Every client order gets its own proof record.

One record per order, binding it to the product, lot, certificate, supplier packet, and reviewer behind it. It publishes only from a lot that has cleared its documentation, and it stays bound to that lot afterwards.

A passport is minted from a lot, never from a claim

Six steps run between the order shipping and a buyer opening the link, and the cleared lot is the gate at step two. That is why an uncleared lot can never publish one, why a refusal comes back naming the requirement that was not met, and why a recall published months after release can still reach an issued passport through its permanent lot binding.

From the order shipping to the buyer opening the link.

Six steps, and the cleared lot is the gate at step two.

01

The record a person actually opens

One lot, one order, and the documents behind them. Completeness is stated in plain words with no score, every reported value is shown exactly as the certificate documents it, and the limits are printed on the face of the card rather than in a footer. Veritura reads and records the values. It does not perform or repeat any test.

The person holding the vial and the pharmacist answering for it read the same facts at different depths, so the audit-grade detail is one tap away rather than deleted.

  • Plain words, never a score
  • Values as printed by the issuing laboratory
  • Limits on the face of the record
Discover Methodology
The record a person actually opens: a designed view of the Veritura workspace

02

What the record binds, link by link

Eight links, and the field each one stores: the order, the represented product, the lot, the certificate, the supplier packet, the reviewer, the source file, and the methodology version. The lot binding is permanent, which is the only reason a recall published months after release can still reach a passport that has already been opened by a patient.

The eight links are stored fields, not a summary. A recall published months after release still reaches an issued passport through its permanent binding to the lot.

  • Eight links, each with its stored field
  • Lot binding is permanent
  • Methodology version stamped on every record
Discover Order-level COA traceability
What the record binds, link by link: a designed view of the Veritura workspace

03

Six ways a release stops

Release is not a status a person sets. It is a gate, and a refusal comes back naming the requirement that was not met rather than failing quietly: the lot is not cleared, a ClearGate hold stands, a recall signal stands, the qualification file is below the policy minimum, a required custom item is not attested, or your policy requires a human-reviewed lot.

A refusal names the requirement that was not met, in words a reviewer can act on: attach the missing file, ask the supplier, resolve the hold, or wait for the human-reviewed lot.

  • A gate, not a status
  • Every refusal names the unmet requirement
Discover Supplier packet diligence
Six ways a release stops: a designed view of the Veritura workspace

04

Customer-facing only after QA

Internal notes, pricing, supplier approval language, and private account context are filtered before anything reaches a customer surface. A patient scanning a vial and a buyer opening a shared link read the same document set as the workspace does, in four plain-language lines computed from the same read, with nothing a patient could mistake for a grade.

Customer-facing means filtered, not simplified into a grade. The four plain-language lines are computed from the same read the workspace uses, so nothing is restated by hand.

  • Internal context filtered before release
  • Same document set, four plain lines
  • Nothing a patient could mistake for a grade
Discover Trust Center
Customer-facing only after QA: a designed view of the Veritura workspace

05

Your order system stays the source of truth

Veritura attaches the evidence layer per order. It does not replace procurement, inventory, pharmacy, ecommerce, or ERP records, and the passport carries your order reference so the person holding the vial can match it against their own packing slip. That match is what turns a vial of this lot into the vial released for their order.

Procurement, inventory, pharmacy, and ecommerce records stay where they are. Veritura attaches the evidence layer per order and carries your order reference so the packing slip is the join.

  • Attached per order, never a replacement
  • Your order reference printed on the record
  • The packing slip is the join
Discover The evidence engine
Your order system stays the source of truth: a designed view of the Veritura workspace

What changes

What you get, in practice.

01Proof that travels with the order

One record per order, bound permanently to the product, lot, certificate, packet, and reviewer.

02Customer-facing without a grade

Four plain-language lines computed from the same read, internal context filtered out.

03A recall that still finds the order

The lot binding is permanent, so a notice months later reaches every passport it touched.

