One record per order, binding it to the product, lot, certificate, supplier packet, and reviewer behind it. It publishes only from a lot that has cleared its documentation, and it stays bound to that lot afterwards.

Six steps run between the order shipping and a buyer opening the link, and the cleared lot is the gate at step two. That is why an uncleared lot can never publish one, why a refusal comes back naming the requirement that was not met, and why a recall published months after release can still reach an issued passport through its permanent lot binding.
Six steps, and the cleared lot is the gate at step two.
01
One lot, one order, and the documents behind them. Completeness is stated in plain words with no score, every reported value is shown exactly as the certificate documents it, and the limits are printed on the face of the card rather than in a footer. Veritura reads and records the values. It does not perform or repeat any test.
The person holding the vial and the pharmacist answering for it read the same facts at different depths, so the audit-grade detail is one tap away rather than deleted.

02
Eight links, and the field each one stores: the order, the represented product, the lot, the certificate, the supplier packet, the reviewer, the source file, and the methodology version. The lot binding is permanent, which is the only reason a recall published months after release can still reach a passport that has already been opened by a patient.
The eight links are stored fields, not a summary. A recall published months after release still reaches an issued passport through its permanent binding to the lot.

03
Release is not a status a person sets. It is a gate, and a refusal comes back naming the requirement that was not met rather than failing quietly: the lot is not cleared, a ClearGate hold stands, a recall signal stands, the qualification file is below the policy minimum, a required custom item is not attested, or your policy requires a human-reviewed lot.
A refusal names the requirement that was not met, in words a reviewer can act on: attach the missing file, ask the supplier, resolve the hold, or wait for the human-reviewed lot.

04
Internal notes, pricing, supplier approval language, and private account context are filtered before anything reaches a customer surface. A patient scanning a vial and a buyer opening a shared link read the same document set as the workspace does, in four plain-language lines computed from the same read, with nothing a patient could mistake for a grade.
Customer-facing means filtered, not simplified into a grade. The four plain-language lines are computed from the same read the workspace uses, so nothing is restated by hand.

05
Veritura attaches the evidence layer per order. It does not replace procurement, inventory, pharmacy, ecommerce, or ERP records, and the passport carries your order reference so the person holding the vial can match it against their own packing slip. That match is what turns a vial of this lot into the vial released for their order.
Procurement, inventory, pharmacy, and ecommerce records stay where they are. Veritura attaches the evidence layer per order and carries your order reference so the packing slip is the join.

