How a certificate becomes a record.
Every certificate figure on this site passes through six stages. This page documents each one, publishes the current state of the pipeline, and states plainly what none of it establishes.
The panel above is rendered from test_result_gate_runs, coa_audit and test_results. Not a description of a process — the process's current state. Counts elsewhere on this page derive from the certificate tables when the page renders. Published constants — the rubric and its weights among them — change when we revise the method, not when the data moves. How old a figure is depends on when the page was last rebuilt: it rebuilds no more often than every 5 minutes, and only when someone asks for it, so a stretch with no readers leaves the last build standing. Much of what it renders is also served as JSON at /api/methodology — that response, not this sentence, is the authority on which figures it carries.
Six stages
A certificate is never published on discovery. It is extracted, resolved, verified where the lab allows it, gated as part of a batch, and committed to an append-only log. Any stage can quarantine a record; nothing is deleted. A recorded gate run stands behind 238 of 1,080 of the certificates held.
Discover
A source is identified — a vendor's testing page, or a lab's own public database. The source URL is recorded before anything is parsed.
Extract
The document is parsed into typed fields. An extraction carries a confidence score wherever the extractor recorded one; anything under 0.80 is held back rather than published.
Resolve
The record is matched to a compound and a vendor. Unresolved records are counted and excluded from vendor aggregates, never silently attached.
Verify
Where the lab can be checked, the certificate's key or task number is resolved against the lab's own record and the response is stored.
Gate
The whole batch is evaluated before any of it goes live. A failed check quarantines the row; a failed batch is not committed at all.
Commit
Rows are written with a SHA-256 of the source document and appended to a hash-chained log. Every later edit is another entry, never an overwrite.
The last line is the date this page read the run, not part of the record itself. Where a lab's report template simply doesn't carry a field, we say so rather than leaving a silent null.
Four states, and what separates them
The tier describes how much of the certificate we could check, not how good the product is. A vendor cannot improve its tier by testing better — only by using a lab that can be checked.
| Tier | Condition | What it establishes | What it does not | Records |
|---|---|---|---|---|
| Confirmed by lab | The certificate was checked against the issuing lab’s own records and matched — either resolved there by its key or task number, or byte-identical to the lab’s own copy. | The document is real and the lab holds a matching record. | That the vial you receive came from this lot. | 407 |
| Checkable — no result recorded | The lab publishes a way to check its certificates; no check result is recorded for this record. | Nothing yet — no result exists, in either direction. | Any inference about the vendor. | 614 |
| Can’t be checked | The lab publishes no way to check a certificate. There is nothing to verify this against, ever. | That the vendor makes a claim, and what the claim is. | That anyone independent has seen it. | 17 |
| Lab not reviewed | We have not yet assessed whether this lab publishes a way to check. | Nothing about the laboratory, in either direction. | That the lab can’t be checked — we have not looked. | 42 |
"Confirmed by lab" covers two different checks, and they are not equally strong.
238 of these records were taken from the issuing laboratory's own database — we never held a
vendor's copy, so there is nothing that could have been altered before we saw it.
The other 169 started as a copy the vendor published: we fetched the laboratory's own file
and compared the two byte for byte, and they are identical.
The second is the stronger statement about a vendor, and it is worth being plain about why. A record pulled
from a lab's database says the lab holds it. A byte-for-byte match says the exact document the vendor is
showing you is the exact document the laboratory issued — nothing edited, nothing substituted, not one
figure moved. We report the two separately for that reason; the tier table above carries their total.
The leaderboard rubric, in full
Six dimensions, each normalised 0–100, then weighted. Weights are set by the reader, not by us — the defaults below are one of four presets. Purity is deliberately excluded: 93% of the 1,039 reported purity values in the corpus are 99% or higher, standard deviation 0.53, and it is the single figure a vendor fully controls.
Where a vendor has no mass-checked vials the scorer currently substitutes qty × 0.5 — a placeholder, not a ruling. The ruled NOT ASSESSED exclusion (structural absence scores 0 and rescales nothing) ships when the lab-share view lands.
A usable lot identifier is non-null, at least five characters, not a placeholder (N/A, Unknown) and not a colour-cap label (Black Cap). 640 of 1,080 records qualify.
Three other presets ship with the leaderboard, and any combination can be set by hand and shared as a URL.
