ClearGate
One decision per order, against the policy you set.
Before an order goes out, something has to decide whether the paperwork behind it is good enough. That decision is yours to define, and ClearGate applies it the same way every time: allow, review, or hold, with the reasons that fired.
The decision
One order in. One signed decision out.
Order time is when the paperwork matters most and gets checked least. This is the whole run, in the order it happens, and the same run whether a person clicked Run or your policy re-ran itself when evidence landed.
What happens between the call and the answer.
One order or lot is read against the policy the customer wrote, and the decision comes back Allow, Review or Hold with every reason naming the rule that fired.
- Operator
Setup, once.
The operator picks a preset and can override eleven named toggles and one threshold. It is a bounded library mapped to fields the evaluator actually reads, not a free-form rule language.
Record state: Policy stored, versioned - Your policy
An order is screened, a check is saved, or a shipment is received.
ClearGate evaluates. When the policy has auto-decide on, no one has to click Run; the trigger is recorded but the record produced is identical to a manual run.
Record state: Evaluation started - Engine
Evaluation started.
The supplier qualification file and the lot are read against the policy. Hold beats review beats allow. Every reason carries the policy rule code that produced it.
- Engine
A decision exists.
The decision is signed and hash-chained to the one before it, with the policy version pinned inside the record.
Record state: Signed decision on the chain - Engine
The decision is stored.
A hold stamps clearGateHold on the lot, which blocks the passport on its own. A later allow or review clears that hold; the signed record itself is never mutated.
Record state: clearGateHold set or lifted - Operator
Someone questions a decision.
The stored evidence and the pinned policy snapshot are fed back through the same evaluator. A correct decision replays to the identical decision, label and reasons.
Record state: Replay matches, or the record was altered
Three ways it comes back.
Hold beats review beats allow. All the rules are still evaluated after the first one fires, so the record names every reason rather than only the one that decided it.
What enters
One order line
A lot_id, or a supplier with optionally a product and lot so the lot is resolved for you. Your own order reference rides along, and supplier is required when no lot_id is given.
What runs
Your policy, at its pinned version
Your saved policy, or the Standard preset when you have not saved one. Its id and version are pinned before a single rule runs, so a decision is never read against a policy you changed afterwards.
One of these
- ClearGate decision: Allow
No hold rule and no review rule fired. An Allow is the absence of a fired rule, which is why it is the one decision that carries no reason codes.
allow -> Meets your policy
- ClearGate decision: Review
At least one review rule fired and no hold rule did.
review -> Needs review
- ClearGate decision: Hold
At least one hold rule fired.
hold -> Does not meet policy
What each decision carries, and what it does to the order next.
- ClearGate decision: Allow
Meets your policy
What it writes on the lot
A ClearGate hold left on the lot by an earlier decision is lifted. The earlier record itself is never rewritten.
What happens to the order next
Under Standard or Lenient the Passport releases as soon as the lot's own floor is met, stamped with the policy id and version that authorized it. Under Strict the release stays with a person. If an enforcement or recall signal lands on the supplier after this Allow, the entry is marked superseded and asks for a re-run.
- ClearGate decision: Review
Needs review
Reason codes it can carry
- lot_pending
- The lot is pending review.
- file_incomplete
- The qualification file is not complete.
- below_min_completeness
- The qualification file is below the policy minimum percent complete.
- file_attention
- A document renewal or supplier review is coming due.
- needs_human_review
- Policy requires a human-reviewed lot.
- no_file
- No supplier qualification file is on record for this supplier.
What it writes on the lot
No hold is stamped, and a hold left by an earlier decision is lifted.
What happens to the order next
The order stays yours to decide. If you turned on Require a ClearGate Allow before a passport, a release attempt on this lot answers 409 cleargate_required until an Allow is on record.
- ClearGate decision: Hold
Does not meet policy
Reason codes it can carry
- fda_enforcement_hit
- FDA enforcement or recall signal(s) on the source.
- accreditation_expired
- Accreditation is expired.
- recall_exposure
- This lot is exposed to an FDA recall or enforcement signal.
- lot_flagged
- The lot is flagged.
- file_overdue
- The qualification file is overdue: an expired document or an overdue review.
- no_file
- No supplier qualification file is on record, and policy holds on an unqualified source.
- custom_required
- A custom policy item is required and not attested.
What it writes on the lot
clearGateHold is stamped on the lot, which blocks a Passport on its own.
What happens to the order next
A release attempt on that lot is refused with a 409: cleargate_hold where the lot is otherwise cleared, lot_pending_review where it is not. Close the reason that fired and the next decision lifts the hold. The held decision stays in the log exactly as it was written.
A ClearGate decision always means the documentation meets your policy. It never means Veritura approves the supplier.