The method

1. Intake

Documents arrive by email, upload, or API and are retained as received.

2. Check

Read against identity anchors, your policy, and named public sources.

3. Decide

A named person signs every material decision, with the reason kept.

4. Issue

Cleared orders issue serialized Passports and Seals.

5. Retain

Every document and decision stays on the record for seven years.

What every passport carries

Customer-facing passports and internal traceability records follow the same release contract.

Executive verdict

Released, blocked, source-review, or human-QA required: the record's release state, not an evidence posture.

Evidence map

Order, product, lot, certificate, supplier packet, reviewer, and source file, each pointing back to where it came from.

Evidence replay

Source intake, extraction, reconciliation, QA, release, and archive state, in the order they happened.

Risk boundary

Documentation evidence only. No product-quality or supplier-approval language anywhere on the record.

Next action

Attach the missing file, ask the supplier, release the customer link, or hold reliance.

Everything on this page, in full.

The complete text, for the reader who wants the whole story before a call.

The record a person actually opens.

One lot, one order, and the documents behind them. The completeness read is stated in plain words with no score, every reported value is shown as the certificate documents it, and the limits are on the face of the card rather than in a footnote.

The same record serves a patient who scanned a vial and a buyer who was sent a link. What changes between them is nothing.

Every required field was present on the documents for this lot, and no serious finding stood against them. A paperwork read, never a statement that the medicine is safe, effective, or approved.

PreparationSemaglutide (base) API

LotLOT-7741-A

Quantity250 g

SupplierAurora Pharma Supply

ReceivedJuly 22, 2026

ReleasedJuly 23, 2026

As documented on the certificate

IdentityConforms

Purity (HPLC)98.7%

EndotoxinBelow limit

SterilityNot applicable

Values as printed by the issuing laboratory. Veritura reads and records them. It does not perform or repeat any test.

Where each line came from

  • Certificate of analysisSource-confirmed
  • Certificate of conformanceVeritura evaluated
  • Safety data sheetVeritura evaluated
  • Notices on this lot

    Veritura reads documentation. It does not grade the medicine, approve a supplier, or certify a product. Questions about your treatment stay with the pharmacy or prescriber who dispensed it.

    Local sample data. Not a live account. Every supplier, lot, order, and document shown here is fictional.

    How a passport is issued

A passport is minted from a lot, never from a claim.

Six steps run between the order shipping and a buyer opening the link. The cleared lot is the gate at step two, which is why an uncleared lot can never publish one.

An order ships, from the workspace or from the API.

The order is written with its lot number. The lot is resolved by number within the account and stamped as an exact reference. An ambiguous lot number matching several lots is refused, never guessed.

The floor is checked: the lot must exist, be cleared, carry no ClearGate hold and no recall signal, and satisfy any human-review or ClearGate-Allow requirement the policy sets.

A live recall blocks the mint on its own, independent of state, so the gate never rests solely on clearGateHold.

The order arrived before its lot cleared.

The order parks rather than releasing on its own say-so. Nothing is lost and nothing is published.

The lot clears: the source is named, the missing document lands, the receiving gate passes.

When the account's policy authorizes unattended release, the parked order releases through the same sanctioned path, stamped with the exact policy id and version that authorized it and the lot evidence it rested on.

Bounded per sweep and per account, and billed through the same idempotent ledger, so a backlog clearing at once cannot produce a wave of duplicate charges.

The buyer or patient opens the shared record.

The public page prints the read, the lab and the date. It states documentation completeness in plain words and no number.

Never Clear, Review or Hold. See CUSTOMER_BAND_VOCABULARY.

A passport is issued.

A passport.issued event fires to any subscribed endpoint, signed with an HMAC over the body. Internal, loopback, link-local and private targets are refused outright.

An Evidence Passport publishes what the documentation for a lot states and where it came from. It is not a certificate of quality, an approval, or a statement about the medicine.

What the record binds, link by link.

