Fixed checks. Clear limits.

Reports describe what is present, absent, inconsistent, changed, or not independently verified. They do not assess product safety or quality.

Published standardv1.0DatedApril 30, 2026Stamped onEvery reviewed outputDeterminationNone, signals only

Six fixed checks run on every packet.

What is checked

A mechanical, repeatable process, so two reviewers reach the same record and an inspector can follow it.

Document inventory

COA, batch specificity, lab name, method, sterility/endotoxin fields, business identity, and address fields.

Lot numbers, product identity, purity claims, test dates, lab references, PDF metadata, and repeated document signals.

Public claim audit

Quantitative claims, verifiability claims, identity claims, undefined terms, health-related claims, and disclaimers.

Changes to entity names, addresses, purity figures, COA links, lab references, and body-related language.

Duplicate signal indexing

Repeated hashes, visual fingerprints, lot values, lab/purity patterns, and verification links inside the user's saved archive.

Profile counts summarize documentation observations across saved reports, snapshots, corrections, and watchlist activity.

01

What runs before a person sees anything.

The same run on every document, in the same order, with nothing an operator can set. Six checks describe what is looked for; this is what produces the material they are applied to.

Bytes in hand.

A SHA-256 of the file contents is taken. That hash is the document's identity for the rest of its life: it keys the read cache, it is stored on the check record as fileHash, and it is what the reuse index compares.

02

Three ways a read lands.

A band records how much of a complete certificate is actually present. It only ever tightens, so nothing that read partial can later become clean, and an unresolved high-severity finding can never sit inside a complete band.

Whichever door it came through: dropped on the quality desk, filed by the supplier on a request link, or posted to the API. All three land on the same read.

Hash the bytes, pull the embedded text, and read the page itself when there is not enough of it. The transcription is keyed on the file hash plus the model plus the prompt hash and runs at temperature 0, so the same bytes give the same answer twice and a changed prompt re-reads the document rather than serving the previous reader's answer.

One of these bands

Score 80 or above, no required field absent, and no high-severity finding standing on the documentation.

A required field is not present, or the read is thin. Completeness is recorded field by field, so the record names which fields were not detected rather than rolling the gap into a single number.

band: partial | sparse | undocumented

Too little was recovered from the file to form a record: not enough text, no structured rows, and no product with a quantitative result. Nothing is scored and no findings are raised. The record says the file could not be read and asks for a sharper one, because those fields were not absent, they were not extracted.

Reading a document establishes what the document says. It does not establish that the document is genuine, that the lab issued it, or anything about the medicine it describes.

A material change requires a new version.

Every reviewed output stamps the methodology version it was produced under. Material changes require a new methodology version, noted publicly.

Accountable for the methodology

What is checked, and the public sources it is checked against, are published. The detection heuristics themselves are not, because publishing them would help fraudulent documents evade them and because they change faster than any page.

How findings are graded

Fixed checks. Clear limits.

Every observation lands in one of four buckets.

No subjective or paid ranking, no vendor scoring, and no certification of product quality. The one place results carry an order is the public network directory, and the grade that sets it is published below.

Match

The sources that state the value agree, and the reviewed materials reconcile.

Written as a source-backed observation: value A appears in source E1, value B appears in source E2, and the reviewed materials do not reconcile.

Missing documentation

The value is not present in reviewed material, so the record says it was not detected instead of filling the gap from assumptions.

The value is present but nothing reviewed settles it. The record states what Veritura did not independently verify.

Completeness is recorded field by field: COA, lot, lab, method, purity, MS and sequence evidence, sterility, endotoxin, strength, address, and disclaimer language. Presence or absence is recorded mechanically.

Record posture

These are separate axes. A reconciliation bucket is not a posture, and a posture describes the paperwork, not the medicine.

Every item also carries where it came from, so an inspector sees what was actually verified and what was attested.

Evidence origin: Veritura evaluated
Read from the document itself or from a public source.
Evidence origin: Operator attested
The operator confirms what Veritura cannot read.
Evidence origin: Source-confirmed
A recorded lab reply is the only thing that flips a document to source-confirmed.
Evidence origin: Human-reviewed
A delivered written diligence memo that received human QA before delivery.