Boundary
Veritura does not test medicine, approve suppliers, recommend purchases, or make medical, legal, product-safety, or FDA-approval determinations. There is no paid or subjective placement: suppliers cannot pay for a better result or a better position, no listing fee, no subscription, and no pay-to-rank. Where results are ordered rather than filtered, the order is set by a published documentation-coverage grade, and that grade is never a recommendation, a preference, or a statement about any product.
What the gate reads
Four rails fire. The worst rail governs.
A screen is not one lookup. Supplier documentation, substance eligibility, prescriber registry, and the qualification file all run, and the composite verdict is the worst of the four.
Four-rail decision
Four independent evidence rails converge into a versioned operational receipt.
- Supplier ClearGateDocumentation against your policy
- Substance eligibilityLive FDA lists
- Prescriber registryNPPES, live
- Qualification fileYour supplier record
Resolving supplier cleargate.
All four rails fire on every screen and the worst rail governs; all four resolving is what produces an Allow. A decision about an order against the policy you set, never a statement that the medicine is safe, effective, or approved.
Local sample data. Not a live account. Every supplier, lot, order, and document shown here is fictional.
Supplier ClearGate
Documentation against your policy. The supplier's qualification file and the lot are evaluated against the rules you turned on, and every reason names the rule that fired.
Substance eligibility
Live FDA lists. Whether a substance is eligible to compound for your facility type is resolved against the current bulks, do-not-compound, and shortage lists, as a decision against your eligibility policy, never a legal opinion.
Prescriber registry
NPPES, live. A prescriber NPI or a name scoped to a state is resolved against the public registry at the moment of the screen.
Qualification file
Your supplier record. The six-element file's own rollup, current, due, or overdue, is read as a rail in its own right, so a file that stopped moving shows up at order time.
All four rails fire; the worst rail governs. One signed verdict, a decision against your policy, never an approval. A rail you did not provide inputs for is marked not provided and does not affect the verdict.
Mode 01
Single order
Supplier, product, lot, order reference, and optionally a prescriber NPI or name. All four rails fire and the composite verdict is signed.
Mode 02
Whole PO
One line per supplier, product, and lot. One signed decision per line, and the worst decision governs the PO.
Mode 03
Supplier rail only
The supplier documentation rail on its own, for when a supplier name is all you have. The full screen runs this plus three more rails.
The presets
Three floors, and exactly how they differ.
A preset is the floor, not the ceiling. Every preset holds on the hardest public-record signals; what changes is how much of the file has to be in place before an order clears, and who pulls the trigger on release.
Strict
Everything must be complete, current, and human-reviewed. Any hard signal holds, and a supplier with no qualification file at all is a hard hold rather than a soft review.
Standard
A cleared lot, a current file, and no hard signals. Gaps drop to review rather than hold. This is the default when no policy has been saved.
Lenient
Only the hardest public-record signals hold. An FDA enforcement hit on the source and recall exposure on the lot still stop the order; everything else allows.
| Rule | Strict | Standard | Lenient |
|---|---|---|---|
| Cleared lot required | Yes. A flagged lot holds, a pending lot reviews | Yes. A flagged lot holds, a pending lot reviews | No |
| Complete qualification file required | Yes. Review until all six elements are satisfied | No | No |
| Current file required | Yes. Overdue holds, coming due reviews | Yes. Overdue holds, coming due reviews | No |
| Minimum file completeness | 100% | 50% | No minimum |
| Expired accreditation | Hold | Hold | Does not block |
| FDA enforcement or recall signal on the source | Hold | Hold | Hold |
| Recall exposure on the lot | Hold | Hold | Hold |
| Human-reviewed lot required | Yes. Review until a person has reviewed the lot | No | No |
| Supplier with no qualification file | Hold | Review | Review |
| Re-runs when new evidence arrives | Yes | Yes | Yes |
| Releases a Passport on a policy Allow | No. The release stays with a person | Yes | Yes |
Auto-decide and auto-release are two different switches.
Re-run ClearGate automatically when evidence arrives
Every saved check or received shipment re-evaluates this policy against the lot and stores the signed decision, with no one having to click Run. All three presets do this.
Release passports on a policy Allow, with no manual release
A passport releases the moment its lot is cleared, carries no hold, and satisfies this policy. The release is stamped with the exact policy version that authorized it. Standard and Lenient do this; Strict does not.
The difference is who pulls the trigger, never what gets recorded. An automatic decision produces the same signed, hash-chained, replayable record a manual run produces. The floor still governs either way: an uncleared lot, a lot carrying a hold, or a lot exposed to a recall never publishes a passport.
The Strict, Standard, and Lenient presets are included on the Clinic plan at $99/mo. Custom policy, per-rule toggles, thresholds, and operator-attested items, is part of the Facility plan at $399/mo.