Eight links, and the field each one stores. The lot binding is permanent, which is the only reason a recall published months after release can still reach an issued passport.

Client

Workspace or account. A lot number resolves within the account, and a number matching several lots is refused rather than guessed.

Order

orderId and customerRef. A customer reference that reads like patient information is rejected outright.

API / product

supplierName and productName: the identity of what shipped, as the record states it.

Lot

sourceLotId, bound permanently. This is the link a later recall travels along to reach a record already issued.

COA

coaId, reportId and labName, plus the file, text, structure and visual fingerprints, so reuse of one certificate across lots stays visible.

Supplier packet

supplierPacketId and memoId: the qualification file and the diligence memo the release rested on.

Reviewer

reviewer, and the release authority itself. A lot a person reviewed stamps human_reviewed_lot rather than auto_cleared_lot.

Passport

publicShareId and unitCount: the public reference at /verify/<publicShareId>, and how many physical units it covers.

The client's order system stays the source of truth.

Veritura attaches the evidence layer per order. It does not replace procurement, inventory, pharmacy, ecommerce, or ERP records.

CSV, API, or partner intake should pass the same core fields: client, order, API/product, lot, COA, supplier packet, reviewer, and release status.

Order traceability should read like an operating record, not a data dump.

Every customer-safe passport and internal traceability record follows the same release contract: verdict, evidence chain, replay, boundary, next action, and export package.

Executive verdict

Released, blocked, source-review, or human-QA required. This is the record's release state, not an evidence posture and not a ClearGate decision.

Evidence map

Order, API/product, lot, COA, supplier packet, reviewer, and source file.

Evidence replay

Source intake, extraction, reconciliation, QA, release, and archive state.

Risk boundary

Documentation evidence only. No product-quality or supplier-approval claim.

Next action

Attach missing file, ask supplier, release customer link, or hold reliance.

Export package

Passport link, evidence room, audit trail, weekly rollup, and usage event.

Customer-safe only after QA

Internal notes, pricing, supplier approval language, and private account context are filtered before release.

Six ways a release stops.

Release is not a status a person sets. It is a gate, and a refusal comes back naming the requirement that was not met rather than failing quietly.

One floor governs the mint route, the operator release route and the unattended rail alike, so nothing releases around it. A live recall signal blocks the mint on its own, independent of every other state on the record.

Every passport should show how proof became safe to release.

Replay the path from client order event to source attachment, field extraction, reconciliation, memo QA, customer-safe release, and archive state.

If the source-to-decision path cannot be explained, the passport stays in operator review.

AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.

One record, three readers.

The person holding the vial and the pharmacist answering for it want the same facts at very different depths, so the audit-grade detail is one tap away rather than deleted.

Semaglutide (base) API

The document set met the configured policy. It describes the paperwork, not the medicine.

The issuing laboratory confirmed issuance through the recorded verification route.

OrderPO-DEMO-0413

LotLOT-7741-A

SupplierAurora Pharma Supply

Quantity250 g

ReceivedJuly 22, 2026

ReleasedJuly 23, 2026

Passport issuedJuly 23, 2026

Methodologyv1.0 · April 30, 2026

Documents on file

COA-7741-A.pdf · Issuing laboratory confirmed issuance through the recorded route

CoC-7741.pdf · Required identity, lot, and date fields present

SDS-SEMA-04.pdf · Current revision on file

GMP-AUR-2026.pdf · Supplied by the operator

Recorded in workspace · Container and label checked at receipt

LBL-7741-A.jpg · Lot identifier matches the certificate of analysis

What this record does not establish

  • Documentation diligence only. No product was tested and no supplier was approved.
  • Absence of a public-source match is not proof of absence.
  • Produced under methodology v1.0, April 30, 2026.
  • The workspace record, region by region.

    This is the operator's view of one released passport. Every panel on it answers a different question, and two of them are on different axes that look alike until you read the label above them.

