Before an order goes out, something has to decide whether the paperwork behind it is good enough. That decision is yours to define, and ClearGate applies it the same way every time: allow, review, or hold, with the reasons that fired.

Order time is when the paperwork matters most and gets checked least. The run is the same whether a person clicked Run or your policy re-ran itself when new evidence landed: the order or lot is read against the policy you wrote, and the decision comes back Allow, Review, or Hold with every reason naming the rule that fired. Hold beats review beats allow, and all the rules are still evaluated after the first one fires.
The same run whether a person clicked Run or your policy re-ran itself when evidence landed.
01
Allow stamps no hold and lifts any hold left by an earlier decision. Review names what is pending: a lot under review, a file below the policy minimum, a renewal coming due, or a policy that requires a human-reviewed lot. Hold names the hard signals: an enforcement or recall match on the source or the lot, an expired accreditation, an overdue file, or an unattested required item, and a hold blocks a Passport on its own.
Every reason is kept, not only the first one that fired, so a hold explains itself fully and a reviewer never has to re-run the screen to learn what else was wrong.

02
A preset is the floor, not the ceiling. Strict requires everything complete, current, and human-reviewed, and treats a supplier with no file as a hard hold. Standard, the default, needs a cleared lot, a current file, and no hard signals, and drops gaps to review. Lenient holds only on the hardest public-record signals: an enforcement hit on the source or recall exposure on the lot.
The presets are floors, not ceilings. Every one still holds on the hardest public-record signals; what changes is how much of the file must be in place and who releases.

03
Auto-decide lets your policy re-run itself the moment new evidence lands on a lot, so the record is never waiting on someone to click. Auto-release is a separate switch, off by default, and even with it on, the hard signals still stop the order and a person still signs the release. Deciding and releasing are kept apart on purpose.
Deciding and releasing are two switches on purpose. The policy can re-run itself when evidence lands, but a person signs every release, and the receipt names them.

04
Screen one order with supplier, product, lot, order reference, and optionally a prescriber. Screen a whole purchase order as one line per supplier, product, and lot, with one signed decision per line and the worst decision governing the PO. Or run the supplier documentation rail alone when a supplier name is all you have.
A whole purchase order screens as one line per supplier, product, and lot, with one signed decision per line, and the worst line governs the order, which is what a buyer needs at the desk.

05
Every screen produces a versioned operational receipt: the four rail results, the rules that fired, the policy version, who ran it, and when. It is a decision about an order against the policy you set. It is never a statement that the medicine is effective or that a supplier is endorsed, and the receipt says so on its face.
The receipt is versioned and never rewritten. A later decision supersedes it and lifts an earlier hold, but the earlier record stays exactly as it was signed.

