Veritura reads every supplier document, states what is present, missing, or expired, resolves the order against the policy you wrote, and keeps one record from receiving to the patient.

A certificate checked at the door and forgotten by release is the gap inspectors find. Veritura keeps a lot, an order, a supplier, and a Passport as one record seen from different angles, so every status stays attached to the document and the person that produced it, and the customer only ever sees the cleared part.
Five jobs, one record. The screens below are drawn from the product as it runs today.
01
Nothing is decided on the first screen. It counts what the checks produced overnight, plots screened and held orders across the last twelve weeks, and lists the most recent events in the order they happened, so the open items are visible before a single document is opened and the day starts with the queue, not the inbox.
In practice the morning starts with a list, not a search. Held orders sit at the top with the rule that held them, and the person who needs to sign is named on the line.

02
Each certificate is reconciled against the laboratory that issued it, the standard it has to meet, the file's own internals, and every other document already in your workspace. A file the engine could not read is recorded as unreadable rather than reported as missing every field, because those fields were not absent, they were not extracted.
The four lanes never go quiet. A lane with nothing to work with says not applicable, so a reviewer can see at a glance what was checked and what could not be, before trusting a result.

03
Six structured elements per supplier, each holding a named thing with a stated way to satisfy it and its own date: manufacturer identity, accreditation, FDA registration status, quality agreement, documentation specifications, and ongoing review. Each dated document carries a current, due, or overdue status, so a lapsed certificate surfaces before an order goes out against it.
When an inspector asks for the supplier file, the answer is one screen: six elements, each with its date and its origin label, and the review cadence that keeps it living.

04
When an order is placed, ClearGate reads the supplier file, the lot, and the policy you configured, and returns one decision: allow, review, or hold. Every rule is still evaluated after the first one fires, so the record names every reason rather than only the one that decided it, and a hold blocks a Passport on its own.
ClearGate is the same run every time, whether a person clicked or the policy re-ran itself when new evidence landed, which is what makes two reviewers reach the same decision.

05
A cleared lot is the gate. Only then is an Evidence Passport minted for the order, binding it to the product, lot, certificate, supplier packet, and reviewer behind it. The patient scanning a vial and the pharmacist answering for it read the same document set at different depths, and the lot binding is permanent, which is why a recall published months later can still reach an issued Passport.
Customers see only the cleared part. Internal notes, pricing, and supplier language are filtered before release, and a Passport can be verified by anyone with its serial and no account.

Why this exists
Federal law requires that bulk substances used in compounding be accompanied by a valid certificate of analysis, and names no method for establishing that a certificate is valid. Every pharmacy, facility, clinic, and platform in the chain is left to decide for itself. That gap is the whole reason an independent evidence layer exists.
The requirement appears in the federal compounding provisions for both 503A pharmacies and 503B outsourcing facilities. Validity is required. A way to establish it is not described.
In 2026 the FDA published a warning letter to a bulk supplier on its own published lists, describing relabelled active ingredient and altered manufacturing and retest dates. A buyer who checked the list and received a certificate still held a document that did not say what it appeared to say.
A large telehealth provider ran a per-batch certificate lookup from a code in each shipment for over a year and reported thousands of subscribers opening it every month. The demand for the record is not the question. Who checks it is.
What changes
Held orders, the rule that held them, and who needs to sign, before a single document is opened.
Inspector, partner, or patient: the same record, at the depth each is allowed to see.
Every material decision carries a person, a policy version, a reason, and a signature.
The method
Documents arrive by email, upload, or API and are retained as received.
Read against identity anchors, your policy, and named public sources.
A named person signs every material decision, with the reason kept.
Cleared orders issue serialized Passports and Seals.
Every document and decision stays on the record for seven years.
Everything on this page is one of these five, seen closer up.
Read every supplier document and state what it does and does not establish, with the page and line cited.
Resolve the read into one decision per order, against the policy you set, signed by a person.
Hand the finished record to whoever asks next, including the patient, without the internal notes.
Watch the public record after release and say, by lot, when something changes.
Run any of it from your own system in one call, with the same record behind it.
The complete text, for the reader who wants the whole story before a call.
Everything below is one of these five, seen closer up.
Read every supplier document and state what it does and does not establish.
Resolve the read into one decision per order, against the policy you set.
Hand the finished record to whoever asks next, including the patient.
Watch the public record after release and say when something changes.
Run any of it from your own system, in one call.