Every lab, and whether we can check it
7 of 14 labs in the register can be checked at all, and we resolve 2 of those automatically (read 2026-08-26). The register below names each one and what its tier records.
| Lab | Records | Confirmed by lab | Verification | Tier |
|---|---|---|---|---|
| Janoshik Analytical | 374 | 224 | Portal · automated | 2 |
| Freedom Diagnostics | 373 | 169 | Portal · manual | 2 |
| ILS Laboratories | 104 | — | Portal · manual | 2 |
| Vanguard Laboratory | 90 | — | Portal · manual | 2 |
| MDX Biolabs | 52 | — | Portal · manual | 3 |
| MZ Biolabs | 17 | — | No lookup | 2 |
| TrustPointe Analytics LLC | 14 | 14 | Portal · automated | 2 |
| Horizon Analytical | 14 | — | Portal · manual | 3 |
| Kovera Labs | 13 | — | Not assessed | 3 |
| BTLabs | 12 | — | Not assessed | 3 |
| BioRegen | 7 | — | Not assessed | 3 |
| Chromate Analytical | 6 | — | Not assessed | 3 |
| Liquilabs s.r.o. | 3 | — | Not assessed | 3 |
| Colmaric Laboratories | 1 | — | Not assessed | 2 |
| Tier | Labs | What the tier records |
|---|---|---|
| Tier 1 | 0 | ISO 17025 scope we can independently confirm |
| Tier 2 | 7 | assigned by hand as the stronger documentation tier at the last register review — the Verification column states what the lab actually publishes |
| Tier 3 | 7 | assigned by hand as the weaker documentation tier at the last register review — the Verification column states what the lab actually publishes |
Tier records how much of a lab's process is externally documented, not the quality of its instrumentation. Every tier in the scale is listed whether or not a lab currently sits in it.
What runs on every record, without being asked
| Check | What it catches | Coverage | Findings |
|---|---|---|---|
| Document hash | The same PDF republished under another vendor or lot | 1,030 hashed | 1 pair sharing a document |
| Lab lookup resolution | A certificate the issuing lab has no record of | 1,021 of 1,080 from a lab with a lookup | 0 unresolved of 238 harvested |
| Extraction confidence floor | Values parsed from an unreadable or ambiguous scan | 1,049 carry a confidence value | 0 below the 0.80 floor |
| Lot identifier validity | Placeholders and colour-cap labels posing as lot numbers | 717 publish a lot field | 77 rejected as unusable |
| Measured vs labelled mass | Vials materially short of their stated content | 470 pairs | 34 more than 5% below label |
| Shared-batch fingerprint | One synthesis run relabelled by two brands | 609 usable lots | 35 pairs across 6 vendors |
| Purity plausibility | Implausible rounding or zero-variance reporting | 1,039 values | 3 whole-number results |
Bounded claim. None of these checks can detect batch substitution — a genuine certificate for a genuinely good lot, displayed beside vials shipped from a different run. Only a lot number printed on your vial, matching the one on the record, closes that gap. We say this rather than implying coverage we do not have.
Where a person overrides the pipeline
Resolution stands at . Where automation cannot resolve a record, an operator decides and the reason is written into the record in plain language — not a status code. The reason is stored as written prose rather than as a status code, which is what makes it auditable at all. Surfacing those reasons on the record pages themselves is not built yet.
Measured mass is reported against two populations,
deliberately. Across the full corpus of 1080 certificates, 470 report both a
labelled and a measured mass and 34 measure more than 5% below label. The overview
aggregates only the 941 scored certificates, and it aggregates them BY LABORATORY: every
withheld record is excluded — all 139 of them, not only the
127 under spot audit.
We no longer publish a per-vial shortfall table naming the vendor. Variance against label is
only a vendor-level claim if every laboratory reports mass on the same basis, and they do not — one
lab states "net peptide content" on some of its templates and "net content" on others, and a blend's
measured figure is a sum across several compounds rather than one. Where a certificate does not state
its basis, we do not infer one, so the figure is reported as the laboratory's and not as anybody's
shortfall.
A held record is not a hidden one: it keeps its own page, its place in the certificate browser, and the reason it is held written onto the record. What it loses is the scored set. 127 certificates are held pending an operator spot audit and 130 are Freedom Diagnostics certificates whose vendor provenance we have not confirmed — 120 carry both holds, and 2 for a reason neither of those names. All told, 139 of the 1,080 we hold are withheld from the 941 this site scores, so none of them reach a leaderboard position, a vendor rollup or any figure that names a vendor. The counts in this section are drawn from the 1,080, which means these records are inside them.
What none of this establishes
Stating the boundary precisely is more useful than a general disclaimer, so here is the boundary.