What changes
One record per order, bound permanently to the product, lot, certificate, packet, and reviewer.
Four plain-language lines computed from the same read, internal context filtered out.
The lot binding is permanent, so a notice months later reaches every passport it touched.
The method
Documents arrive by email, upload, or API and are retained as received.
Read against identity anchors, your policy, and named public sources.
A named person signs every material decision, with the reason kept.
Cleared orders issue serialized Passports and Seals.
Every document and decision stays on the record for seven years.
Customer-facing passports and internal traceability records follow the same release contract.
Released, blocked, source-review, or human-QA required: the record's release state, not an evidence posture.
Order, product, lot, certificate, supplier packet, reviewer, and source file, each pointing back to where it came from.
Source intake, extraction, reconciliation, QA, release, and archive state, in the order they happened.
Documentation evidence only. No product-quality or supplier-approval language anywhere on the record.
Attach the missing file, ask the supplier, release the customer link, or hold reliance.
The complete text, for the reader who wants the whole story before a call.
One lot, one order, and the documents behind them. The completeness read is stated in plain words with no score, every reported value is shown as the certificate documents it, and the limits are on the face of the card rather than in a footnote.
The same record serves a patient who scanned a vial and a buyer who was sent a link. What changes between them is nothing.
Every required field was present on the documents for this lot, and no serious finding stood against them. A paperwork read, never a statement that the medicine is safe, effective, or approved.
PreparationSemaglutide (base) API
LotLOT-7741-A
Quantity250 g
SupplierAurora Pharma Supply
ReceivedJuly 22, 2026
ReleasedJuly 23, 2026
As documented on the certificate
IdentityConforms
Purity (HPLC)98.7%
EndotoxinBelow limit
SterilityNot applicable
Values as printed by the issuing laboratory. Veritura reads and records them. It does not perform or repeat any test.
Where each line came from
Notices on this lot
Veritura reads documentation. It does not grade the medicine, approve a supplier, or certify a product. Questions about your treatment stay with the pharmacy or prescriber who dispensed it.
Local sample data. Not a live account. Every supplier, lot, order, and document shown here is fictional.
How a passport is issued
Six steps run between the order shipping and a buyer opening the link. The cleared lot is the gate at step two, which is why an uncleared lot can never publish one.
An order ships, from the workspace or from the API.
The order is written with its lot number. The lot is resolved by number within the account and stamped as an exact reference. An ambiguous lot number matching several lots is refused, never guessed.
The floor is checked: the lot must exist, be cleared, carry no ClearGate hold and no recall signal, and satisfy any human-review or ClearGate-Allow requirement the policy sets.
A live recall blocks the mint on its own, independent of state, so the gate never rests solely on clearGateHold.
The order arrived before its lot cleared.
The order parks rather than releasing on its own say-so. Nothing is lost and nothing is published.
The lot clears: the source is named, the missing document lands, the receiving gate passes.
When the account's policy authorizes unattended release, the parked order releases through the same sanctioned path, stamped with the exact policy id and version that authorized it and the lot evidence it rested on.
Bounded per sweep and per account, and billed through the same idempotent ledger, so a backlog clearing at once cannot produce a wave of duplicate charges.
The buyer or patient opens the shared record.
The public page prints the read, the lab and the date. It states documentation completeness in plain words and no number.
Never Clear, Review or Hold. See CUSTOMER_BAND_VOCABULARY.
A passport is issued.
A passport.issued event fires to any subscribed endpoint, signed with an HMAC over the body. Internal, loopback, link-local and private targets are refused outright.
An Evidence Passport publishes what the documentation for a lot states and where it came from. It is not a certificate of quality, an approval, or a statement about the medicine.
Eight links, and the field each one stores. The lot binding is permanent, which is the only reason a recall published months after release can still reach an issued passport.
Workspace or account. A lot number resolves within the account, and a number matching several lots is refused rather than guessed.
orderId and customerRef. A customer reference that reads like patient information is rejected outright.
supplierName and productName: the identity of what shipped, as the record states it.
sourceLotId, bound permanently. This is the link a later recall travels along to reach a record already issued.
coaId, reportId and labName, plus the file, text, structure and visual fingerprints, so reuse of one certificate across lots stays visible.
supplierPacketId and memoId: the qualification file and the diligence memo the release rested on.
reviewer, and the release authority itself. A lot a person reviewed stamps human_reviewed_lot rather than auto_cleared_lot.
publicShareId and unitCount: the public reference at /verify/<publicShareId>, and how many physical units it covers.
Veritura attaches the evidence layer per order. It does not replace procurement, inventory, pharmacy, ecommerce, or ERP records.
CSV, API, or partner intake should pass the same core fields: client, order, API/product, lot, COA, supplier packet, reviewer, and release status.
Every customer-safe passport and internal traceability record follows the same release contract: verdict, evidence chain, replay, boundary, next action, and export package.
Released, blocked, source-review, or human-QA required. This is the record's release state, not an evidence posture and not a ClearGate decision.
Order, API/product, lot, COA, supplier packet, reviewer, and source file.
Source intake, extraction, reconciliation, QA, release, and archive state.
Documentation evidence only. No product-quality or supplier-approval claim.
Attach missing file, ask supplier, release customer link, or hold reliance.
Passport link, evidence room, audit trail, weekly rollup, and usage event.