Custom policy
Configurable presets and bounded custom rules.
Above the preset floor sits a fixed library of toggles and one threshold. Each maps to a field ClearGate evaluates, so a policy can never ask the gate for a judgment it does not make.
Require a cleared lot
Hold if the lot is flagged; review if it is still pending.
Require a complete qualification file
Review until all six file elements are satisfied.
Require a current file
Hold on an expired document or overdue review; review when one is coming due.
Block on expired accreditation
Hold when the accreditation on file is past its renewal date.
Block on an FDA enforcement hit
Hold when the source matches an FDA enforcement or recall record.
Block on recall exposure
Hold when the lot is exposed to a recall signal.
Require a human-reviewed lot
Review until a person has reviewed the lot, not just the automated gate.
Hold on an unqualified supplier
Hold, not just review, when there is no qualification file on record for the supplier, so the gate can stop an order from a source you have never qualified.
Require a ClearGate Allow before a passport
Block issuing an Evidence Passport on a lot until it has passed ClearGate with an Allow decision, so the policy rail cannot be skipped.
Re-run ClearGate automatically when evidence arrives
Every saved check or received shipment re-evaluates this policy against the lot and stores the signed decision, with no one having to click Run.
Release passports on a policy Allow
A passport releases the moment its lot is cleared, carries no hold, and satisfies this policy. Billing applies exactly as on a manual release.
Minimum file completeness
Review when the qualification file is below this percent complete. Set anywhere from 0 to 100.
Custom required items, operator-attested
Add your own required documents, an insurance certificate on file, for example. They are never auto-graded: a required item that has not been attested holds the order, and an attested item carries who attested it and when.
Every element is labeled Veritura evaluated, read from the document or a public source, or Operator attested, where you confirm what we cannot read. The file never overstates what was checked.
The record
A decision you can replay in front of an inspector.
A decision nobody can reconstruct is an opinion. Every ClearGate decision is signed, chained to the one before it, and re-runnable from its own stored evidence.
Signed and hash-chained
Each decision carries a signature and a hash over the decision before it. The log shows whether the chain is intact, so a record that was altered cannot pass as one that was not.
Replayable
A decision stores the evidence it read and a snapshot of the policy version that governed it. Replaying it re-runs the same evaluator against the same inputs, and a correct decision replays to the identical decision, label, and reasons.
Reason-coded
Every reason names the policy rule that fired and the level it fired at, so the log answers why this order held rather than only that it did.
Exportable per decision
Each entry downloads as a signed determination PDF for the batch record, alongside the whole-log export.
Superseded when the world changes
When a supplier recall lands after an Allow, that entry is marked superseded and asks for a re-run. The signed record itself is never rewritten.
The policy in force is visible
The console names the preset and the policy version that is governing right now, so a decision is never read against a policy you have since changed.
Boundary
AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.
Order Channel
Orders
| Order | Supplier | Product | Lot | ClearGate | Received |
|---|---|---|---|---|---|
| ORD-DEMO-1084 | Aurora Pharma Supply | Semaglutide (base) API | LOT-7741-A | ClearGate decision: Allow Six-document packet complete; issuing lab confirmed the COA | Jul 22, 2026 |
| ORD-DEMO-1085 | Keystone Peptide Labs | Tirzepatide API | LOT-KP-2407 | ClearGate decision: Review Sterility and endotoxin evidence not supplied | Jul 22, 2026 |
| ORD-DEMO-1086 | BlueRiver API Co | BPC-157 | LOT-BR-0816 | ClearGate decision: Hold COA lot and shipment label do not match; route unreachable | Jul 21, 2026 |
| ORD-DEMO-1087 | Meridian Compounding Source | Lidocaine HCl | LOT-MC-1129 | ClearGate decision: Allow Six of six qualification elements on file; packet complete | Jul 21, 2026 |
| ORD-DEMO-1088 | Aurora Pharma Supply | Ascorbic Acid | LOT-ASP-1180 | ClearGate decision: Allow Packet complete; no indexed reuse signal | Jul 20, 2026 |
| ORD-DEMO-1089 | Meridian Compounding Source | Glutathione | LOT-MC-1131 | ClearGate decision: Allow Packet complete; residual solvents within the printed specification | Jul 17, 2026 |
| ORD-DEMO-1090 | Keystone Peptide Labs | Sermorelin | LOT-KP-2411 | ClearGate decision: Review Undisclosed salt form on the COA; net peptide content unstated | Jul 16, 2026 |
| ORD-DEMO-1091 | Aurora Pharma Supply | Methylcobalamin | LOT-7748-B | ClearGate decision: Allow Packet complete; certificate of conformance on file | Jul 15, 2026 |
The API
POST /v1/cleargate
Call one endpoint at order time and get one decision against the policy you set, with a tamper-evident signed record behind it. Wire it into your fulfillment, Shopify, or pharmacy system.