How a wrong figure gets fixed
Vendors, labs and readers can dispute any figure. A reason is mandatory. Both parties are notified.
The dispute appears on the record with the reason given. We do not rule on who is right, and we do not remove the record.
A correction is a new version, not an overwrite. The prior version stays citable at its own permalink, and the change is in the audit chain.
Our own bounded guarantee. If a certificate we published as Confirmed by lab is contradicted by the issuing lab, we correct it publicly within 48 hours and record the correction in the rejections ledger. We are not guaranteeing any product — we are guaranteeing our own handling of the evidence.
Every correction we have published, newest first. Each states what the page said, what it says now, and the population the counts were taken over — a corrected figure without its population is the defect it is correcting.
Was: C-1 stated that "as at 16 Aug 2026, 170 of its certificates had been fetched from the laboratory's own host and each was byte-for-byte identical to the copy we hold."
Now: The figure is 169. Freedom Diagnostics rows carrying a lab-fetched sha256 in verification_response: 169; rows with verification_status = lab_confirmed: 169 — two derivations agreeing, measured 21 Aug 2026 with the row set unchanged since before C-1's stated date, so the entry was off by one on arrival rather than overtaken by intake.
A dated correction is exempt from re-derivation — the frozen-literal doctrine protects it — but the exemption assumes the literal was true at its own stated date. This one was transcribed, not derived, and the only write it can refer to touched 169 rows. A correction is a new claim starting at zero evidence: it ships with its own derivation or it ships a new defect into the one surface whose subject is defects.
Scope: the 169 byte-matched Freedom Diagnostics rows of its 368 in test_results @ epoch 20260821031815; the corrected count reproduced at epoch 20260821035548
Was: Six hand-written sentences describing relationships in the data: that a certificate from one named laboratory could not yet reach the top tier, that every certificate confirmable against a laboratory database came from one of two named laboratories, that confirmation and contamination-panel depth did not overlap at all, that independent confirmation had not been attempted on any vendor-published certificate — and, in this ledger itself, that every one of a named laboratory's fetched certificates had matched, stated in the present tense with a count that had since moved.
Now: Each of those surfaces states counts drawn from the same records it renders beside, and draws no conclusion the counts do not carry. Where a figure is zero the sentence still derives, so it moves when the data does. The ledger's own entry now carries the date it was measured, which is what makes it a record of a reading rather than a standing claim.
THE USEFUL LESSON IS NOT THAT FIVE SENTENCES WENT STALE. It is that C-1 had already retracted one of them, and the replacement it published SOFTENED the categorical instead of removing it: "can never reach our top tier" became "cannot reach our top tier yet". The shape survived the correction — a universal about a named laboratory, with a live count welded beside it — so the same sentence went stale a second time, by the same mechanism, in the text written to fix it. A correction that edits the wording and keeps the assertion has changed how confidently a false thing is said. Retract the SHAPE: state counts, and let the reader draw the conclusion. Everything else here follows from that. The five were true when written and were falsified by ordinary intake — a third laboratory became confirmable, and certificates carrying a contamination panel were confirmed — because nothing re-measures a paragraph. And the surfaces were re-read after the previous change only where a sentence had been edited, which is why static copy nobody had touched was the last place still asserting it.
Scope: Six sentences across three published surfaces and this ledger. Four were identified from the production database; the fifth was found by sweeping every universal or exclusive claim about confirmation, laboratories or panels across all four lab-testing surfaces before changing any of them; the sixth was found by the test written in the same change, which exempts a retraction's quoted claim but not the sentence offered in its place. No figure on any page changed as a result of this correction and no record was re-assessed: the counts were already correct, and the prose beside them was not.
Was: A confirmation metric that counted one of the two ways a certificate can be matched against the issuing laboratory. Four vendors were shown as having no lab-side evidence at all; on the largest, that was 98 certificates reading zero. The same records were labelled "Vendor-published" on the certificate browser and on their own record pages, and the purity figures on peptide pages left them out.
Now: The metric counts both routes — documents taken from the laboratory's own database, and vendor-published documents whose bytes we matched against the laboratory's own copy — everywhere it is computed, and it is named for what it measures rather than for the word "confirmed". Each record states which of the two routes applies to it.
One word covered two populations. The overview counted 407 records as confirmed while the leaderboard scored 238, one click apart, because the tier read the evidence and the score read a single status value. The peptide-page purity figures had the same gap. Correcting one surface and not the other would have left the same defect with a smaller blast radius, so both were corrected together. No vendor's underlying evidence changed and nothing was re-checked: every one of these records already carried its confirmation, and the surfaces were reading past it.
