Methodology v1.0

Fixed checks. Clear limits.

Reports describe what is present, absent, inconsistent, changed, or not independently verified. They do not assess product safety or quality.

Published standard
v1.0
Dated
Stamped on
Every reviewed output
Determination
None, signals only

What is checked

Six fixed checks run on every packet.

A mechanical, repeatable process, so two reviewers reach the same record and an inspector can follow it.

  1. 01

    Document inventory

    COA, batch specificity, lab name, method, sterility/endotoxin fields, business identity, and address fields.

  2. 02

    Internal consistency

    Lot numbers, product identity, purity claims, test dates, lab references, PDF metadata, and repeated document signals.

  3. 03

    Public claim audit

    Quantitative claims, verifiability claims, identity claims, undefined terms, health-related claims, and disclaimers.

  4. 04

    Historical change detection

    Changes to entity names, addresses, purity figures, COA links, lab references, and body-related language.

  5. 05

    Duplicate signal indexing

    Repeated hashes, visual fingerprints, lot values, lab/purity patterns, and verification links inside the user's saved archive.

  6. 06

    Vendor profile rollups

    Profile counts summarize documentation observations across saved reports, snapshots, corrections, and watchlist activity.

What runs before a person sees anything.

The same run on every document, in the same order, with nothing an operator can set. Six checks describe what is looked for; this is what produces the material they are applied to.

  1. Engine

    Bytes in hand.

    A SHA-256 of the file contents is taken. That hash is the document's identity for the rest of its life: it keys the read cache, it is stored on the check record as fileHash, and it is what the reuse index compares.

    Record state: Content hash recorded
  2. Engine

    A PDF or image whose embedded text is too thin to trust.

    The page itself is read. The transcription is cached on file hash plus model plus prompt hash, so a changed prompt re-reads the document instead of serving the previous reader's answer, and the read runs at temperature 0 so the same bytes give the same answer.

    180 second ceiling, measured rather than guessed: a multi-page certificate needed 82.4s and a 60s ceiling turned a readable document into a false unreadable.

    Record state: Transcription available
  3. Engine

    Transcription or text layer available.

    Structured rows, document links, QR values, PDF metadata, and text, structure and visual fingerprints are derived. The fingerprints are what later documents from the same source get compared against.

    Record state: Extraction complete
  4. Engine

    Extraction complete.

    The fields a complete certificate carries are read into rows: product, strength, lot, purity or assay, method, testing lab, report ID, date, sterility, endotoxin. A field the document does not state is printed as 'Not stated on the document', never guessed.

    Record state: Read rows built
  5. Engine

    Read rows built.

    The four lanes run and each returns one state with its reason. No lane may silently disappear.

    Record state: Lane states recorded
  6. Engine

    Lanes complete.

    A completeness band is computed. An unresolved high-severity finding can never sit inside a 'complete' band: the band only ever tightens, so nothing that read partial can become clean.

    complete requires score 80 or above, no required field absent, and no high-severity finding.

    Record state: complete | partial | sparse | undocumented

Three ways a read lands.

A band records how much of a complete certificate is actually present. It only ever tightens, so nothing that read partial can later become clean, and an unresolved high-severity finding can never sit inside a complete band.

What enters

One document

Whichever door it came through: dropped on the quality desk, filed by the supplier on a request link, or posted to the API. All three land on the same read.

What runs

The read

Hash the bytes, pull the embedded text, and read the page itself when there is not enough of it. The transcription is keyed on the file hash plus the model plus the prompt hash and runs at temperature 0, so the same bytes give the same answer twice and a changed prompt re-reads the document rather than serving the previous reader's answer.

One of these bands

  • Record state: complete

    Score 80 or above, no required field absent, and no high-severity finding standing on the documentation.

    band: complete

  • Record state: partial, sparse or undocumented

    A required field is not present, or the read is thin. Completeness is recorded field by field, so the record names which fields were not detected rather than rolling the gap into a single number.

    band: partial | sparse | undocumented

  • Record state: unreadable

    Too little was recovered from the file to form a record: not enough text, no structured rows, and no product with a quantitative result. Nothing is scored and no findings are raised. The record says the file could not be read and asks for a sharper one, because those fields were not absent, they were not extracted.

    score: null

Reading a document establishes what the document says. It does not establish that the document is genuine, that the lab issued it, or anything about the medicine it describes.