    Evidence posture

    The document set for this lot, in the workspace's own vocabulary. Only a complete read with a named supplier and lot number reaches this state; anything thin, unreadable or unidentified stays pending, and one high-severity finding is enough to flag it.

    Certificate of analysis

    Evidence origin, which is provenance rather than a verdict, so it carries no status dot at all. Source-confirmed is set by one thing only: the issuing laboratory's own recorded reply.

    The identity row

    Order, lot, supplier and quantity, then the dates the lot was received and released and the passport issued, stamped with the methodology version the read ran under.

    Documents on file

    Each document with the origin that established it. The record binds coaId, reportId and labName alongside the file, text, structure and visual fingerprints, which is what makes one certificate reused across two lots visible at all.

    What a patient sees instead

    This panel is the workspace. The public page a patient opens states documentation completeness in plain words and prints no number, and the workspace posture vocabulary above never appears on it.

    Shown to the patient or buyer: Documentation reads complete

    What this record does not establish

    Part of the record, not fine print under it. The shipping product renders it inside the passport at the same size as the evidence above it, and this page reproduces it the same way.

    An Evidence Passport publishes what the documentation for a lot states and where it came from. It is not a certificate of quality, an approval, or a statement about the medicine.

    What the customer surface prints.

    A patient scanning a vial and a buyer opening a shared link read the same document set as the workspace does, in four plain-language lines computed from the same read.

    Documentation reads completeEvery required field was present and no high-severity finding stood against the document set. The customer page states this in words and shows no number.

    Documentation has gapsThe partial and the sparse band both print this one line. The band only ever tightens, so nothing that read partial can later be shown as clean.

    Largely undocumentedAlmost nothing a certificate is expected to state was recovered from the document.

    Could not read this documentToo little was recovered from the file to form a record. Nothing is scored and no gaps are raised, because those fields were not absent, they were not extracted.

    The patient page prints the band in words and no numeric score. A number beside the name of someone's medicine reads as a quality grade, which it is not.

    A paperwork-completeness read, never a product-quality or safety determination.

    What the paperwork says about your batch.

    This page shows what the paperwork for your batch says, checked by Veritura, which is independent of the pharmacy and the supplier.

  • Notices on file. Where none have been published, the page says so and says that Veritura keeps watching public FDA recall and enforcement notices naming this supplier. Where one has, it states what was found, says plainly that it may or may not involve this batch, and hands the question to the pharmacy that dispensed it.
  • What the lab measured. Each test, the limit the lab itself printed beside it, and whether the result was within the limit, outside the limit, or not compared when the units differ or no limit was printed on the document.
  • Who handled it. The supply chain as a run of named hands, naming only the parties the paperwork names.
  • Questions about your medicine. Talk to the pharmacy that dispensed it, or your prescriber, with the contact route shown only where the pharmacy published one.
  • No number. A completeness score printed next to the name of someone's medication invites arithmetic about their treatment, so the patient view carries the band in words and no score.
  • Read from the certificate of analysis for this batch. Veritura keeps the paperwork record and checks each result against the limit printed beside it. It does not test the medicine itself.

    Clean proof without internal leakage.

    Customer-facing evidence is separated from internal notes, pricing, and supplier-approval language.

  • The proof chain. Order, lot, COA, and review state, with the product and the reviewer named.
  • Evidence rows. The COA, the supplier packet, and the memo, each with its status and the workflow it came from.
  • The release state. Released proof, or review in progress. The customer link is generated on release.
  • What is never in it. Internal pricing, private notes, supplier approval language, product-quality claims, or legal and medical conclusions.
  • Documentation evidence only. This does not approve a supplier, certify quality, confirm safety, provide medical guidance, or replace wet-lab testing.

    The full record, one tap away.

    Everything an auditor or a pharmacist would want is kept in full behind one toggle, not removed from the page.