Each stop names who acts, what the system does to what it was handed, and the state it leaves behind for the next one. Everything further down this page is one of these stops seen from the surface that runs it.
A certificate arrives by upload, on a supplier request link, or on POST /v1/check. Anything over 8 MB is refused before any work is done, and a SHA-256 of the bytes becomes the document's identity for the rest of its life. A page with no usable text layer is read as an image.
Content hash recorded. It keys the read cache, it sits on the check record, and it is what the reuse index compares.
The fields a complete certificate carries are read into rows, and a field the document does not state is printed as not stated rather than guessed. Then four lanes run: the issuing lab, the printed standard, the file's own metadata, and every other document already on record from that source. Each lane returns Ran, Not applicable, or Could not verify with its reason.
A completeness band of complete, partial, sparse or undocumented, plus any finding. A high-severity finding moves the lot to Hold and blocks its passport.
The shipment is gated
Supplier, product and lot are entered on the bench, the container label is photographed and read against the paperwork, and seven gates evaluate what is already on the record instead of what was typed. A panel out of scope for the preparation is marked not applicable, never counted as a gap.
One of four dispositions: Documentation release ready, Request supplier correction, Quarantine pending evidence, or Hold for human review, each with the lot state it produces.
The order meets your policy
The supplier qualification file and the lot are read against the policy you wrote, from a bounded library of eleven named toggles and one threshold. Hold beats review beats allow, and every reason carries the rule that produced it.
Meets your policy, Needs review, or Does not meet policy, signed and hash-chained to the decision before it with the policy version pinned inside.
A cleared lot publishes
Release checks a floor: the lot must exist, be cleared, carry no ClearGate hold and no recall signal, and satisfy any human review your policy requires. An order that arrives before its lot clears parks at source_review rather than releasing on its own say-so.
A released record readable at /verify, or a 409 naming the requirement that was not met.
The vial carries it
Serials are minted against that lot in the shape VS-XXXX-XXXX, collision-checked against every serial already issued, and printed as a sheet, a thermal label, or raw ZPL straight to the printer. The label goes on the vial at packing.
A seal batch. Whoever holds the vial scans it, and a saved vial moves from pending_confirm to active once the emailed link is opened.
The record keeps watching
Recent FDA drug enforcement records are pulled on a cycle and scanned for lot numbers already on record. A match has to sit on a token boundary, so 1305 can never match inside 213055, and a short all-digit number has to be distinctive enough not to be a catalog number or a date.
Every matching lot moves to Hold in every account that logged it, every passport minted from that lot is stamped with a post-release signal, and no new passport can mint from it.
The check reads documentation for completeness, consistency, reuse and tamper signals. It never declares a document fake, and it cannot establish provenance unless the issuing lab records its own reply.
Quarter to date · 104 Allow, 18 Review, 6 Hold
Documentation met the configured workspace policy
Held on the evidence on file, not on a test result
Qualification files under ongoing review
LOT-7741-A released under policy
Semaglutide (base) API · Aurora Pharma Supply · 6 documents on file
LOT-KP-2407 · Keystone Peptide Labs · prefilled corrected-COA request sent
Lot identifier mismatch recorded
LOT-BR-0816 · shipment label reads BR-0818 · verification route unreachable
V-SBX-00012 · Lidocaine HCl · LOT-MC-1129 · Meridian Compounding Source
openFDA enforcement search re-run for 4 suppliers · no match in captured sources
Nothing is decided on this screen. It counts what the stops above produced, plots screened and held orders across twelve weeks, and lists the most recent events in the order they happened, so the open items are visible before a single record is opened.
Every saved check, receiving record, ClearGate decision, released Passport and monitoring signal in the account.
The tiles count on the ClearGate axis, Allow and Hold, because what was screened is an order. A document set carries a posture instead, and the two vocabularies are never added into one number.
You open the lot, the supplier or the order behind a line and act there. A Hold on this screen is held on the evidence on file, not on a test result.
One engine behind every view, so a lot, an order, a supplier, and a Passport are the same record seen from different angles.
One record, carried through every handoff, with each status still attached to what produced it.
Linking document: packet captured, hashed, and scoped.
A Passport can be released once the lot clears. An uncleared lot never publishes one.
Local sample data. Not a live account. Every supplier, lot, order, and document shown here is fictional.
Lots cleared, documents reviewed, Passports issued, suppliers watched, and open alerts, with the action queue first.
The Order Channel: an invite-only ordering front door where every request carries its evidence and its ClearGate posture.