Internal notes, pricing, supplier approval language, and private account context are filtered before release.
Release is not a status a person sets. It is a gate, and a refusal comes back naming the requirement that was not met rather than failing quietly.
One floor governs the mint route, the operator release route and the unattended rail alike, so nothing releases around it. A live recall signal blocks the mint on its own, independent of every other state on the record.
Replay the path from client order event to source attachment, field extraction, reconciliation, memo QA, customer-safe release, and archive state.
If the source-to-decision path cannot be explained, the passport stays in operator review.
AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.
The person holding the vial and the pharmacist answering for it want the same facts at very different depths, so the audit-grade detail is one tap away rather than deleted.
The document set met the configured policy. It describes the paperwork, not the medicine.
The issuing laboratory confirmed issuance through the recorded verification route.
OrderPO-DEMO-0413
LotLOT-7741-A
SupplierAurora Pharma Supply
Quantity250 g
ReceivedJuly 22, 2026
ReleasedJuly 23, 2026
Passport issuedJuly 23, 2026
Methodologyv1.0 · April 30, 2026
COA-7741-A.pdf · Issuing laboratory confirmed issuance through the recorded route
CoC-7741.pdf · Required identity, lot, and date fields present
SDS-SEMA-04.pdf · Current revision on file
GMP-AUR-2026.pdf · Supplied by the operator
Recorded in workspace · Container and label checked at receipt
LBL-7741-A.jpg · Lot identifier matches the certificate of analysis
This is the operator's view of one released passport. Every panel on it answers a different question, and two of them are on different axes that look alike until you read the label above them.
The document set for this lot, in the workspace's own vocabulary. Only a complete read with a named supplier and lot number reaches this state; anything thin, unreadable or unidentified stays pending, and one high-severity finding is enough to flag it.
Evidence origin, which is provenance rather than a verdict, so it carries no status dot at all. Source-confirmed is set by one thing only: the issuing laboratory's own recorded reply.
Order, lot, supplier and quantity, then the dates the lot was received and released and the passport issued, stamped with the methodology version the read ran under.
Each document with the origin that established it. The record binds coaId, reportId and labName alongside the file, text, structure and visual fingerprints, which is what makes one certificate reused across two lots visible at all.
This panel is the workspace. The public page a patient opens states documentation completeness in plain words and prints no number, and the workspace posture vocabulary above never appears on it.
Shown to the patient or buyer: Documentation reads complete
Part of the record, not fine print under it. The shipping product renders it inside the passport at the same size as the evidence above it, and this page reproduces it the same way.
An Evidence Passport publishes what the documentation for a lot states and where it came from. It is not a certificate of quality, an approval, or a statement about the medicine.
A patient scanning a vial and a buyer opening a shared link read the same document set as the workspace does, in four plain-language lines computed from the same read.
Documentation reads completeEvery required field was present and no high-severity finding stood against the document set. The customer page states this in words and shows no number.
Documentation has gapsThe partial and the sparse band both print this one line. The band only ever tightens, so nothing that read partial can later be shown as clean.
Largely undocumentedAlmost nothing a certificate is expected to state was recovered from the document.
Could not read this documentToo little was recovered from the file to form a record. Nothing is scored and no gaps are raised, because those fields were not absent, they were not extracted.
The patient page prints the band in words and no numeric score. A number beside the name of someone's medicine reads as a quality grade, which it is not.
A paperwork-completeness read, never a product-quality or safety determination.
This page shows what the paperwork for your batch says, checked by Veritura, which is independent of the pharmacy and the supplier.
Read from the certificate of analysis for this batch. Veritura keeps the paperwork record and checks each result against the limit printed beside it. It does not test the medicine itself.
Customer-facing evidence is separated from internal notes, pricing, and supplier-approval language.
Documentation evidence only. This does not approve a supplier, certify quality, confirm safety, provide medical guidance, or replace wet-lab testing.
Everything an auditor or a pharmacist would want is kept in full behind one toggle, not removed from the page.
A paperwork-completeness read, never a product-quality or safety determination. The PDF copy exists to hand to a clinician; nothing pushes one at a patient.
Veritura is independent of the pharmacy that dispensed this medicine and of the supplier who made it. We read the paperwork behind a batch and keep the record. Documentation status only, never a quality, safety, or FDA-approval determination.
Paste the verification link or record ID from a Veritura Evidence Passport or Verified Supplier record, and we will resolve the documentation read.
Every released record resolves from its own verify address, and the lookup also takes a pasted record ID. A vial QR is scanned on a phone, so that is the surface the page is built for first.
An automated read of the submitted document by a party that does not sell the product. A tamper-evident fingerprint you can cross-check against the original certificate. Documentation completeness, source chain, and reuse signals.
The browser recomputes SHA-256 over the record's canonical fields, in that exact order, using its own WebCrypto, and compares the result against the fingerprint printed on the record.
No released record for this link. The evidence record is not released for verification, or the link is incorrect. If you received it from a supplier, ask them for a current Veritura verification link.
On a partner-branded host the partner's own mark leads, and the line under it reads "Independently verified by Veritura". It renders whenever a partner brand does, and there is no way to configure it off.