  • Identity and record ID. Supplier, product, lot, order, COA reference, reviewer, methodology version, and the date the record was verified.
  • A tamper-evident fingerprint. SHA-256 over the record's canonical fields in a fixed order, printed with the exact fields it covers. Change any field and the fingerprint changes.
  • Verify it yourself. The browser recomputes the fingerprint locally from the visible record fields and compares it against the one on the record, so no trust in the page is required.
  • Chain of evidence. The record's dated journey, each entry timestamped in UTC.
  • The checks that ran. Required document-field completeness, source-chain reconciliation, duplicate and reused-document signal scan, order/lot/COA cross-match, and the customer-safe release gate.
  • Documentation completeness at issue, in words, with how the lot cleared and on what date.
  • A paperwork-completeness read, never a product-quality or safety determination. The PDF copy exists to hand to a clinician; nothing pushes one at a patient.

    Veritura is independent of the pharmacy that dispensed this medicine and of the supplier who made it. We read the paperwork behind a batch and keep the record. Documentation status only, never a quality, safety, or FDA-approval determination.

One link, and anyone can resolve it.

Paste the verification link or record ID from a Veritura Evidence Passport or Verified Supplier record, and we will resolve the documentation read.

The link

Every released record resolves from its own verify address, and the lookup also takes a pasted record ID. A vial QR is scanned on a phone, so that is the surface the page is built for first.

What a Veritura record shows

An automated read of the submitted document by a party that does not sell the product. A tamper-evident fingerprint you can cross-check against the original certificate. Documentation completeness, source chain, and reuse signals.

Recompute the fingerprint yourself

The browser recomputes SHA-256 over the record's canonical fields, in that exact order, using its own WebCrypto, and compares the result against the fingerprint printed on the record.

When there is nothing to show

No released record for this link. The evidence record is not released for verification, or the link is incorrect. If you received it from a supplier, ask them for a current Veritura verification link.

The attribution is the product, not a courtesy.

On a partner-branded host the partner's own mark leads, and the line under it reads "Independently verified by Veritura". It renders whenever a partner brand does, and there is no way to configure it off.

Veritura is independent and reviews documentation only. A verified record is not a certification, an approval, or a claim that any product is safe, effective, legal, or FDA-approved.

A released record keeps working.

Clean yesterday can become review-needed tomorrow.

Recall mode

Lot search becomes an action map. Search or select a lot and the ledger shows affected orders, buyers, COAs, supplier packets, and unresolved evidence gaps.

Continuous reverification

Evidence records are watched for stale COAs, new public-source posture, supplier changes, and repeat-reliance refresh windows.

Supplier notice watch

Public FDA recall and enforcement notices naming the supplier keep being read after release. A notice names the supplier, not necessarily the batch, and the record says exactly that instead of raising an alarm about someone's prescription.

Cross-account comparison

Your document evidence is compared across the Veritura account network, not just this workspace. Counts only: no other account's identity, supplier, files, lots, or customers are shown.

Audit trail

Every passport, supplier response, and release event stays traceable.

Evidence graph

Every released record strengthens supplier, lot, COA, reviewer, and dispute history.

What an enforcement record published months later does to a passport already issued.

The passport stays bound to its lot forever. That binding is the whole mechanism: without it a signal landing after release would have nothing to travel along.

A flagged lot has passports minted from it.

Every passport bound to that lot is stamped with a post-release recall signal. Stamping is idempotent: the record stays in the FDA window for its whole duration, so a repeat sweep refreshes the existing signal in place rather than stacking duplicates.

The passport stays bound to its lot forever, which is what lets a later recall reach it at all.

Each affected account is notified privately: a lot.recall_hit webhook and an email to the account owner, each seeing only its own lots. The fan-out is deduped so a given account, lot and recall fires once.

The lot now carries a recall signal.

No new passport can mint or release from it, independent of every other state on the record.

A lot-number match against public FDA enforcement data is a documentation and enforcement signal, never a safety or approval determination. A lot number can be reused across firms, so the firm identity and the lot must be confirmed against the FDA record.

A released record is what makes a fast notice possible.

A binder tells you a lot was received. It cannot tell you who is still holding a vial from it. Release is what turns the record into a reachable list.

