Methodology v1.0
Fixed checks. Clear limits.
Reports describe what is present, absent, inconsistent, changed, or not independently verified. They do not assess product safety or quality.
- Published standard
- v1.0
- Dated
- Stamped on
- Every reviewed output
- Determination
- None, signals only
What is checked
Six fixed checks run on every packet.
A mechanical, repeatable process, so two reviewers reach the same record and an inspector can follow it.
01
Document inventory
COA, batch specificity, lab name, method, sterility/endotoxin fields, business identity, and address fields.
02
Internal consistency
Lot numbers, product identity, purity claims, test dates, lab references, PDF metadata, and repeated document signals.
03
Public claim audit
Quantitative claims, verifiability claims, identity claims, undefined terms, health-related claims, and disclaimers.
04
Historical change detection
Changes to entity names, addresses, purity figures, COA links, lab references, and body-related language.
05
Duplicate signal indexing
Repeated hashes, visual fingerprints, lot values, lab/purity patterns, and verification links inside the user's saved archive.
06
Vendor profile rollups
Profile counts summarize documentation observations across saved reports, snapshots, corrections, and watchlist activity.
What runs before a person sees anything.
The same run on every document, in the same order, with nothing an operator can set. Six checks describe what is looked for; this is what produces the material they are applied to.
- Engine
Bytes in hand.
A SHA-256 of the file contents is taken. That hash is the document's identity for the rest of its life: it keys the read cache, it is stored on the check record as fileHash, and it is what the reuse index compares.
Record state: Content hash recorded - Engine
A PDF or image whose embedded text is too thin to trust.
The page itself is read. The transcription is cached on file hash plus model plus prompt hash, so a changed prompt re-reads the document instead of serving the previous reader's answer, and the read runs at temperature 0 so the same bytes give the same answer.
180 second ceiling, measured rather than guessed: a multi-page certificate needed 82.4s and a 60s ceiling turned a readable document into a false unreadable.
Record state: Transcription available - Engine
Transcription or text layer available.
Structured rows, document links, QR values, PDF metadata, and text, structure and visual fingerprints are derived. The fingerprints are what later documents from the same source get compared against.
Record state: Extraction complete - Engine
Extraction complete.
The fields a complete certificate carries are read into rows: product, strength, lot, purity or assay, method, testing lab, report ID, date, sterility, endotoxin. A field the document does not state is printed as 'Not stated on the document', never guessed.
Record state: Read rows built - Engine
Read rows built.
The four lanes run and each returns one state with its reason. No lane may silently disappear.
Record state: Lane states recorded - Engine
Lanes complete.
A completeness band is computed. An unresolved high-severity finding can never sit inside a 'complete' band: the band only ever tightens, so nothing that read partial can become clean.
complete requires score 80 or above, no required field absent, and no high-severity finding.
Record state: complete | partial | sparse | undocumented
Three ways a read lands.
A band records how much of a complete certificate is actually present. It only ever tightens, so nothing that read partial can later become clean, and an unresolved high-severity finding can never sit inside a complete band.
What enters
One document
Whichever door it came through: dropped on the quality desk, filed by the supplier on a request link, or posted to the API. All three land on the same read.
What runs
The read
Hash the bytes, pull the embedded text, and read the page itself when there is not enough of it. The transcription is keyed on the file hash plus the model plus the prompt hash and runs at temperature 0, so the same bytes give the same answer twice and a changed prompt re-reads the document rather than serving the previous reader's answer.
One of these bands
- Record state: complete
Score 80 or above, no required field absent, and no high-severity finding standing on the documentation.
band: complete
- Record state: partial, sparse or undocumented
A required field is not present, or the read is thin. Completeness is recorded field by field, so the record names which fields were not detected rather than rolling the gap into a single number.
band: partial | sparse | undocumented
- Record state: unreadable
Too little was recovered from the file to form a record: not enough text, no structured rows, and no product with a quantitative result. Nothing is scored and no findings are raised. The record says the file could not be read and asks for a sharper one, because those fields were not absent, they were not extracted.
score: null
Reading a document establishes what the document says. It does not establish that the document is genuine, that the lab issued it, or anything about the medicine it describes.
