Accountable, versioned, defensible.

This page is how the work is governed and where its limits are. Veritura checks paperwork. It never tests the product.

Checked against named public sources

openFDAPubChemFDA FURLSState boards of pharmacyUSP
Public sources consulted during document checks. No affiliation or endorsement implied.
How a record is built

A mechanical, repeatable process, so two reviewers reach the same record and an inspector can follow it. Every material observation points back to a source file, a field, a hash, or an explicit limitation. Findings are tied to evidence, not opinion, and if the evidence changes the record is corrected transparently with the basis for the change preserved.

How a record is built, and what governs it.

A mechanical, repeatable process, so two reviewers reach the same record.

01

Reconciliation, four buckets

Every reviewed document lands in one of four buckets: matches, mismatches, missing documentation, or could not verify. There is no subjective or paid ranking, no vendor scoring, and no certification of product quality anywhere in the method, and the published check catalogue lists every row as a signal for a person's review.

The four buckets are the whole vocabulary of a finding, which is why an inspector can follow a record months later and reach the same conclusion without a briefing.

  • Matches, mismatches, missing, could not verify
  • No paid ranking, no vendor scoring
  • Every row a signal, never a determination
Discover Methodology
Reconciliation, four buckets: a designed view of the Veritura workspace

02

Completeness, field by field

Certificate, lot, laboratory, method, purity, mass-spectrometry and sequence evidence, sterility, endotoxin, strength, address, and disclaimer language. Presence or absence is recorded mechanically, and a field the document does not claim to state is recorded as not claimed rather than as missing, so the record never overstates a gap.

Not claimed is distinct from missing on purpose. A document that never claimed to state a field is not penalised for it, and the record never overstates a gap.

  • Eleven fields, recorded mechanically
  • Not claimed is distinct from missing
  • The record never overstates a gap
Discover Order-level COA traceability
Completeness, field by field: a designed view of the Veritura workspace

03

Forensics and reuse

Cross-document forensics surface reused certificates and duplicate-report signals across the entire index. The specific detection signals are deliberately unpublished, because publishing them would teach document forgers what to avoid. What is published is how a reused signal is raised and what a reviewer sees when it is.

Publishing how a reused signal is raised, while keeping the detection signals private, protects the check from the people it is meant to catch.

  • Reuse surfaced across the whole index
  • Detection signals deliberately unpublished
  • What the reviewer sees is published
Discover Supplier packet diligence
Forensics and reuse: a designed view of the Veritura workspace

04

Source checks, with the search preserved

FDA, openFDA, import-alert, NDC, and laboratory-verify lanes preserve the search that was run, the source URL, the capture date, and the reviewer context. Absence of a public-source match is recorded as absence of a match, not as proof of absence, and the record says so in those words.

Absence of a match is recorded as absence of a match, in those words, because a public source that returns nothing is not proof that nothing exists.

  • The search, the URL, the capture date
  • Absence of a match is not proof of absence
Discover The evidence engine
Source checks, with the search preserved: a designed view of the Veritura workspace

05

Protected and access-scoped

Documents and evidence records are encrypted in transit and access-scoped to your workspace, handled through provider-backed storage controls when production storage is configured. Every output excludes product-approval, medical, and purchase language, and the risk boundary is printed on the record itself, next to the evidence.

The boundary is printed on the record next to the evidence, so a reader never has to find a policy page to learn what the output does not claim.

  • Encrypted in transit, scoped to your workspace
  • The boundary printed on the record
Discover Evidence Passport
Protected and access-scoped: a designed view of the Veritura workspace

What changes

What you get, in practice.

01A method you can follow

Mechanical and repeatable, so two reviewers reach the same record and an inspector can replay it.

02Every output states its boundary

No product-approval, medical, or purchase language, printed on the record itself.

03Corrections, never silent

If evidence changes, the record changes and says so, with the basis preserved.

Six standing facts

What backs the work, and what it does not convert into.

Published methodology v1.0

Every reviewed output stamps the methodology version, dated April 30, 2026. Material changes require a new version and a visible record here.

SHA-256 evidence trail

Every reviewed document is hashed and assigned an evidence ID, preserved in the report so the file can be reconstructed at inspection time.