The lot binding is permanent

A passport is bound to its lot at issue and the link is never rewritten. That binding is the path a recall published months later travels back along to every record already issued from that lot.

A patient can put themselves on the list

Scanning the seal on the vial opens the record, and a patient can claim it with an email address. The claim starts pending and only the emailed link activates it, so nobody is added to a list they did not ask to be on.

One button reaches everyone holding that lot

When a signal lands, a single action notifies every active claimant across every seal batch of that lot, deduplicated so one address gets one message, each deep-linked to the record it concerns.

It carries no patient identity

The record stores an email address, the saved serials, and the notice history for those serials. No name, no address, no health information, and no field for them. Deletion is self-serve.

A notice states what was published about a lot and links to the record. It is not a recall, not a clinical judgment, and not medical advice; the treatment question stays with the pharmacy or the prescriber who dispensed it.

Usage is tied to released production evidence, not dashboard views.

A shareable, per-order proof of the documentation review behind a specific order. One link, one PDF.

per released production Passport, pay as you go and separate from your plan

per Passport at 500 or more per month, on a volume agreement

Customa committed rate for high-volume platforms

Sandbox Evidence Passport records are free and non-billable, up to 25 records.

First oneYour first released production Evidence Passport is complimentary when that offer is enabled.

Sandbox records are free for testing.

Usage trigger

A released production passport. Dashboard views and sandbox records do not create production usage events.

One release per order-lot-product

Production usage is controlled by client workspace rules, not dashboard views or repeated edits.

Sandbox stays labeled

Sandbox records are non-billable and clearly labeled. Production evidence records unlock only after a paid or signed client workspace.

What this record does not establish.

On the shipping product the boundary renders inside the record, at the same size as the evidence above it. It is reproduced here the same way.

Veritura does not test medicine, approve suppliers, recommend purchases, or make medical, legal, product-safety, or FDA-approval determinations. There is no paid or subjective placement: suppliers cannot pay for a better result or a better position, no listing fee, no subscription, and no pay-to-rank. Where results are ordered rather than filtered, the order is set by a published documentation-coverage grade, and that grade is never a recommendation, a preference, or a statement about any product.

A COA check or Passport records whether the documents are complete and consistent. It is not a safety, quality, efficacy, legality, or FDA-approval claim.

Documentation evidence only. This does not approve a supplier, certify quality, confirm safety, provide medical guidance, or replace wet-lab testing.

This workspace can show internal notes, source gaps, and QA posture. The customer passport does not show internal pricing, private notes, supplier approval language, product-quality claims, or legal/medical conclusions.

Documentation evidence, traceability, workflow control, and customer-safe proof only. No supplier approval, product-quality certification, legal advice, medical advice, or wet-lab replacement claims are generated by this layer.

Evidence posture only. Not supplier approval, product-quality certification, legal advice, medical advice, or wet-lab replacement.

Produced under methodology v1.0, April 30, 2026.

Veritura reads and connects the paperwork behind an order. It never tests, grades, or endorses the medicine itself, and it never releases anything on its own.
The boundaryDocumentation evidence, not medicinal judgmentVeritura

What runs underneath.

4Things every document is reconciled against: the issuing laboratory, the standard, the file, and every other document seen
17Forensic signals read on every file, from reused signatures to edit stacks
6Dated elements in every supplier file, each current, due, or overdue
0Autonomous releases, ever. A person signs every material decision

FAQ

Only from a lot that has cleared its documentation. An uncleared lot cannot publish one, and a refusal names the requirement that was not met rather than failing quietly.

One lot, one order, and the documents behind them, in plain words with no score. Values are shown exactly as the certificate documents them, and the limits are printed on the face of the record.

The lot binding is permanent, so a post-release signal is stamped on every passport minted from that lot, and anyone who saved a vial is reached through their own account, without a name ever entering the pharmacy’s or the clinic’s record.

Still have questions? Talk to a person.