A living six-element qualification file per supplier, each dated document marked current, due, or overdue.
Order- and lot-bound proof pages. A cleared lot is the gate, so an uncleared lot can never publish one.
Living Supply Shield: saved suppliers and lots watched against FDA enforcement and recall feeds.
One click builds an inspector-ready binder of every saved check, supplier, lot, and qualification file current as of the pull.
Policy presets, custom rules, team seats, and self-serve test and live API keys you can rotate any time.
The document set met the configured policy. It describes the paperwork, not the medicine.
The issuing laboratory confirmed issuance through the recorded verification route.
OrderPO-DEMO-0413
LotLOT-7741-A
SupplierAurora Pharma Supply
Quantity250 g
ReceivedJuly 22, 2026
ReleasedJuly 23, 2026
Passport issuedJuly 23, 2026
Methodologyv1.0 · April 30, 2026
COA-7741-A.pdf · Issuing laboratory confirmed issuance through the recorded route
CoC-7741.pdf · Required identity, lot, and date fields present
SDS-SEMA-04.pdf · Current revision on file
GMP-AUR-2026.pdf · Supplied by the operator
Recorded in workspace · Container and label checked at receipt
LBL-7741-A.jpg · Lot identifier matches the certificate of analysis
A Passport is minted from a lot, never from a claim, which is why an uncleared lot can never publish one. On this internal record the two axes appear under their own labels: the document set has a posture, each element has an origin, and neither is collapsed into one word.
A cleared lot, the order it covers, the documents and the lab behind it, and the file fingerprints that make reuse of the same certificate across lots visible.
Release is refused unless the floor is met: no ClearGate hold, no recall signal, and any human review your policy requires. A refusal names the requirement rather than failing quietly.
A shared page that prints what the documentation states, the lab and the date, in plain words and with no number. A patient or a buyer never sees a posture word or a score, because a number beside the name of someone's medicine reads as a quality grade, which it is not.
A mechanical, repeatable pass, so two reviewers reach the same record and an inspector can follow it.
17-signal forensic pass on every file: reused signatures, producer anomalies, a file created after its own stated test date, and signals consistent with a generated document. Signals, never proof.
Lots and firms are checked against openFDA enforcement and recall records. Only a recorded lab reply flips a document to source-confirmed.
The same lot, report ID, file, or visual fingerprint appearing across indexed records surfaces as a review signal, alongside template drift against the supplier's own prior documents.
Image-heavy and scanned COAs are read with OCR, so fields and signals are extracted even when there is no embedded text.
A capped first-pass extraction drafts the field map, the conflict list, the missing-evidence list, and the supplier questions.
Delivered diligence memos get a reviewer's check of the final language. Automated checks claim no human sign-off.
Every check in the published catalog, and what each one does and does not establish, is listed in full on the evidence engine.
AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.
An inspector grades the file as a living system, not a one-time onboarding folder. Veritura keeps every dated document current and gates every order against it.
Legal name, address, FDA registration and FEI number, confirmed against the registration snapshot when one is available and marked on file when it is not.
NABP, VAWD, or equivalent, held with its effective and expiry dates, so a lapsed certificate surfaces before an order goes out against it.
Registration and listing checked against live openFDA enforcement and recall feeds, with any hit on the firm shown on the file.
The signed agreement and its renewal date, tracked like every other dated document you rely on.
Your required COA panels and document standards, evaluated against what each packet actually contains rather than assumed.
A review cadence with a next-review date, so the file carries a living current, due, overdue status instead of a stamp.
Every element is labeled Veritura evaluated, read from the document or a public source, or Operator attested, where you confirm what we cannot read. The file never overstates what was checked.
Ongoing review due Jul 30
Corrected source route requested
The score grades the documentation evidence on file only. It is not an approval, a ranking, a certification, or a statement about any product.
You set the bar. We keep the record.
Does not meet policy
A ClearGate decision always means the documentation meets your policy. It never means Veritura approves the supplier.
All three presets re-run the gate automatically when new evidence lands. Standard and Lenient also release the Passport on a policy Allow; Strict keeps the release with a person.
Six-document packet complete; issuing lab confirmed the COA
Sterility and endotoxin evidence not supplied
COA lot and shipment label do not match; route unreachable
Six of six qualification elements on file; packet complete
Packet complete; no indexed reuse signal
Packet complete; residual solvents within the printed specification
Undisclosed salt form on the COA; net peptide content unstated
Packet complete; certificate of conformance on file
Each row is one order read against the policy you wrote. The ClearGate column carries Allow, Review or Hold and, under it, the reason that fired. An order carries a decision; the document set behind it carries a posture. The two never share a column.