Version control

A material change requires a new version.

Every reviewed output stamps the methodology version it was produced under. Material changes require a new methodology version, noted publicly.

Accountable

Joey Soto, founder

Accountable for the methodology

Published scope

What is checked, and the public sources it is checked against, are published. The detection heuristics themselves are not, because publishing them would help fraudulent documents evade them and because they change faster than any page.

How findings are graded

Every observation lands in one of four buckets.

No subjective or paid ranking, no vendor scoring, and no certification of product quality. The one place results carry an order is the public network directory, and the grade that sets it is published below.

  • Match

    The sources that state the value agree, and the reviewed materials reconcile.

  • Mismatch

    Written as a source-backed observation: value A appears in source E1, value B appears in source E2, and the reviewed materials do not reconcile.

  • Missing documentation

    The value is not present in reviewed material, so the record says it was not detected instead of filling the gap from assumptions.

  • Could not verify

    The value is present but nothing reviewed settles it. The record states what Veritura did not independently verify.

Completeness is recorded field by field: COA, lot, lab, method, purity, MS and sequence evidence, sterility, endotoxin, strength, address, and disclaimer language. Presence or absence is recorded mechanically.

Record posture

Evidence posture: ClearEvidence posture: ReviewEvidence posture: Hold

These are separate axes. A reconciliation bucket is not a posture, and a posture describes the paperwork, not the medicine.

Evidence origin

Every item also carries where it came from, so an inspector sees what was actually verified and what was attested.

Evidence origin: Veritura evaluated
Read from the document itself or from a public source.
Evidence origin: Operator attested
The operator confirms what Veritura cannot read.
Evidence origin: Source-confirmed
A recorded lab reply is the only thing that flips a document to source-confirmed.
Evidence origin: Human-reviewed
A delivered written diligence memo that received human QA before delivery.

Limitation

A result is a documentation posture of Clear, Review, or Hold on the document set. A ClearGate decision of Allow, Review, or Hold is a separate axis, resolving one order against the policy you configure. Both describe the paperwork, not the medicine.

Limitation

Absence of a public match is not proof of absence. A missing document is not a failed test. A similarity indicator is not a fraud determination.

How the directory is ordered

One published grade sets the order. Nothing else does.

The public network directory is the only surface on which results carry an order. It is set by the documentation-coverage grade below, which is objective, disclosed, and cannot be bought.

  • Unverified

    Nothing has been read yet. Not listed in the public directory.

  • Documentation reviewed

    Veritura read the submitted COA and supporting documents for completeness and consistency. Not listed in the public directory.

  • FDA-source matched

    The above, plus the FDA registration matched a weekly FDA source excerpt and a published credential exists. This is the floor for appearing in the directory at all.

  • Full lab panel attested

    The above, plus a current, accredited, multi-vial panel the source attested: identity, purity, endotoxin, heavy metals, and microbial, on three or more vials. Attested by the source and cross-checkable where the named lab publishes a portal. Veritura runs no test of its own.

Tie handling
Two sources on the same rung are ordered alphabetically by entity name. There is no second scoring pass and no editorial tie-break.
Missing data
A missing element never rounds up. An element that was not supplied leaves the rung it would have earned unearned, and a source below the FDA-source-matched rung is not listed.
Freshness
The registration match is against the weekly FDA source excerpt, and the lab rung requires a current panel. Every listed profile carries the date it was checked.
What money buys
The review itself, and nothing else. There is no listing fee, no placement fee, no subscription that moves a position, and no way to pay for a rung.

Boundary

The grade orders documentation evidence and nothing else. It is not a preference, a recommendation, a quality or safety judgment, a certification, or a statement that any listed source is better than any other. Order is not endorsement, and a buyer must still run its own qualification.

Worked examples

How Veritura turns documents into observations.

Each check records what the materials show, what they do not show, and what Veritura did not independently verify.