A result is a documentation posture of Clear, Review, or Hold on the document set. A ClearGate decision of Allow, Review, or Hold is a separate axis, resolving one order against the policy you configure. Both describe the paperwork, not the medicine.

Absence of a public match is not proof of absence. A missing document is not a failed test. A similarity indicator is not a fraud determination.

How the directory is ordered

One published grade sets the order. Nothing else does.

The public network directory is the only surface on which results carry an order. It is set by the documentation-coverage grade below, which is objective, disclosed, and cannot be bought.

Unverified

Nothing has been read yet. Not listed in the public directory.

Veritura read the submitted COA and supporting documents for completeness and consistency. Not listed in the public directory.

01

FDA-source matched

The above, plus the FDA registration matched a weekly FDA source excerpt and a published credential exists. This is the floor for appearing in the directory at all.

02

Full lab panel attested

The above, plus a current, accredited, multi-vial panel the source attested: identity, purity, endotoxin, heavy metals, and microbial, on three or more vials. Attested by the source and cross-checkable where the named lab publishes a portal. Veritura runs no test of its own.

Missing data
A missing element never rounds up. An element that was not supplied leaves the rung it would have earned unearned, and a source below the FDA-source-matched rung is not listed.
Freshness
The registration match is against the weekly FDA source excerpt, and the lab rung requires a current panel. Every listed profile carries the date it was checked.
What money buys
The review itself, and nothing else. There is no listing fee, no placement fee, no subscription that moves a position, and no way to pay for a rung.

The grade orders documentation evidence and nothing else. It is not a preference, a recommendation, a quality or safety judgment, a certification, or a statement that any listed source is better than any other. Order is not endorsement, and a buyer must still run its own qualification.

How Veritura turns documents into observations.

Each check records what the materials show, what they do not show, and what Veritura did not independently verify.

The checks are driven by versioned context rules, not freeform guesses.

Reference data defines expected fields by context, claim categories, method signals, freshness bands, and report thresholds.

A human controls the language on delivered memos.

What ships as a written deliverable passes a person first. What does not is labelled as automated, and claims no sign-off.

Automated extraction and archive signals are treated as draft review prompts.

Where a person enters the record.

On the document path a person enters at three points. What a person states is recorded as attested, with who and when, and reading the document behind an attestation still never verifies the practice behind it.

A certificate arrives by upload, by supplier request link, or on the API.

The file is accepted as bytes. Anything over 8 MB is refused before any work is done.

A lab is named on the document.

A confirmation email to the issuing lab is drafted and the request is stamped on the record.

The lab answers and the account holder records the reply.

The recorded reply enters the state machine. Confirmed is the only path to confirmed:true. Not issued and mismatch are loud: a maximum-severity flag, a retest recommendation, and a supplier.alert webhook, because they cannot be settled on paper.

The check reads documentation for completeness, consistency, reuse and tamper signals. It never declares a document fake, and it cannot establish provenance unless the issuing lab records its own reply.

Human review controls final language for paid pharmacy and partner deliverables.

Source custody

Records preserve file identity, source IDs, visible fields, evidence rows, and limits.

No supplier approval, product certification, legal advice, medical guidance, or purchase steering.

AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.

Each Veritura deliverable must be understandable in under sixty seconds.

A buyer should not need to decode a dashboard or read a wall of text. The standard forces every output into a clean operating artifact with a verdict, evidence map, evidence replay, risk boundary, next action, and export package.

Executive verdict

The operator can state the record posture without caveat hunting.

Every material claim points to a source file, row, field, or explicit limitation.

Evidence replay

The artifact shows how intake, extraction, reconciliation, QA, release, and archive state produced the decision.

The artifact excludes product approval, safety, legal, medical, and purchase language.

Next action

The client knows exactly what to ask, hold, route, review, or release next.

The record can be forwarded, archived, audited, or attached to a workspace.

If any gate is missing, the output stays in review instead of pretending to be enterprise-ready.

PDFs, memos, and customer proof must be reproducible from source records. Every deliverable points back to the reviewed packet, source inventory, limitations, and human QA posture.