Version control
A material change requires a new version.
Every reviewed output stamps the methodology version it was produced under. Material changes require a new methodology version, noted publicly.
Accountable
Joey Soto, founder
Accountable for the methodology
Published scope
What is checked, and the public sources it is checked against, are published. The detection heuristics themselves are not, because publishing them would help fraudulent documents evade them and because they change faster than any page.
How findings are graded
Every observation lands in one of four buckets.
No subjective or paid ranking, no vendor scoring, and no certification of product quality. The one place results carry an order is the public network directory, and the grade that sets it is published below.
Match
The sources that state the value agree, and the reviewed materials reconcile.
Mismatch
Written as a source-backed observation: value A appears in source E1, value B appears in source E2, and the reviewed materials do not reconcile.
Missing documentation
The value is not present in reviewed material, so the record says it was not detected instead of filling the gap from assumptions.
Could not verify
The value is present but nothing reviewed settles it. The record states what Veritura did not independently verify.
Completeness is recorded field by field: COA, lot, lab, method, purity, MS and sequence evidence, sterility, endotoxin, strength, address, and disclaimer language. Presence or absence is recorded mechanically.
Record posture
These are separate axes. A reconciliation bucket is not a posture, and a posture describes the paperwork, not the medicine.
Evidence origin
Every item also carries where it came from, so an inspector sees what was actually verified and what was attested.
- Evidence origin: Veritura evaluated
- Read from the document itself or from a public source.
- Evidence origin: Operator attested
- The operator confirms what Veritura cannot read.
- Evidence origin: Source-confirmed
- A recorded lab reply is the only thing that flips a document to source-confirmed.
- Evidence origin: Human-reviewed
- A delivered written diligence memo that received human QA before delivery.
Limitation
A result is a documentation posture of Clear, Review, or Hold on the document set. A ClearGate decision of Allow, Review, or Hold is a separate axis, resolving one order against the policy you configure. Both describe the paperwork, not the medicine.
Limitation
Absence of a public match is not proof of absence. A missing document is not a failed test. A similarity indicator is not a fraud determination.
How the directory is ordered
One published grade sets the order. Nothing else does.
The public network directory is the only surface on which results carry an order. It is set by the documentation-coverage grade below, which is objective, disclosed, and cannot be bought.
Unverified
Nothing has been read yet. Not listed in the public directory.
Documentation reviewed
Veritura read the submitted COA and supporting documents for completeness and consistency. Not listed in the public directory.
FDA-source matched
The above, plus the FDA registration matched a weekly FDA source excerpt and a published credential exists. This is the floor for appearing in the directory at all.
Full lab panel attested
The above, plus a current, accredited, multi-vial panel the source attested: identity, purity, endotoxin, heavy metals, and microbial, on three or more vials. Attested by the source and cross-checkable where the named lab publishes a portal. Veritura runs no test of its own.
- Tie handling
- Two sources on the same rung are ordered alphabetically by entity name. There is no second scoring pass and no editorial tie-break.
- Missing data
- A missing element never rounds up. An element that was not supplied leaves the rung it would have earned unearned, and a source below the FDA-source-matched rung is not listed.
- Freshness
- The registration match is against the weekly FDA source excerpt, and the lab rung requires a current panel. Every listed profile carries the date it was checked.
- What money buys
- The review itself, and nothing else. There is no listing fee, no placement fee, no subscription that moves a position, and no way to pay for a rung.
Boundary
The grade orders documentation evidence and nothing else. It is not a preference, a recommendation, a quality or safety judgment, a certification, or a statement that any listed source is better than any other. Order is not endorsement, and a buyer must still run its own qualification.
Worked examples
How Veritura turns documents into observations.