What changes
Allow, review, or hold, with every rule that fired, not only the first.
Written once, re-run when evidence lands, and never released without a person.
Rails, rules, policy version, signer, and time, superseded but never rewritten.
The method
Documents arrive by email, upload, or API and are retained as received.
Read against identity anchors, your policy, and named public sources.
A named person signs every material decision, with the reason kept.
Cleared orders issue serialized Passports and Seals.
Every document and decision stays on the record for seven years.
A screen is not one lookup. All four run on every order and the composite verdict is the worst of the four.
The supplier's qualification file and the lot, evaluated against the rules you turned on, every reason naming its rule.
Whether a substance is eligible to compound for your facility type, resolved against the current FDA bulks, do-not-compound, and shortage lists.
A prescriber NPI or a name scoped to a state, resolved against the public NPPES registry at the moment of the screen.
The six-element file's own rollup, current, due, or overdue, read as a rail so a file that stopped moving shows up at order time.
The complete text, for the reader who wants the whole story before a call.
Order time is when the paperwork matters most and gets checked least. This is the whole run, in the order it happens, and the same run whether a person clicked Run or your policy re-ran itself when evidence landed.
One order or lot is read against the policy the customer wrote, and the decision comes back Allow, Review or Hold with every reason naming the rule that fired.
The operator picks a preset and can override eleven named toggles and one threshold. It is a bounded library mapped to fields the evaluator actually reads, not a free-form rule language.
An order is screened, a check is saved, or a shipment is received.
ClearGate evaluates. When the policy has auto-decide on, no one has to click Run; the trigger is recorded but the record produced is identical to a manual run.
The supplier qualification file and the lot are read against the policy. Hold beats review beats allow. Every reason carries the policy rule code that produced it.
The decision is signed and hash-chained to the one before it, with the policy version pinned inside the record.
The decision is stored.
A hold stamps clearGateHold on the lot, which blocks the passport on its own. A later allow or review clears that hold; the signed record itself is never mutated.
Someone questions a decision.
The stored evidence and the pinned policy snapshot are fed back through the same evaluator. A correct decision replays to the identical decision, label and reasons.
Hold beats review beats allow. All the rules are still evaluated after the first one fires, so the record names every reason rather than only the one that decided it.
A lot_id, or a supplier with optionally a product and lot so the lot is resolved for you. Your own order reference rides along, and supplier is required when no lot_id is given.
Your policy, at its pinned version
Your saved policy, or the Standard preset when you have not saved one. Its id and version are pinned before a single rule runs, so a decision is never read against a policy you changed afterwards.
No hold rule and no review rule fired. An Allow is the absence of a fired rule, which is why it is the one decision that carries no reason codes.
allow -> Meets your policy
At least one review rule fired and no hold rule did.
review -> Needs review
At least one hold rule fired.
hold -> Does not meet policy
What it writes on the lot
A ClearGate hold left on the lot by an earlier decision is lifted. The earlier record itself is never rewritten.
What happens to the order next
Under Standard or Lenient the Passport releases as soon as the lot's own floor is met, stamped with the policy id and version that authorized it. Under Strict the release stays with a person. If an enforcement or recall signal lands on the supplier after this Allow, the entry is marked superseded and asks for a re-run.
Reason codes it can carry
lot_pendingThe lot is pending review.
file_incompleteThe qualification file is not complete.
below_min_completenessThe qualification file is below the policy minimum percent complete.
file_attentionA document renewal or supplier review is coming due.
needs_human_reviewPolicy requires a human-reviewed lot.
no_fileNo supplier qualification file is on record for this supplier.
What it writes on the lot
No hold is stamped, and a hold left by an earlier decision is lifted.
What happens to the order next
The order stays yours to decide. If you turned on Require a ClearGate Allow before a passport, a release attempt on this lot answers 409 cleargate_required until an Allow is on record.
Reason codes it can carry
fda_enforcement_hitFDA enforcement or recall signal(s) on the source.
accreditation_expiredAccreditation is expired.
recall_exposureThis lot is exposed to an FDA recall or enforcement signal.
lot_flaggedThe lot is flagged.
file_overdueThe qualification file is overdue: an expired document or an overdue review.
no_fileNo supplier qualification file is on record, and policy holds on an unqualified source.
custom_requiredA custom policy item is required and not attested.
What it writes on the lot
clearGateHold is stamped on the lot, which blocks a Passport on its own.
What happens to the order next
A release attempt on that lot is refused with a 409: cleargate_hold where the lot is otherwise cleared, lot_pending_review where it is not. Close the reason that fired and the next decision lifts the hold. The held decision stays in the log exactly as it was written.
A ClearGate decision always means the documentation meets your policy. It never means Veritura approves the supplier.