POST /v1/cleargate, one decision per order against the policy you set: meets your policy, needs review, or does not meet policy.
curl -X POST https://veritura.co/v1/cleargate \
-H "Authorization: Bearer vk_live_..." \
-H "Content-Type: application/json" \
-d '{
"supplier": "Aurora Pharma Supply",
"product": "Semaglutide API",
"lot": "LOT-7741-A",
"order_id": "PO-DEMO-0413"
}'{
"ok": true,
"decision": {
"decisionId": "cgd_...",
"decision": "review",
"label": "Needs review",
"policy": { "id": "pol_...", "version": 3, "preset": "standard" },
"supplier": "Aurora Pharma Supply",
"lotId": "LOT-7741-A",
"orderRef": "PO-DEMO-0413",
"reasons": [
{ "level": "review", "code": "lot_pending",
"detail": "The lot is pending review." }
],
"evidence": { ... },
"environment": "production",
"timestamp": "...",
"signature": "sha256=..."
}
}Identify the order
Send a lot_id, or send supplier with optionally product and lot and the lot is resolved for you. Supplier is required when no lot_id is given.
order_id
Your own order or PO reference. It is carried on the signed decision so the record and your system agree on what was decided.
Test and live keys
Self-serve from Settings. A test key returns a sandbox decision, a live key a production one, and the response says which environment it came from. Rotate any time, revoke instantly.
The same path as the dashboard
The API and the dashboard run the same decision path, so a decision made by an integration is indistinguishable in the log from one made by a person.
The endpoints this decision sits with
- POST/v1/cleargate
- One decision per order against the policy you set: meets your policy, needs review, or does not meet policy.
- POST/v1/eligibility
- Allow, Review, or Hold on whether a substance is eligible to compound for a facility type against the current FDA lists.
- POST/v1/passports
- Issue from a cleared lot with an order reference. The cleared lot is the gate, so an uncleared lot can never publish a passport.
Errors, in the endpoint’s own words
- 401
- A valid API key is required: Authorization: Bearer vk_live_... (or vk_test_...).
- 400
- Provide supplier (and optionally product + lot), or a lot_id.
Signed webhooks
Subscribe to passport.issued, lot.recall_hit, and supplier.alert. Every delivery is HMAC-signed in the X-Veritura-Signature header, so a recall that lands after fulfillment finds its way back to your systems.
The /v1 API, with keys and signed webhooks to automate ClearGate and Evidence Passports, is part of the Facility plan at $399/mo. Platform accounts pre-commit a year of passport volume upfront at a bought-down rate.
A different axis
The Receiving Gate is not ClearGate.
The intake gate for each shipment: match the label to the paperwork, read the micro evidence, and set the lot state before anything moves downstream.
ClearGate decides an order against your policy and answers in Allow, Review, or Hold. The Receiving Gate dispositions a shipment and sets the lot state that ClearGate then reads. Two gates, two vocabularies, and they are never interchanged: a receiving disposition is not a ClearGate decision, and neither one is an evidence posture of Clear, Review, or Hold.
The seven gates, every tier each one can resolve to, and the branch that picks a disposition are documented where the work happens, on receiving for compounding pharmacies.
What each disposition means on the bench.
Documentation release ready
Every gate is satisfied on the record: the label reconciles to the paperwork, the COA is present, and the micro evidence is attached rather than asserted.
Sets the lot to cleared
Request supplier correction
A documentation gap is open that the supplier has to close. The gate drafts the exact ask, naming the evidence it needs for this exact lot.
Sets the lot to pending review
Quarantine pending evidence
The certificate is missing, or a micro result was marked present with no source result, method, or evidence reference behind it. Nothing moves downstream on an assertion.
Sets the lot to pending review
Hold for human review
Neither one can be settled on paper at the bench. The record routes to a person and names what has to be reconciled before any reliance.
Sets the lot to flagged
A clean receipt does not lift every flag
A documentation release on this gate does not clear a lot whose flag came from a recall signal, from a routing for human review, or from a high-severity finding on its documentation. A receipt cannot answer a document finding; a corrected certificate can. And a re-receipt that comes back quarantine or correction supersedes an earlier clear until the gates pass again.
The lot state is what ClearGate reads next
This is where the two axes meet, and the only place they touch. The disposition sets the lot state; the lot state is one of the inputs ClearGate evaluates against your policy. When your policy has auto-decide on, ClearGate re-runs against the lot the moment the receipt is saved, through the same path a manual run uses.
Boundary
Documentation receiving gate only. This is not a product quality, safety, efficacy, compliance, or FDA-approval determination.
Gate every order against your own policy.
Before money moves, so a bad source is caught before it ships, not after.