Human review, labelled precisely

AI assists first-pass extraction and drafting. A person reviews the final language on delivered diligence memos. Automated checks and Passports claim no human sign-off.

$1M professional liability coverage

Errors-and-omissions coverage supports the documentation-diligence work. It does not convert any report into approval or regulatory sign-off.

Correction policy

If evidence changes, the record is corrected and says that it changed. Supported observations are never removed for being unfavourable.

Ask about anything on this page.

Questions about the method, the boundary, or the record go to the people who wrote them.

  • Founder-led. You hear back from the person who built the method.
  • Send a real, redacted document set and we run it through the check.
  • Encrypted in transit and access-scoped to your workspace.
Two numbers let us send a written scope and a price, usually within a day. No account and no card.

Everything on this page, in full.

The complete text, for the reader who wants the whole story before a call.

Six standing facts.

Published methodology v1.0

Every reviewed output stamps the methodology version (v1.0 . 2026-04-30). Material changes require a new version and a visible record on this page.

SHA-256 evidence trail

Every reviewed document is hashed and assigned an evidence ID, preserved in the report so the file can be reconstructed at inspection time.

Human review, labeled precisely

AI assists first-pass extraction and drafting. A human reviews the final language on delivered diligence memos. Automated checks and Passports claim no human sign-off.

$1M professional liability (E&O) coverage in place

Professional liability / errors-and-omissions coverage supports the documentation-diligence work. It does not convert any report into approval, safety coverage, legal advice, or regulatory sign-off.

Protected and access-scoped

Documents and evidence records are encrypted in transit, access-scoped to your workspace, and handled through provider-backed storage controls when production storage is configured. Practice and sample packets are isolated from billing and delivery.

Correction policy

If evidence changes, the record is corrected transparently, with the basis for the change preserved. Findings are tied to evidence, not opinion.

How a record is built.

A mechanical, repeatable process, so two reviewers reach the same record and an inspector can follow it.

Executive verdict

The record opens with the posture a human can act on, not a hidden conclusion.

Evidence map

Material observations point back to source files, fields, hashes, or explicit limitations.

Reconciliation, four buckets

Matches, mismatches, missing documentation, and could-not-verify. No subjective or paid ranking, no vendor scoring, no certification of product quality. Published Verified Supplier profiles carry an objective grade of the documentation evidence only.

Completeness, field by field

COA, lot, lab, method, purity, MS and sequence evidence, sterility, endotoxin, strength, address, and disclaimer language. Presence or absence recorded mechanically, and a field the document does not state is recorded as not stated on the document rather than inferred.

Forensics and reuse

Cross-document forensics surface reused certificates and duplicate-report signals across the entire index. The specific detection signals are deliberately unpublished: publishing them would teach document fraud how to evade them.

Source checks

FDA, openFDA, import-alert, NDC, and lab-verify lanes preserve the search, source URL, capture date, and reviewer context.

Supplier qualification file

The six-element file is built with honest tiers. Each item is labeled Veritura evaluated or Operator attested, with a living current, due, or overdue status on every dated document.

Risk boundary

Every output excludes product approval, safety, legal, medical, or purchase language.

Next action

The client sees the supplier ask, hold, review, or release step tied to the evidence. At receiving that ask is drafted for them, composed from the specific gaps the gates found.

Human QA

The output becomes a reliance hold, a supplier question, an evidence memo, or an Evidence Passport. Never supplier approval or product certification.

methodologyv1.0 . 2026-04-30

reconciliation4 buckets

completenessfield-by-field

evidence_idE1 . SHA-256 recorded

forensicsreuse / producer signals

source_lanesopenFDA . NDC . lab

qarelease-gated

determinationnone, signals only

AI may assist extraction and drafting. Delivered written diligence memos receive human QA. Self-serve checks, ClearGate decisions, and Passports are automated unless the record explicitly says otherwise, and no human sign-off is claimed on them.

Five lanes, each one recorded.

Every lane preserves the search, the source URL, the capture date, and the reviewer context.

The issuing lab is resolved against a verify-portal registry with a ready-to-send confirmation email, and only a recorded lab reply flips a document to source-confirmed.