Veritura does not test medicine, approve suppliers, recommend purchases, or make medical, legal, product-safety, or FDA-approval determinations. There is no paid or subjective placement: suppliers cannot pay for a better result or a better position, no listing fee, no subscription, and no pay-to-rank. Where results are ordered rather than filtered, the order is set by a published documentation-coverage grade, and that grade is never a recommendation, a preference, or a statement about any product.
What the gate reads
A screen is not one lookup. Supplier documentation, substance eligibility, prescriber registry, and the qualification file all run, and the composite verdict is the worst of the four.
Four independent evidence rails converge into a versioned operational receipt.
All required evidence rails resolved
All four rails fire on every screen and the worst rail governs; all four resolving is what produces an Allow. A decision about an order against the policy you set, never a statement that the medicine is safe, effective, or approved.
Local sample data. Not a live account. Every supplier, lot, order, and document shown here is fictional.
Documentation against your policy. The supplier's qualification file and the lot are evaluated against the rules you turned on, and every reason names the rule that fired.
Live FDA lists. Whether a substance is eligible to compound for your facility type is resolved against the current bulks, do-not-compound, and shortage lists, as a decision against your eligibility policy, never a legal opinion.
NPPES, live. A prescriber NPI or a name scoped to a state is resolved against the public registry at the moment of the screen.
Your supplier record. The six-element file's own rollup, current, due, or overdue, is read as a rail in its own right, so a file that stopped moving shows up at order time.
All four rails fire; the worst rail governs. One signed verdict, a decision against your policy, never an approval. A rail you did not provide inputs for is marked not provided and does not affect the verdict.
Supplier, product, lot, order reference, and optionally a prescriber NPI or name. All four rails fire and the composite verdict is signed.
One line per supplier, product, and lot. One signed decision per line, and the worst decision governs the PO.
The supplier documentation rail on its own, for when a supplier name is all you have. The full screen runs this plus three more rails.
A preset is the floor, not the ceiling. Every preset holds on the hardest public-record signals; what changes is how much of the file has to be in place before an order clears, and who pulls the trigger on release.
Everything must be complete, current, and human-reviewed. Any hard signal holds, and a supplier with no qualification file at all is a hard hold rather than a soft review.
A cleared lot, a current file, and no hard signals. Gaps drop to review rather than hold. This is the default when no policy has been saved.
Only the hardest public-record signals hold. An FDA enforcement hit on the source and recall exposure on the lot still stop the order; everything else allows.
Every saved check or received shipment re-evaluates this policy against the lot and stores the signed decision, with no one having to click Run. All three presets do this.
A passport releases the moment its lot is cleared, carries no hold, and satisfies this policy. The release is stamped with the exact policy version that authorized it. Standard and Lenient do this; Strict does not.
The difference is who pulls the trigger, never what gets recorded. An automatic decision produces the same signed, hash-chained, replayable record a manual run produces. The floor still governs either way: an uncleared lot, a lot carrying a hold, or a lot exposed to a recall never publishes a passport.
Above the preset floor sits a fixed library of toggles and one threshold. Each maps to a field ClearGate evaluates, so a policy can never ask the gate for a judgment it does not make.
Hold if the lot is flagged; review if it is still pending.
Review until all six file elements are satisfied.
Hold on an expired document or overdue review; review when one is coming due.
Hold when the accreditation on file is past its renewal date.
Hold when the source matches an FDA enforcement or recall record.
Hold when the lot is exposed to a recall signal.
Review until a person has reviewed the lot, not just the automated gate.
Hold, not just review, when there is no qualification file on record for the supplier, so the gate can stop an order from a source you have never qualified.
Block issuing an Evidence Passport on a lot until it has passed ClearGate with an Allow decision, so the policy rail cannot be skipped.
Every saved check or received shipment re-evaluates this policy against the lot and stores the signed decision, with no one having to click Run.
A passport releases the moment its lot is cleared, carries no hold, and satisfies this policy. Billing applies exactly as on a manual release.
Review when the qualification file is below this percent complete. Set anywhere from 0 to 100.
Add your own required documents, an insurance certificate on file, for example. They are never auto-graded: a required item that has not been attested holds the order, and an attested item carries who attested it and when.
Every element is labeled Veritura evaluated, read from the document or a public source, or Operator attested, where you confirm what we cannot read. The file never overstates what was checked.
A decision nobody can reconstruct is an opinion. Every ClearGate decision is signed, chained to the one before it, and re-runnable from its own stored evidence.
Each decision carries a signature and a hash over the decision before it. The log shows whether the chain is intact, so a record that was altered cannot pass as one that was not.
A decision stores the evidence it read and a snapshot of the policy version that governed it. Replaying it re-runs the same evaluator against the same inputs, and a correct decision replays to the identical decision, label, and reasons.