An order with its supplier, product and lot, plus the qualification file and the lot evidence already on record for that source.
The filter is the policy axis, not a search convenience. Pick Hold and you are looking at every order your own rules would not pass, with the rule named on each row.
A signed decision, hash-chained to the one before it with the policy version pinned inside. A hold is stamped on the lot and blocks its passport until a later allow or review lifts it.
Select a layer to see exactly what it contributes. The record moves from submitted document to policy, order, and released proof.
6 files · SHA-256 identity retained
standard-v3 · signed sample decision
Lot linked · documentation release ready
Sample Passport · active record
Each lane preserves the search, the source URL, and the capture date.
FDA's list current as of June 23, 2026, captured June 30, 2026
Not found in the snapshot never means not registered. It means the name did not match the captured list.
BlueRiver API Co · the published verify link for LOT-BR-0816 did not answer on three attempts. A corrected source route has been requested.
MON-DEMO-18·1 supplier · 1 lot · 1 order
Keystone Peptide Labs · LOT-KP-2407 carries no sterility or endotoxin result. Missing evidence is not a failed test; the lot stays in review until it lands.
MON-DEMO-21·1 supplier · 1 lot
openFDA enforcement and recall records re-captured for 4 suppliers. No match in the captured sources. Disposition unchanged.
Aurora Pharma Supply · ongoing review is due July 30, 2026. Five of six elements remain on file with current dates.
A monitoring signal maps a captured public record to the suppliers, lots, and orders it touches. It never changes a disposition on its own, and no match in a captured source is not proof of absence.
An enforcement record published months later still has to find the lot. The sweep scans recent FDA records for lot numbers already on record here, and because a Passport stays permanently bound to the lot it was minted from, a match months on still reaches the record a buyer is holding.
Recent FDA enforcement and recall records pulled on a cycle, plus the supplier names this account tracks. Each pull keeps its search, its source URL and its capture date.
Severity says how loud a line is, not what it decides. Action needed, Attention and Informational are their own axis, deliberately not the posture words and not the ClearGate words.
A lot named in an enforcement record moves to Hold in every account that logged it, and every Passport minted from it is stamped with a post-release signal. Anything softer stays a line to look at, and telling the people holding a sealed vial stays the pharmacy's call.
The cleared lot is the gate, so an uncleared lot can never publish a passport. These four are the integration path; seal minting, seal labels, and the three network routes are on the same key and are listed in full in the reference.
POST/v1/passportsIssue from a cleared lot with an order reference.
POST/v1/cleargateOne decision per order against the policy you set.
POST/v1/eligibilityAllow, Review, or Hold on whether a substance is eligible to compound for a facility type against the current FDA lists.
POST/v1/checkThe document check, as an embeddable call.
Every delivery is HMAC-signed in the X-Veritura-Signature header.
Test and live keys are self-serve from Settings on the Facility and Platform plans. Test keys run in sandbox. Rotate any time, revoke instantly.
Orders reach Veritura the way your system already moves them; passports issue and release under your own policy; patients get their record without anyone clicking send. Your whole job becomes reading one morning digest of anything that needs you, and most mornings it says nothing does.
Your pharmacy system already exports what shipped today. Point that scheduled export at a watched folder and it posts itself. The file is parsed in memory, only order, lot, and email are kept, and the raw export is never stored. Mixed-lot days work in one file; each row binds to its own lot.
Real time, per order. Any platform that can send a webhook when an order ships, directly or through a Zapier or Make step, posts to your private URL and the passport exists the same second. Field names are matched tolerantly, so most payloads work unchanged.
Autonomy never weakens a gate. Every self-released passport stands on the identical floor as a manual one: a cleared lot, no hold, no recall signal, your policy satisfied, and a payment method in front of every production release. What fails a gate waits in one exception queue, with its reason and its one fix.
How to turn it on · Settings → Autopilot
Release on policy Allow is on in your ClearGate policy (it is the default), so cleared lots release their own passports.
Connect your orders on the API page: download the drop watcher, or create your webhook URL, or both.
Email patients automatically one switch, and any arriving order that carries an email sends the record on release. The address is kept for one purpose, so a recall on that lot can reach them, and every notice carries an unsubscribe.