What is checked, and the public sources it is checked against, are published. The detection heuristics themselves are not, because publishing them would help fraudulent documents evade them and because they change faster than any page.

Every document is checked against four things.

Each document is reconciled against the lab that issued it, the standard it has to meet, the file's own internals, and every other document we have seen. Each lane returns one of three states with its reason, ran, not applicable, or could not verify, and no lane is allowed to disappear. Findings are signals for human review, never approval or safety claims.

Checked against the lab

Checked against the standard

Checked against the file itself

Checked against the network

How each lane runs, and the full published check catalog, is on the evidence engine.

Public sources

openFDA enforcement and recall records

Lots and firms are matched against open enforcement and recall data in real time.

FDA registration snapshot

Manufacturer identity is checked against a dated registration snapshot, and unmatched names are surfaced for review.

503B registered-facility list

A dated capture of the FDA outsourcing-facility list, shown with both its source date and its capture date.

503B snapshot: FDA's list current as of June 23, 2026, captured June 30, 2026

Not found in the snapshot never means not registered. It means the name did not match the captured list.

Three axes. Never mixed.

A result is a documentation posture of Clear, Review, or Hold on the document set. A ClearGate decision of Allow, Review, or Hold is a separate axis, resolving one order against the policy you configure. Both describe the paperwork, not the medicine.

Evidence posture

ClearGate

A ClearGate decision always means the documentation meets your policy. It never means Veritura approves the supplier. Customer-facing phrasing: Meets your policy, Needs review, Does not meet policy.

Evidence origin

Absence of a public match is not proof of absence. A missing document is not a failed test. A similarity indicator is not a fraud determination.

Semaglutide (base) API

The document set met the configured policy. It describes the paperwork, not the medicine.

The issuing laboratory confirmed issuance through the recorded verification route.

OrderPO-DEMO-0413

LotLOT-7741-A

SupplierAurora Pharma Supply

Quantity250 g

ReceivedJuly 22, 2026

ReleasedJuly 23, 2026

Passport issuedJuly 23, 2026

Methodologyv1.0 · April 30, 2026

Documents on file

COA-7741-A.pdf · Issuing laboratory confirmed issuance through the recorded route

CoC-7741.pdf · Required identity, lot, and date fields present

SDS-SEMA-04.pdf · Current revision on file

GMP-AUR-2026.pdf · Supplied by the operator

Recorded in workspace · Container and label checked at receipt

LBL-7741-A.jpg · Lot identifier matches the certificate of analysis

What this record does not establish

  • Documentation diligence only. No product was tested and no supplier was approved.
  • Absence of a public-source match is not proof of absence.
  • Produced under methodology v1.0, April 30, 2026.
The methodology has a named owner.

Joey Soto, founderAccountable for the methodology

PharmD and sterile-compounding advisorsInput on the methodology

Regulatory affairs and 503B quality advisorsInput on the methodology

Final operational decisions stay with the customer.

Advisors appear as roles. A named advisor quote may only be published if that person actually gave it in writing.

What Veritura does not do.

Veritura does not

Rank vendors by preference, payment, or judgment, recommend purchases, test physical material, certify products, provide medical, legal, or regulatory advice, determine legality, or confirm FDA approval, clearance, or registration.

Veritura does

Document what is present, conflicting, missing, changed, or not verified in reviewed materials, with cited evidence, hashes, limits, and the next supplier question, for a human to decide.

Veritura does not test medicine, approve suppliers, recommend purchases, or make medical, legal, product-safety, or FDA-approval determinations. There is no paid or subjective placement: suppliers cannot pay for a better result or a better position, no listing fee, no subscription, and no pay-to-rank. Where results are ordered rather than filtered, the order is set by a published documentation-coverage grade, and that grade is never a recommendation, a preference, or a statement about any product.

Security and data handling

Supplier diligence should collect less data, not more.

Veritura is built around document evidence, business contact information, source records, and report boundaries. It is not designed to collect patient information, intended use, clinical outcomes, or medical histories.

PostureData minimization first

Patient dataNot requested

File recordName, size, metadata, SHA-256 hash

E&O coverage$1M professional liability (E&O) coverage in place

ContactJoey@veritura.co

Data minimization

Intake asks for business contact details, supplier identifiers, document context, and decision context. It does not ask what a patient is taking, why a product might be used, or what outcomes are expected.