Worked examples: what the reviewed materials show, and how the report phrases it.
CheckWhat the materials showHow the report phrases it
Example 01Lot mismatchProduct page lists Lot BPC240817. Uploaded COA lists Lot BPC240301.Observation: the visible lot values do not match across reviewed materials. Veritura does not determine intent or product quality.
Example 02Purity reconciliationProduct page states 99%+. COA reports 98.7% by HPLC.Observation: the public quantitative claim is not supported by the provided COA value.
Example 03PDF metadata gapCOA test date is August 22, 2024. PDF creation date is February 14, 2026.Observation: the file was generated after the stated test date. This can have ordinary explanations; Veritura does not infer fabrication.
Example 04Duplicate signalSame verification link appears in multiple saved reports for unrelated product records.Observation: repeated archive signal detected. This is a review signal, not an authenticity conclusion.
Example 05Claim-risk categoryResearch-use disclaimer appears alongside body, performance, or therapeutic-style language.Observation: claim category flagged. Veritura does not determine legal significance.

Reference intelligence layer

The checks are driven by versioned context rules, not freeform guesses.

Reference data defines expected fields by context, claim categories, method signals, freshness bands, and report thresholds.

Human review

A human controls the language on delivered memos.

What ships as a written deliverable passes a person first. What does not is labelled as automated, and claims no sign-off.

Automated extraction and archive signals are treated as draft review prompts.

Where a person enters the record.

On the document path a person enters at three points. What a person states is recorded as attested, with who and when, and reading the document behind an attestation still never verifies the practice behind it.

  1. Operator

    A certificate arrives by upload, by supplier request link, or on the API.

    The file is accepted as bytes. Anything over 8 MB is refused before any work is done.

    Record state: Bytes in hand
  2. Operator

    A lab is named on the document.

    A confirmation email to the issuing lab is drafted and the request is stamped on the record.

    Record state: Lab verification requested
  3. Operator

    The lab answers and the account holder records the reply.

    The recorded reply enters the state machine. Confirmed is the only path to confirmed:true. Not issued and mismatch are loud: a maximum-severity flag, a retest recommendation, and a supplier.alert webhook, because they cannot be settled on paper.

    Record state: source_confirmed | source_denied | source_mismatch | unconfirmed_no_response

The check reads documentation for completeness, consistency, reuse and tamper signals. It never declares a document fake, and it cannot establish provenance unless the issuing lab records its own reply.

  • Memo QA

    Human review controls final language for paid pharmacy and partner deliverables.

  • Source custody

    Records preserve file identity, source IDs, visible fields, evidence rows, and limits.

  • Boundary language

    No supplier approval, product certification, legal advice, medical guidance, or purchase steering.

Boundary

AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.

Release gate

Each Veritura deliverable must be understandable in under sixty seconds.

A buyer should not need to decode a dashboard or read a wall of text. The standard forces every output into a clean operating artifact with a verdict, evidence map, evidence replay, risk boundary, next action, and export package.

  1. Gate 01

    Executive verdict

    The operator can state the record posture without caveat hunting.

  2. Gate 02

    Evidence map

    Every material claim points to a source file, row, field, or explicit limitation.

  3. Gate 03

    Evidence replay

    The artifact shows how intake, extraction, reconciliation, QA, release, and archive state produced the decision.

  4. Gate 04

    Risk boundary

    The artifact excludes product approval, safety, legal, medical, and purchase language.

  5. Gate 05

    Next action

    The client knows exactly what to ask, hold, route, review, or release next.

  6. Gate 06

    Export package

    The record can be forwarded, archived, audited, or attached to a workspace.

Internal release gate

Six gates required

If any gate is missing, the output stays in review instead of pretending to be enterprise-ready.

Evidence and export

PDFs, memos, and customer proof must be reproducible from source records. Every deliverable points back to the reviewed packet, source inventory, limitations, and human QA posture.

Acceptance standard

No Veritura output ships as customer-safe until the verdict, evidence map, replay path, boundary language, next action, and export package are present and consistent with the source record.

Gate 06, the export package

The record that leaves the workspace.

Sample workspace · not a live account

Evidence Passport

Semaglutide (base) API

V-SBX-00013

Evidence posture

Evidence posture: Clear

The document set met the configured policy. It describes the paperwork, not the medicine.

Certificate of analysis

Source-confirmed

The issuing laboratory confirmed issuance through the recorded verification route.