Scope: 167 of the 807 records this site scores; 169 of the 1,012 held @ 2026-08-16 (epoch 20260816120451). On the leaderboard's own population — 23 vendors, the certificates each publishes — 4 vendors understated, 0 overstated, 19 unchanged. On the peptide pages, which count only primary results: 204 rising to 266, moving the median purity on 20 compounds by at most 0.79 points, and adding a purity summary to four compounds that had too few results to show one. These are three different denominators and are not comparable with each other.
Was: Nine certificates shown under "Lookup pending — the lab publishes a lookup; we have not run it."
Now: Confirmed. The lookup had in fact been run on 30 July: each of the nine was fetched from the issuing laboratory's own host and its SHA-256 compared with ours. All nine matched.
The result was written to the record and the status field was never moved, so every surface deriving a tier from that field went on reporting the check as outstanding. The evidence was in the database the whole time; the answer was read off a status column instead of off the evidence. That is the defect this entire ledger exists for, and it is ours.
Scope: 9 records, all at one vendor, of the 1,012 held @ 2026-08-16. Confirmed 2026-07-30/31, corrected 2026-08-16 — seventeen days. The date the evidence was recorded is measured (first_checked_at, in the data); exactly which sentence rendered on which day is not, because the tier vocabulary changed during the period.
Was: A column headed "Confirm" showing, for each vendor, the share of its certificates at labs whose lookup WE had automated.
Now: A column headed "Lab lookup" showing the share whose issuing lab publishes a lookup a reader can work. The leaderboard reordered. NO VENDOR'S SCORE FELL — the metric moved every score in the same direction, so every apparent drop in rank is displacement by another vendor rising, not a decline by the vendor that moved down.
The score read a column recording our own pipeline coverage and rendered it as a claim about the laboratory. The ranking was not wrong about the vendors; it was measuring us and labelling it them.
Scope: all 23 ranked vendors; 430 of 661 ranked records changed value @ 2026-08-15
Was: That consecutive lab report numbers showed two brands had submitted a shared batch together.
Now: Stated as what it is — an inference from matching compound, purity and measured mass. Report-number adjacency does not hold for most of these pairs and is no longer offered as evidence.
A pattern that held for the first examples looked at was generalised into a stated mechanism, and the mechanism was then published as the reason.
Scope: the shared-batch pairs rendered on the leaderboard @ 2026-08-15
Was: A corpus of 728 certificates, with tier counts of 238 / 201 / 289 — a partition of OUR QUEUE STATE presented as a partition of what the laboratories can be checked against.
Now: The partition derives from the laboratory's own lookup_status, and it is published in full: 238 taken from a lab's database, 167 confirmed by byte-match, 291 pending and 267 unverified at labs that publish a lookup, 17 at a lab that publishes none, and 30 at labs nobody has assessed.
The tier was labelled with a property of the LABORATORY and computed from a property of OUR PIPELINE. Those are different partitions, so the counts were a correct measurement of the wrong question — and the largest single instance of the defect this ledger exists for.
Scope: the 1,010 records carrying a resolved compound, of the 1,012 held @ 2026-08-16 (epoch 20260816120451). The seven figures sum to 1,010 and are counted independently, none by subtraction.
Was: Horizon Analytical recorded as publishing no lookup, with a note calling its certificates structurally uncheckable.
Now: Horizon Analytical publishes a public lookup, no login, keyed on a report number printed on the certificate. Our own Horizon records still carry no such reference, which is a separate fact and is now recorded as one.
The register field describing the LABORATORY was set from a fact about OUR RECORDS. Both statements were true; only one of them was about the lab, and the wrong one had been stored.
Scope: 14 of the 807 records this site scores; 14 of the 1,012 held @ 2026-08-16
Was: That a certificate from Freedom Diagnostics could never reach our top tier because there was no portal to check it against.
Now: Freedom Diagnostics does publish a public lookup, and we have run it: as at 16 Aug 2026, 170 of its certificates had been fetched from the laboratory's own host and each was byte-for-byte identical to the copy we hold.
Two surfaces read two different columns for the same claim. The overview read lookup_status; the register read lookup_url_template, which is a display field and was empty for this lab. The sentence stated a fact about the laboratory that was drawn from neither.
Scope: 365 of the 1,012-record corpus; 236 of the 807 records this site scores @ 2026-08-16
What has changed, and when
Every methodology version stays live at its own URL so a citation made last quarter still resolves to the rules that were in force.