interpretation, rule context, finding, and human responsibility.

01

A parsed value needs provenance

Normalized customs data remains connected to source bytes, transformation versions, validation, and field or relationship evidence.

02

A signal is not a legal conclusion

Deterministic rules identify conditions for qualified review without replacing regulated professional judgment.

03

Reproducibility is part of the result

Durable jobs, versioned parsers, rule identity, context attribution, and governed source state make repeated review inspectable.

Architecture

A modular application with durable workers and tenant boundaries.

The React browser uses a FastAPI service. PostgreSQL remains authoritative for business data and job state while workers process governed source objects through explicit stages.

  1. 01Authorized browser or machine intake
  2. 02Governed source object and durable job
  3. 03Validation and malware quarantine
  4. 04Versioned parser and canonical customs data
  5. 05Deterministic rule evaluation and findings
  6. 06Browser review, HTML report, or audit packet

PostgreSQL holds durable authority

Redis delivers work hints while database jobs record claims, heartbeats, retries, recovery, and material completion state.

Source bytes stay governed

Provider-neutral object storage uses opaque keys, quarantine eligibility, retention, legal holds, tombstones, and controlled physical purge.

Tenant access is enforced below the interface

Central authorization and PostgreSQL row-level security scope workspace data even when API or worker paths change.

Rules remain constrained

Typed context, stable rule versions, bounded evidence, and execution limits support repeatable analysis without arbitrary code or an opaque model.

Technology

Built for traceability and controlled operation.

Application

  • Python
  • TypeScript
  • FastAPI
  • React
  • Vite
  • SQLAlchemy

Data and files

  • PostgreSQL
  • Alembic
  • Provider-neutral object storage
  • Local and S3-compatible adapters

Background work

  • RQ
  • Redis delivery
  • PostgreSQL durable jobs
  • Separately scalable workers

Security and operations

  • Passkey MFA
  • Row-level security
  • ClamAV
  • Prometheus
  • Grafana
  • SFTP adapter

Analysis model

  • Versioned parser contract
  • Canonical customs records
  • Constrained deterministic rules
  • Provenance-aware findings

Development

The evidence and analysis foundations are implemented.

Four foundation phases are accepted and Phase 5 has begun with the declarative rules engine. Rule governance, human finding workflows, campaigns, immutable reports, and later customs workflows remain incomplete.

Stage
Active development
Accepted foundations
Phases 1 through 4
Baseline engine
5 versioned rules
Production status
Not confirmed

Implemented foundations

  • Authenticated React and FastAPI application for workspaces, dashboards, uploads, pedimentos, analysis, settings, security, and operations
  • Secure identity, roles, machine access, controlled support, durable audit, PostgreSQL isolation, and separately scalable workers
  • Governed individual, archive, API, and SFTP intake with quarantine, duplicate detection, provenance, retention, legal holds, and deletion
  • Versioned pedimento parser contract, canonical customs data, validation, declaration history, rectification, reprocessing, and provenance-aware APIs
  • Constrained deterministic engine with five baseline rules, stable identities, ruleset membership, bounded evidence, and analysis-context attribution
  • Dashboard signals, current HTML report, audit packet ZIP, bilingual copy, white-label configuration, synthetic fixtures, and recorded automated validation

Next product layer

Complete proposal, approval, effective-date, release, activation, and rollback governance for rules. Then add human finding disposition, evidence, cases, campaigns, historical reevaluation, persisted report artifacts, integrity manifests, independent benchmark review, and final security, accessibility, legal, and domain qualification.