Order
PO-DEMO-0413
Lot
LOT-7741-A
Supplier
Aurora Pharma Supply
Quantity
250 g
Received
July 22, 2026
Released
July 23, 2026
Passport issued
July 23, 2026
Methodology
v1.0 · April 30, 2026

Documents on file

6

  • Certificate of analysis

    COA-7741-A.pdf · Issuing laboratory confirmed issuance through the recorded route

    Source-confirmed
  • Certificate of conformance

    CoC-7741.pdf · Required identity, lot, and date fields present

    Veritura evaluated
  • Safety data sheet

    SDS-SEMA-04.pdf · Current revision on file

    Veritura evaluated
  • GMP certificate

    GMP-AUR-2026.pdf · Supplied by the operator

    Operator attested
  • Receiving inspection

    Recorded in workspace · Container and label checked at receipt

    Operator attested
  • Shipment label

    LBL-7741-A.jpg · Lot identifier matches the certificate of analysis

    Veritura evaluated

What this record does not establish

  • Documentation diligence only. No product was tested and no supplier was approved.
  • Absence of a public-source match is not proof of absence.
  • Produced under methodology v1.0, April 30, 2026.

Corrections

Reports change when the evidence supports a change.

Nothing is silently rewritten, and nothing supported is removed because it is unwelcome.

Evidence-backed corrections can update factual records without rewriting the methodology trail.

What a correction re-runs.

A stored decision is signed when it is written, replayed against its own pinned snapshot when it is questioned, and answered by a corrected document rather than by an edit. The earlier record is never mutated; it stays in the log exactly as it was written.

  1. Engine

    A decision exists.

    The decision is signed and hash-chained to the one before it, with the policy version pinned inside the record.

    Record state: Signed decision on the chain
  2. Operator

    Someone questions a decision.

    The stored evidence and the pinned policy snapshot are fed back through the same evaluator. A correct decision replays to the identical decision, label and reasons.

    Record state: Replay matches, or the record was altered
  3. Engine

    The check is saved.

    The lot it describes is upserted and the release gate re-evaluates the whole document SET for that lot's subject and dosage form, not just the newest file. A single-panel certificate no longer clears a lot on its own; several certificates together can.

    The lot's band describes the set. A thin contributor still blocks: a sparse or unreadable scrap does not become release evidence by sitting next to good paperwork.

    Record state: Lot state re-derived from the set

Boundary

Who can submit. Users, vendors, labs, or other relevant parties may submit factual corrections, supplemental documents, or responses tied to a report ID.

Boundary

What we review. Correction requests are reviewed against the underlying source material and the methodology version used for the report.

Boundary

What we do not remove. Veritura does not remove supported observations because they are unfavorable. Reports are corrected when a factual error or missing source is demonstrated.

Boundary

Vendor responses. Where appropriate, a response or supplemental document may be attached to a report without changing the original observation.

Boundary

Correction contact. Correction requests should include the report ID, the specific observation at issue, and the document or source that supports the correction. Send requests to Joey@veritura.co.

Limitations

Reports document evidence. They do not certify products.

Reports are not safety assessments, quality assessments, legal determinations, or purchase recommendations. There is no paid or subjective placement; where results are ordered, they are ordered by the disclosed documentation-coverage grade published above.

Current posture

Controlled and documented

The current standard documents operating controls, boundaries, and buyer-visible safeguards.

Limitation

Not a safety assessment. Veritura does not determine whether any product is safe, sterile, effective, pure, legal, or appropriate for any use.

Limitation

Not product testing. Reports are based on submitted documents, public pages, metadata, and snapshots. Veritura does not test physical material.

Limitation

Authenticity limits. A report may identify metadata, repeated file signals, links, and inconsistencies. It cannot prove document provenance unless an issuing lab or source independently confirms it.

Limitation

No purchase recommendation. Reports do not recommend, endorse, discourage, rank, or facilitate purchases from any vendor.

What you can inspect

The documents a serious buyer should be able to read.

Six documents are published alongside this one.

  • Supplier Packet Audit SOP

    How packet review is performed.

  • Traceability Standard

    How order, lot, COA, packet, reviewer, and customer proof connect.

  • Report Limitations

    What Veritura can and cannot determine.

  • Security and Data Handling

    Data minimization, headers, access boundaries, and current limitations.

  • Correction Policy

    How evidence-backed corrections are handled.

  • Privacy

    How account and report data is handled.

See how the checks are phrased before you rely on a report.

Create a dashboard and follow a record end to end, or talk to us about covering your supplier base.