Each check records what the materials show, what they do not show, and what Veritura did not independently verify.
| Check | What the materials show | How the report phrases it |
|---|---|---|
| Example 01Lot mismatch | Product page lists Lot BPC240817. Uploaded COA lists Lot BPC240301. | Observation: the visible lot values do not match across reviewed materials. Veritura does not determine intent or product quality. |
| Example 02Purity reconciliation | Product page states 99%+. COA reports 98.7% by HPLC. | Observation: the public quantitative claim is not supported by the provided COA value. |
| Example 03PDF metadata gap | COA test date is August 22, 2024. PDF creation date is February 14, 2026. | Observation: the file was generated after the stated test date. This can have ordinary explanations; Veritura does not infer fabrication. |
| Example 04Duplicate signal | Same verification link appears in multiple saved reports for unrelated product records. | Observation: repeated archive signal detected. This is a review signal, not an authenticity conclusion. |
| Example 05Claim-risk category | Research-use disclaimer appears alongside body, performance, or therapeutic-style language. | Observation: claim category flagged. Veritura does not determine legal significance. |
Reference intelligence layer
The checks are driven by versioned context rules, not freeform guesses.
Reference data defines expected fields by context, claim categories, method signals, freshness bands, and report thresholds.
Human review
A human controls the language on delivered memos.
What ships as a written deliverable passes a person first. What does not is labelled as automated, and claims no sign-off.
Automated extraction and archive signals are treated as draft review prompts.
Where a person enters the record.
On the document path a person enters at three points. What a person states is recorded as attested, with who and when, and reading the document behind an attestation still never verifies the practice behind it.
- Operator
A certificate arrives by upload, by supplier request link, or on the API.
The file is accepted as bytes. Anything over 8 MB is refused before any work is done.
Record state: Bytes in hand - Operator
A lab is named on the document.
A confirmation email to the issuing lab is drafted and the request is stamped on the record.
Record state: Lab verification requested - Operator
The lab answers and the account holder records the reply.
The recorded reply enters the state machine. Confirmed is the only path to confirmed:true. Not issued and mismatch are loud: a maximum-severity flag, a retest recommendation, and a supplier.alert webhook, because they cannot be settled on paper.
Record state: source_confirmed | source_denied | source_mismatch | unconfirmed_no_response
The check reads documentation for completeness, consistency, reuse and tamper signals. It never declares a document fake, and it cannot establish provenance unless the issuing lab records its own reply.
Memo QA
Human review controls final language for paid pharmacy and partner deliverables.
Source custody
Records preserve file identity, source IDs, visible fields, evidence rows, and limits.
Boundary language
No supplier approval, product certification, legal advice, medical guidance, or purchase steering.
Boundary
AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.
Release gate
Each Veritura deliverable must be understandable in under sixty seconds.
A buyer should not need to decode a dashboard or read a wall of text. The standard forces every output into a clean operating artifact with a verdict, evidence map, evidence replay, risk boundary, next action, and export package.
Gate 01
Executive verdict
The operator can state the record posture without caveat hunting.
Gate 02
Evidence map
Every material claim points to a source file, row, field, or explicit limitation.
Gate 03
Evidence replay
The artifact shows how intake, extraction, reconciliation, QA, release, and archive state produced the decision.
Gate 04
Risk boundary
The artifact excludes product approval, safety, legal, medical, and purchase language.
Gate 05
Next action
The client knows exactly what to ask, hold, route, review, or release next.
Gate 06
Export package
The record can be forwarded, archived, audited, or attached to a workspace.
Internal release gate
Six gates required
If any gate is missing, the output stays in review instead of pretending to be enterprise-ready.
Evidence and export
PDFs, memos, and customer proof must be reproducible from source records. Every deliverable points back to the reviewed packet, source inventory, limitations, and human QA posture.
Acceptance standard
No Veritura output ships as customer-safe until the verdict, evidence map, replay path, boundary language, next action, and export package are present and consistent with the source record.
Gate 06, the export package
The record that leaves the workspace.
Evidence Passport
Semaglutide (base) API
Evidence posture
Evidence posture: ClearThe document set met the configured policy. It describes the paperwork, not the medicine.
Certificate of analysis
Source-confirmedThe issuing laboratory confirmed issuance through the recorded verification route.