No Veritura output ships as customer-safe until the verdict, evidence map, replay path, boundary language, next action, and export package are present and consistent with the source record.

Gate 06, the export package

The record that leaves the workspace.

The document set met the configured policy. It describes the paperwork, not the medicine.

The issuing laboratory confirmed issuance through the recorded verification route.

Order
PO-DEMO-0413
Lot
LOT-7741-A
Supplier
Aurora Pharma Supply
Quantity
250 g
Received
July 22, 2026
Released
July 23, 2026
Passport issued
July 23, 2026
Methodology
v1.0 · April 30, 2026

Documents on file

COA-7741-A.pdf · Issuing laboratory confirmed issuance through the recorded route

CoC-7741.pdf · Required identity, lot, and date fields present

SDS-SEMA-04.pdf · Current revision on file

GMP-AUR-2026.pdf · Supplied by the operator

Recorded in workspace · Container and label checked at receipt

LBL-7741-A.jpg · Lot identifier matches the certificate of analysis

What this record does not establish

  • Documentation diligence only. No product was tested and no supplier was approved.
  • Absence of a public-source match is not proof of absence.
  • Produced under methodology v1.0, April 30, 2026.

Reports change when the evidence supports a change.

Nothing is silently rewritten, and nothing supported is removed because it is unwelcome.

Evidence-backed corrections can update factual records without rewriting the methodology trail.

What a correction re-runs.

A stored decision is signed when it is written, replayed against its own pinned snapshot when it is questioned, and answered by a corrected document rather than by an edit. The earlier record is never mutated; it stays in the log exactly as it was written.

A decision exists.

The decision is signed and hash-chained to the one before it, with the policy version pinned inside the record.

Someone questions a decision.

The stored evidence and the pinned policy snapshot are fed back through the same evaluator. A correct decision replays to the identical decision, label and reasons.

The check is saved.

The lot it describes is upserted and the release gate re-evaluates the whole document SET for that lot's subject and dosage form, not just the newest file. A single-panel certificate no longer clears a lot on its own; several certificates together can.

The lot's band describes the set. A thin contributor still blocks: a sparse or unreadable scrap does not become release evidence by sitting next to good paperwork.

Who can submit. Users, vendors, labs, or other relevant parties may submit factual corrections, supplemental documents, or responses tied to a report ID.

What we review. Correction requests are reviewed against the underlying source material and the methodology version used for the report.

What we do not remove. Veritura does not remove supported observations because they are unfavorable. Reports are corrected when a factual error or missing source is demonstrated.

Vendor responses. Where appropriate, a response or supplemental document may be attached to a report without changing the original observation.

Correction contact. Correction requests should include the report ID, the specific observation at issue, and the document or source that supports the correction. Send requests to Joey@veritura.co.

Reports document evidence. They do not certify products.

Reports are not safety assessments, quality assessments, legal determinations, or purchase recommendations. There is no paid or subjective placement; where results are ordered, they are ordered by the disclosed documentation-coverage grade published above.

The current standard documents operating controls, boundaries, and buyer-visible safeguards.

Not a safety assessment. Veritura does not determine whether any product is safe, sterile, effective, pure, legal, or appropriate for any use.

Not product testing. Reports are based on submitted documents, public pages, metadata, and snapshots. Veritura does not test physical material.

Authenticity limits. A report may identify metadata, repeated file signals, links, and inconsistencies. It cannot prove document provenance unless an issuing lab or source independently confirms it.

No purchase recommendation. Reports do not recommend, endorse, discourage, rank, or facilitate purchases from any vendor.

What you can inspect

01

The documents a serious buyer should be able to read.

Six documents are published alongside this one.

02

Supplier Packet Audit SOP

How packet review is performed.

How order, lot, COA, packet, reviewer, and customer proof connect.

01

Report Limitations

What Veritura can and cannot determine.

02

Security and Data Handling

Data minimization, headers, access boundaries, and current limitations.

How evidence-backed corrections are handled.

Privacy

How account and report data is handled.

See how the checks are phrased before you rely on a report.

Create a dashboard and follow a record end to end, or talk to us about covering your supplier base.