Every reason names the policy rule that fired and the level it fired at, so the log answers why this order held rather than only that it did.
Each entry downloads as a signed determination PDF for the batch record, alongside the whole-log export.
When a supplier recall lands after an Allow, that entry is marked superseded and asks for a re-run. The signed record itself is never rewritten.
The console names the preset and the policy version that is governing right now, so a decision is never read against a policy you have since changed.
AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.
Six-document packet complete; issuing lab confirmed the COA
Sterility and endotoxin evidence not supplied
COA lot and shipment label do not match; route unreachable
Six of six qualification elements on file; packet complete
Packet complete; no indexed reuse signal
Packet complete; residual solvents within the printed specification
Undisclosed salt form on the COA; net peptide content unstated
Packet complete; certificate of conformance on file
Call one endpoint at order time and get one decision against the policy you set, with a tamper-evident signed record behind it. Wire it into your fulfillment, Shopify, or pharmacy system.
POST /v1/cleargate, one decision per order against the policy you set: meets your policy, needs review, or does not meet policy.
Send a lot_id, or send supplier with optionally product and lot and the lot is resolved for you. Supplier is required when no lot_id is given.
Your own order or PO reference. It is carried on the signed decision so the record and your system agree on what was decided.
Self-serve from Settings. A test key returns a sandbox decision, a live key a production one, and the response says which environment it came from. Rotate any time, revoke instantly.
The API and the dashboard run the same decision path, so a decision made by an integration is indistinguishable in the log from one made by a person.
POST/v1/cleargateOne decision per order against the policy you set: meets your policy, needs review, or does not meet policy.
POST/v1/eligibilityAllow, Review, or Hold on whether a substance is eligible to compound for a facility type against the current FDA lists.
POST/v1/passportsIssue from a cleared lot with an order reference. The cleared lot is the gate, so an uncleared lot can never publish a passport.
401A valid API key is required: Authorization: Bearer vk_live_... (or vk_test_...).
400Provide supplier (and optionally product + lot), or a lot_id.
Subscribe to passport.issued, lot.recall_hit, and supplier.alert. Every delivery is HMAC-signed in the X-Veritura-Signature header, so a recall that lands after fulfillment finds its way back to your systems.
Platform accounts pre-commit a year of passport volume upfront at a bought-down rate.
The intake gate for each shipment: match the label to the paperwork, read the micro evidence, and set the lot state before anything moves downstream.
ClearGate decides an order against your policy and answers in Allow, Review, or Hold. The Receiving Gate dispositions a shipment and sets the lot state that ClearGate then reads. Two gates, two vocabularies, and they are never interchanged: a receiving disposition is not a ClearGate decision, and neither one is an evidence posture of Clear, Review, or Hold.
The seven gates, every tier each one can resolve to, and the branch that picks a disposition are documented where the work happens, on receiving for compounding pharmacies.
Every gate is satisfied on the record: the label reconciles to the paperwork, the COA is present, and the micro evidence is attached rather than asserted.
Sets the lot to cleared
A documentation gap is open that the supplier has to close. The gate drafts the exact ask, naming the evidence it needs for this exact lot.
Sets the lot to pending review
The certificate is missing, or a micro result was marked present with no source result, method, or evidence reference behind it. Nothing moves downstream on an assertion.
Sets the lot to pending review
Neither one can be settled on paper at the bench. The record routes to a person and names what has to be reconciled before any reliance.
Sets the lot to flagged
A documentation release on this gate does not clear a lot whose flag came from a recall signal, from a routing for human review, or from a high-severity finding on its documentation. A receipt cannot answer a document finding; a corrected certificate can. And a re-receipt that comes back quarantine or correction supersedes an earlier clear until the gates pass again.
This is where the two axes meet, and the only place they touch. The disposition sets the lot state; the lot state is one of the inputs ClearGate evaluates against your policy. When your policy has auto-decide on, ClearGate re-runs against the lot the moment the receipt is saved, through the same path a manual run uses.
Documentation receiving gate only. This is not a product quality, safety, efficacy, compliance, or FDA-approval determination.
Before money moves, so a bad source is caught before it ships, not after.
Veritura reads and connects the paperwork behind an order. It never tests, grades, or endorses the medicine itself, and it never releases anything on its own.

Supplier documentation against your policy, substance eligibility against the current FDA lists, the prescriber against the public NPPES registry, and the supplier's qualification file. All four fire, and the worst rail governs.
Review names what is pending, such as a renewal coming due. Hold names hard signals, such as an enforcement match on the source, and a hold blocks a Passport on its own. Hold beats review beats allow.
Yes. Strict, Standard, and Lenient are presets, and every one still holds on the hardest public-record signals. What changes is how much of the file must be in place and who releases.
Still have questions? Talk to a person.