Veritura is independent and reviews documentation only. A verified record is not a certification, an approval, or a claim that any product is safe, effective, legal, or FDA-approved.
Clean yesterday can become review-needed tomorrow.
Lot search becomes an action map. Search or select a lot and the ledger shows affected orders, buyers, COAs, supplier packets, and unresolved evidence gaps.
Evidence records are watched for stale COAs, new public-source posture, supplier changes, and repeat-reliance refresh windows.
Public FDA recall and enforcement notices naming the supplier keep being read after release. A notice names the supplier, not necessarily the batch, and the record says exactly that instead of raising an alarm about someone's prescription.
Your document evidence is compared across the Veritura account network, not just this workspace. Counts only: no other account's identity, supplier, files, lots, or customers are shown.
Every passport, supplier response, and release event stays traceable.
Every released record strengthens supplier, lot, COA, reviewer, and dispute history.
The passport stays bound to its lot forever. That binding is the whole mechanism: without it a signal landing after release would have nothing to travel along.
A flagged lot has passports minted from it.
Every passport bound to that lot is stamped with a post-release recall signal. Stamping is idempotent: the record stays in the FDA window for its whole duration, so a repeat sweep refreshes the existing signal in place rather than stacking duplicates.
The passport stays bound to its lot forever, which is what lets a later recall reach it at all.
Each affected account is notified privately: a lot.recall_hit webhook and an email to the account owner, each seeing only its own lots. The fan-out is deduped so a given account, lot and recall fires once.
The lot now carries a recall signal.
No new passport can mint or release from it, independent of every other state on the record.
A lot-number match against public FDA enforcement data is a documentation and enforcement signal, never a safety or approval determination. A lot number can be reused across firms, so the firm identity and the lot must be confirmed against the FDA record.
A binder tells you a lot was received. It cannot tell you who is still holding a vial from it. Release is what turns the record into a reachable list.
A passport is bound to its lot at issue and the link is never rewritten. That binding is the path a recall published months later travels back along to every record already issued from that lot.
Scanning the seal on the vial opens the record, and a patient can claim it with an email address. The claim starts pending and only the emailed link activates it, so nobody is added to a list they did not ask to be on.
When a signal lands, a single action notifies every active claimant across every seal batch of that lot, deduplicated so one address gets one message, each deep-linked to the record it concerns.
The record stores an email address, the saved serials, and the notice history for those serials. No name, no address, no health information, and no field for them. Deletion is self-serve.
A notice states what was published about a lot and links to the record. It is not a recall, not a clinical judgment, and not medical advice; the treatment question stays with the pharmacy or the prescriber who dispensed it.
A shareable, per-order proof of the documentation review behind a specific order. One link, one PDF.
per released production Passport, pay as you go and separate from your planper Passport at 500 or more per month, on a volume agreementCustoma committed rate for high-volume platforms
Sandbox Evidence Passport records are free and non-billable, up to 25 records.First oneYour first released production Evidence Passport is complimentary when that offer is enabled.
Sandbox records are free for testing.
A released production passport. Dashboard views and sandbox records do not create production usage events.
Production usage is controlled by client workspace rules, not dashboard views or repeated edits.
Sandbox records are non-billable and clearly labeled. Production evidence records unlock only after a paid or signed client workspace.
On the shipping product the boundary renders inside the record, at the same size as the evidence above it. It is reproduced here the same way.
Veritura does not test medicine, approve suppliers, recommend purchases, or make medical, legal, product-safety, or FDA-approval determinations. There is no paid or subjective placement: suppliers cannot pay for a better result or a better position, no listing fee, no subscription, and no pay-to-rank. Where results are ordered rather than filtered, the order is set by a published documentation-coverage grade, and that grade is never a recommendation, a preference, or a statement about any product.
A COA check or Passport records whether the documents are complete and consistent. It is not a safety, quality, efficacy, legality, or FDA-approval claim.
Documentation evidence only. This does not approve a supplier, certify quality, confirm safety, provide medical guidance, or replace wet-lab testing.
This workspace can show internal notes, source gaps, and QA posture. The customer passport does not show internal pricing, private notes, supplier approval language, product-quality claims, or legal/medical conclusions.
Documentation evidence, traceability, workflow control, and customer-safe proof only. No supplier approval, product-quality certification, legal advice, medical advice, or wet-lab replacement claims are generated by this layer.
Evidence posture only. Not supplier approval, product-quality certification, legal advice, medical advice, or wet-lab replacement.
Produced under methodology v1.0, April 30, 2026.
Veritura reads and connects the paperwork behind an order. It never tests, grades, or endorses the medicine itself, and it never releases anything on its own.

Only from a lot that has cleared its documentation. An uncleared lot cannot publish one, and a refusal names the requirement that was not met rather than failing quietly.
One lot, one order, and the documents behind them, in plain words with no score. Values are shown exactly as the certificate documents them, and the limits are printed on the face of the record.
The lot binding is permanent, so a post-release signal is stamped on every passport minted from that lot, and anyone who saved a vial is reached through their own account, without a name ever entering the pharmacy’s or the clinic’s record.
Still have questions? Talk to a person.