- Order
- PO-DEMO-0413
- Lot
- LOT-7741-A
- Supplier
- Aurora Pharma Supply
- Quantity
- 250 g
- Received
- July 22, 2026
- Released
- July 23, 2026
- Passport issued
- July 23, 2026
- Methodology
- v1.0 · April 30, 2026
Documents on file
6
- Source-confirmed
Certificate of analysis
COA-7741-A.pdf · Issuing laboratory confirmed issuance through the recorded route
- Veritura evaluated
Certificate of conformance
CoC-7741.pdf · Required identity, lot, and date fields present
- Veritura evaluated
Safety data sheet
SDS-SEMA-04.pdf · Current revision on file
- Operator attested
GMP certificate
GMP-AUR-2026.pdf · Supplied by the operator
- Operator attested
Receiving inspection
Recorded in workspace · Container and label checked at receipt
- Veritura evaluated
Shipment label
LBL-7741-A.jpg · Lot identifier matches the certificate of analysis
What this record does not establish
- Documentation diligence only. No product was tested and no supplier was approved.
- Absence of a public-source match is not proof of absence.
- Produced under methodology v1.0, April 30, 2026.
Corrections
Reports change when the evidence supports a change.
Nothing is silently rewritten, and nothing supported is removed because it is unwelcome.
Evidence-backed corrections can update factual records without rewriting the methodology trail.
What a correction re-runs.
A stored decision is signed when it is written, replayed against its own pinned snapshot when it is questioned, and answered by a corrected document rather than by an edit. The earlier record is never mutated; it stays in the log exactly as it was written.
- Engine
A decision exists.
The decision is signed and hash-chained to the one before it, with the policy version pinned inside the record.
Record state: Signed decision on the chain - Operator
Someone questions a decision.
The stored evidence and the pinned policy snapshot are fed back through the same evaluator. A correct decision replays to the identical decision, label and reasons.
Record state: Replay matches, or the record was altered - Engine
The check is saved.
The lot it describes is upserted and the release gate re-evaluates the whole document SET for that lot's subject and dosage form, not just the newest file. A single-panel certificate no longer clears a lot on its own; several certificates together can.
The lot's band describes the set. A thin contributor still blocks: a sparse or unreadable scrap does not become release evidence by sitting next to good paperwork.
Record state: Lot state re-derived from the set
Boundary
Who can submit. Users, vendors, labs, or other relevant parties may submit factual corrections, supplemental documents, or responses tied to a report ID.
Boundary
What we review. Correction requests are reviewed against the underlying source material and the methodology version used for the report.
Boundary
What we do not remove. Veritura does not remove supported observations because they are unfavorable. Reports are corrected when a factual error or missing source is demonstrated.
Boundary
Vendor responses. Where appropriate, a response or supplemental document may be attached to a report without changing the original observation.
Boundary
Correction contact. Correction requests should include the report ID, the specific observation at issue, and the document or source that supports the correction. Send requests to Joey@veritura.co.
Limitations
Reports document evidence. They do not certify products.
Reports are not safety assessments, quality assessments, legal determinations, or purchase recommendations. There is no paid or subjective placement; where results are ordered, they are ordered by the disclosed documentation-coverage grade published above.
Current posture
Controlled and documented
The current standard documents operating controls, boundaries, and buyer-visible safeguards.
Limitation
Not a safety assessment. Veritura does not determine whether any product is safe, sterile, effective, pure, legal, or appropriate for any use.
Limitation
Not product testing. Reports are based on submitted documents, public pages, metadata, and snapshots. Veritura does not test physical material.
Limitation
Authenticity limits. A report may identify metadata, repeated file signals, links, and inconsistencies. It cannot prove document provenance unless an issuing lab or source independently confirms it.
Limitation
No purchase recommendation. Reports do not recommend, endorse, discourage, rank, or facilitate purchases from any vendor.
What you can inspect
The documents a serious buyer should be able to read.
Six documents are published alongside this one.
Supplier Packet Audit SOP
How packet review is performed.
Traceability Standard
How order, lot, COA, packet, reviewer, and customer proof connect.
Report Limitations
What Veritura can and cannot determine.
Security and Data Handling
Data minimization, headers, access boundaries, and current limitations.
Correction Policy
How evidence-backed corrections are handled.
Privacy
How account and report data is handled.
See how the checks are phrased before you rely on a report.
Create a dashboard and follow a record end to end, or talk to us about covering your supplier base.