File identity preservation

For browser-submitted files, Veritura records name, type, size, last-modified time, and a browser-side SHA-256 hash, so the submitted document identity is preserved.

Provider separation

Structured records go through Supabase, email confirmations through Resend, and checkout through Stripe. Veritura does not store card numbers or card security codes.

Access boundary

Administrative surfaces are separate from public pages and require administrator authorization. Public static access is restricted to an explicit server allowlist.

Report boundary

Reports are documentation diligence records only. They do not approve suppliers, verify product quality, certify purity, determine legality, or replace supplier qualification and wet-lab testing.

Correction route

Users, suppliers, vendors, and labs can submit factual corrections or supplemental evidence through the correction process or by contacting Joey@veritura.co.

Partner referral data posture.

Client submits directly.

Partners can send clients to Veritura without collecting the packet themselves.

Not requested.

The intake is designed for supplier documents, business context, and redacted source material.

Paid and bounded.

AI-assisted review is usage-capped, logged, and positioned as a draft layer before final delivery.

Document memo only.

No supplier approval, product certification, clinical guidance, or purchase facilitation.

Current controls in place before customer outreach.

What belongs in Veritura and what should stay out.

Good input

  • Supplier COAPacket evidence tied to the supplier decision.
  • Supplier quote or product pageUsed to compare claims, fields, and public documentation.
  • Lab reference or QR evidenceUsed to record whether lab-verification material is present.
  • Do not submit

  • Patient identifiersNames, dates of birth, medical record numbers, prescriptions, and health histories are outside scope.
  • Clinical use detailsIntended use, dosing, treatment goals, outcomes, and adverse events are outside scope.
  • Unrelated confidential termsRedact nonessential pricing, banking, and unrelated commercial terms.
  • Users should redact patient data, protected health information, patient identifiers, prescription records, nonessential pricing terms, and unrelated commercial information before submitting materials for review.

What is recorded, and what has no field at all.

Data minimization first. Patient data is not requested, and where Veritura declines to collect something, no field for it exists.

Recorded

  • Document identityFor browser-submitted files: file name, file type, file size, last-modified timestamp, and a browser-side SHA-256 hash, so the submitted document identity can be preserved.
  • Report dataSubmitted URLs, uploaded document metadata, extracted fields, hashes, evidence records, and account details, used to provide saved reports and monitoring.
  • Source contextEach FDA, openFDA, import-alert, NDC, and lab-verify lane preserves the search, the source URL, the capture date, and the reviewer context.
  • Patient vial claimsWhen a patient saves a vial from its scan page, the email address, the saved vial serials, and the notice history for those serials. Nothing else.
  • Never collected

  • Intended useVeritura does not ask what a user intends to do with any product, what conditions they have, what they are taking, or what outcomes they seek. No field for that information exists.
  • Patient identityNo name, no address, and no health information is stored against a saved vial, and no field for them exists.
  • Clinical detailIntended use, dosing, treatment goals, outcomes, and adverse events are outside scope, as are patient identifiers, prescriptions, and health histories.
  • Card and bank credentialsCheckout is Stripe-hosted. Veritura does not store card numbers, card security codes, or bank credentials.
  • Every vial claim is patient-initiated from a printed seal and confirmed by email, and deletion is self-serve: the Delete my space control removes the account and stops all notices.

Reports document evidence. They do not certify products.

Reports are not safety assessments, quality assessments, legal determinations, or purchase recommendations. There is no paid or subjective placement; where results are ordered, they are ordered by the disclosed documentation-coverage grade published above.

Not a safety assessment. Veritura does not determine whether any product is safe, sterile, effective, pure, legal, or appropriate for any use.

Not product testing. Reports are based on submitted documents, public pages, metadata, and snapshots. Veritura does not test physical material.

Authenticity limits. A report may identify metadata, repeated file signals, links, and inconsistencies. It cannot prove document provenance unless an issuing lab or source independently confirms it.

No purchase recommendation. Reports do not recommend, endorse, discourage, rank, or facilitate purchases from any vendor.

The current standard documents operating controls, boundaries, and buyer-visible safeguards.

Built around data minimization.

