TECH SPECS

How TRAX is built

For the people who sign off on platforms: architecture, data, security, integrations and support.

01

Platform architecture

Application
Next.js 14 (App Router, server components) — every page that touches your data renders on the server.
Hosting
Vercel — global edge network, automatic HTTPS, preview deployments for every change.
Database
Supabase Postgres — relational data with foreign keys, check constraints and database-enforced rules.
File storage
Supabase Storage — private buckets only; files move through one-time signed upload links and short-lived signed download links.
Audio engine
Tone.js on the Web Audio API — voice effects, the Mobile Creation Studio and offline rendering (bounces, stems) run on your device.
Transcription
The browser's Web Speech API, on the device, optional per capture.
Planning + maps
React Flow (project flowcharts) and Leaflet with OpenStreetMap tiles (calendar map).
Offline + install
An installable web app (PWA): Quick Capture queues on the device while offline and uploads when you reconnect.
02

Data & storage

Encryption
In transit over TLS everywhere; at rest by the database and storage providers.
Isolation
Row-level security is on for every TRAX table with no client access at all — the browser never talks to the database; every read and write goes through server code that checks who you are and what your role allows.
Files
Audio, images and video live in private buckets. Download links last minutes, not days. Captures up to 50 MB; message attachments up to 25 MB; branding logos up to 1 MB.
History
Project history is append-only and hash-chained: entries can't be edited or deleted — even by us — and the chain can be verified at any time.
Retention
Your data stays until you delete it. Ended trials keep their workspace for 30 days.
Export
Project history as CSV or JSON; captures and bounces as their original files; mobile sketches as WAV bounces and stems ZIPs; sample packs as files.
03

Security

Sign-in
Signed, httpOnly session cookies scoped to TRAX (separate from any other app on the domain). Passwords are hashed with scrypt; admin-issued passphrases must be changed at first sign-in.
Roles
Per-project roles and ten permissions (audio, comments, metadata, splits, approvals, money, licensing, team, uploads) decide what each collaborator sees — sensitive history entries included.
Admin oversight
Admin actions (view-as, logins issued or revoked, pricing, trials, conversation views) are written to an audit log. View-as is read-only: every change is refused.
Abuse protection
Failed sign-ins are slowed down; uploads are checked in storage for owner, size and type before they're accepted; public links (packets, sends, trials) are unguessable and single-purpose.
Email
TRAX sends no email today — delivery happens through drafts in your own mail app, so no third-party mail provider sees your data.
04

Integrations

Today
Your phone's microphone and camera (captures), your mail app (drafts), calendar map tiles (OpenStreetMap).
Roadmap (concept)
Card billing, transactional email, reference-track discovery from public music catalogues, and sample-marketplace partnerships — announced as each is ready.
White Label
Your brand across the whole platform (name, logo, colours, fonts) and a custom domain on the White Label plan.
05

Browser support

Desktop
Current Chrome, Edge, Safari and Firefox.
Android
Current Chrome — the best mobile recording experience (lowest audio latency).
iPhone + iPad
Safari on iOS 16 or newer. Audio starts after a first tap (an iOS rule); recording latency is higher and is compensated automatically.
Install
Add TRAX to your home screen on any of the above; it opens full-screen like an app.
06

Data ownership

Your music and your records are yours. You own every idea, recording, split, contract and number you put into TRAX; we hold them only to run the service for you. We don’t sell your data, we don’t use your audio to train AI models, and you can export everything, any time — leaving is never harder than staying.

Read the full promise, in plain English →

Questions from your security team? Contact us · Privacy · Terms · White Label agreement