The Autopilot card in Settings shows all four switches with their live state, and says fully autonomous only when every one is on.
Every order's passport already reaches the patient on the vial or by email. Now it also brings them back: when the supply window your system recorded is closing, the patient who saved their vial gets a reminder carrying your name, your contact, and your reorder link. A single recovered reorder covers dozens of passports.
Add a days-supply column to the export or webhook you already send, and Veritura computes the run-out date at issue. Five days before the window closes, the reminder goes out, and only to the patient whose saved vial is bound to that exact order. Never to a whole lot, because one patient's supply is nobody else's notice.
When a record's beyond-use date enters a two-week window, every patient who saved a vial from that lot hears about it once, worded as what it is: a date on the record, set by the pharmacy, relayed by Veritura. A documentation fact, never an instruction about the medicine.
The patient opted in by saving their vial, and every email carries an unsubscribe. The message leads with your pharmacy's name and contact, and the reorder button is your own link to your own flow. Veritura never touches the transaction, which is exactly what keeps the record under it independent.
How to turn it on · three things, all yours already
Carry a days supply as one more column on the shipment export or webhook your system already sends. Rows without one simply never remind.
Seal the vial order-bound, the way the composer and the pack station already print them. The seal is how the reminder finds the right patient and no one else.
Set your reorder link on the Autopilot card in Settings, next to the counter that shows every notice and reminder sent.
Reminders are supply arithmetic on the window your system recorded, and every email says so. Nothing on this rail ever discusses dosing, and pharmacies can switch it off in one click.
A Certificate of Analysis covers the ingredient layer, and most compounded prescriptions leave the pharmacy as something more: a finished preparation whose paperwork is a compounding record under USP 795 or 797, or one that starts from a manufactured drug with an NDC listing instead of any certificate. Veritura now reads that layer with the same discipline it brings to a COA, so the medicine without a certificate gets a record too.
Paste the master formulation or compounding record on the Receiving view you already use. Veritura reads what is readable, the preparation name, batch, beyond-use date, sterility basis, and each ingredient line, and whatever you type over it always wins. The preparation becomes a batch on your workspace like any other lot.
Sterile or non-sterile, compounded from an API or from a manufactured drug: four classes, each with its own required set. A sterile preparation from API clears on its record, its beyond-use date, its stated sterility evidence, and every ingredient traced to a verified lot on file. When a fact is not stated, the desk asks you instead of guessing.
The patient's passport now answers what went into it: each ingredient traced to its own verified lot, or the source drug's current listing in the FDA NDC directory, stated in words on the same page patients already open. An ingredient that has not been matched says so plainly, because an honest gap is the point.
Nothing new to learn and nothing new in the nav: one folded card on the Receiving view, and every downstream rail, passports, seals, patient reminders, works for a preparation exactly as it does for a lot that came with a certificate.
No matter the entry point, you get the same defensible, exportable record.
The one decision, first.
Every signal tied to evidence and a next step.
Reconstructable at inspection time.
Documentation evidence only, never supplier approval or product safety language.
The exact ask, hold, review, or release step.
Shareable proof for your buyers.
Veritura does not test medicine, approve suppliers, recommend purchases, or make medical, legal, product-safety, or FDA-approval determinations. There is no paid or subjective placement: suppliers cannot pay for a better result or a better position, no listing fee, no subscription, and no pay-to-rank. Where results are ordered rather than filtered, the order is set by a published documentation-coverage grade, and that grade is never a recommendation, a preference, or a statement about any product.
Veritura performs independent documentation diligence only. Embedded checks, supplier verification, and co-branded Evidence Passports confirm that paperwork is complete and consistent, they are not a representation of product quality, safety, efficacy, legality, or FDA approval, and "Verified by Veritura" is never a certification or approval.
Create a dashboard and follow one lot from receiving to release, or book a call with the people who built the methodology.
Veritura reads and connects the paperwork behind an order. It never tests, grades, or endorses the medicine itself, and it never releases anything on its own.

A lot, an order, a supplier, and a Passport are the same record seen from different angles. Every status stays attached to the document and the person that produced it, so a recall months later still reaches the order it touched.
No. ClearGate returns allow, review, or hold with every reason named, and a person signs the release. Auto-decide can re-run the policy when evidence lands; auto-release is a separate switch, off by default.
The customer-facing Passport: product, lot, what the certificate reports, and who established each line, in plain words with no score. Internal notes, pricing, and supplier language are filtered before release.
Still have questions? Talk to a person.