We collect what is needed to provide the diligence record, and nothing about who you are or what you intend to do.

No intended-use collection. Veritura does not ask what a user intends to do with any product, what conditions they have, what they are taking, or what outcomes they seek.

Report data. Submitted URLs, uploaded document metadata, extracted fields, hashes, evidence records, and account details may be used to provide saved reports and monitoring.

Documents. Uploaded documents are processed to extract documentation signals. Users should avoid submitting private health information or unnecessary personal data.

Patient vial records. When a patient saves a vial from its scan page, Veritura stores the email address, the saved vial serials, and the notice history for those serials, and nothing else. It never stores a name, an address, or any health information, and no field for them exists. Every claim is patient-initiated from a printed seal and confirmed by email, and deletion is self-serve: the Delete my space control removes the account and stops all notices.

Contact. Privacy requests and correction requests should reference the relevant report ID, account email, or submitted source, and can be sent to Joey@veritura.co.

Boundary. Veritura is document diligence only. It does not provide medical, legal, pharmaceutical, or purchase advice, and does not make safety, quality, or FDA-approval claims.

Documentation intelligence, not regulated advice.

Service scope. Veritura evaluates documents, public page text, metadata, source references, and historical changes using fixed documentation checks.

No professional advice. Reports are not medical, legal, pharmaceutical, regulatory, laboratory, or purchasing advice, and are not supplier approval or product certification.

User responsibility. Users are responsible for the materials they submit and for independently evaluating any decisions outside the report scope.

Corrections. Veritura may update, annotate, or preserve reports based on correction requests, supplemental evidence, methodology changes, or operational requirements.

Service contact. Questions about accounts, reports, corrections, or access can be sent to Joey@veritura.co.

Keep submissions factual, document-based, and non-medical.

Keep the review focused on supplier evidence, and keep medical, legal, and patient details outside the workflow.

Do not submit health details. Do not submit personal medical histories, outcomes, dosing information, or intended-use details.

No false or misleading submissions. Do not upload altered documents, impersonate vendors or labs, or submit correction requests without evidence.

No purchasing facilitation. Do not use Veritura to coordinate purchases, sales, shipping, sourcing, or transactions involving regulated or unapproved products.

No abuse. Do not scrape excessively, attack the service, harass vendors or users, or use generated reports out of context.

The redaction rule that goes with these rules is published above. Security and data handling

Reports change when the evidence supports a change.

Nothing is silently rewritten, and nothing supported is removed because it is unwelcome.

Who can submit. Users, vendors, labs, or other relevant parties may submit factual corrections, supplemental documents, or responses tied to a report ID.

What we review. Correction requests are reviewed against the underlying source material and the methodology version used for the report.

What we do not remove. Veritura does not remove supported observations because they are unfavorable. Reports are corrected when a factual error or missing source is demonstrated.

Vendor responses. Where appropriate, a response or supplemental document may be attached to a report without changing the original observation.

Correction contact. Correction requests should include the report ID, the specific observation at issue, and the document or source that supports the correction. Send requests to Joey@veritura.co.

A correction request includes

  • 01The report ID
  • 02The specific observation at issue
  • 03The document or source that supports the correction
  • Send requests to Joey@veritura.co.

    What a correction cannot rewrite

    Evidence-backed corrections can update factual records without rewriting the methodology trail.

A check you can put in front of a board or an inspector.

Follow one lot end to end, from the read to the record you hand someone, or talk to us about covering your supplier base.

Veritura reads and connects the paperwork behind an order. It never tests, grades, or endorses the medicine itself, and it never releases anything on its own.
The boundaryDocumentation evidence, not medicinal judgmentVeritura

Behind every check.

119M+Compounds in the public identity source every check can query
20M+Adverse event reports in the public record every ingredient check can search
100%Findings that carry their page and line citation
0Autonomous releases, ever

FAQ

A person reviews the final language on delivered diligence memos. Automated checks and Passports state that they claim no human sign-off.

Product-approval, medical, and purchase language. The risk boundary is printed on the record itself, next to the evidence, with the methodology version that produced it.

The record is corrected and says that it changed, with the basis preserved. Supported observations are never removed for being unfavourable.

Still have questions? Talk to a person.