Available now
COA Validator
Checks a supplier certificate of analysis for completeness, specification alignment, analytical results, methods, sample quantities, dates, signatures and internal inconsistencies, then produces a traceable report for expert review.
What it checks
Grouped the way the work is actually done: first whether the document says what it must, then whether what it says holds up.
Is the document whole?
Identity of the material and the batch, the issuing laboratory, the dates, the signatures and the authorisations. A certificate that cannot name its own issuer does not pass this quietly.
Are the limits the right limits?
The limit printed on the certificate is compared with the limit that applies to that material. A printed limit looser than the official one is a finding in its own right, separate from whether the result passed.
Do the results meet the limits?
Each reported result is evaluated against the limit that governs it, with the comparison shown rather than summarised.
Was the right method used?
The analytical method named for each test, and whether it is the one the requirement expects.
Do the numbers hang together?
Sample quantities, manufacturing and retest or expiry dates, and whether they are internally consistent.
Does the document contradict itself?
Values that appear twice and disagree, totals that do not add up, a conclusion that the rows beneath it do not support.
Documents it accepts
Supported today
- Certificate of analysis for an active pharmaceutical ingredient
- Certificate of analysis for an excipient or raw material
- Certificate of analysis for a finished product batch
PDF or a scan. Stamped and photographed certificates are common and are handled; a page that genuinely cannot be read produces a hard stop that says so, never a report of empty fields.
Not this product
Certificates of suitability, Drug Master Files, GMP records and medical-device technical documentation are separate problems with separate requirements. They are on the platform roadmap and are not part of the COA Validator.
How a certificate moves through it
The two halves are separate on purpose: the part that reads the document never decides whether it is good, and the part that decides never re-reads the document.
Read
Values are extracted and each one is checked against the page it claims to come from, the cell it claims to sit in and a confidence floor. A value that fails those checks is not passed on.
Judge
Only verified values are evaluated, against requirements drawn from the controlled source register.
Publish
A report that cannot recount its own headline numbers from the rows beneath them is not published at all.
What comes out
One fixed structure, in HTML and PDF, so a reviewer knows where to look without learning a new document each time.
| Section | What it holds |
|---|---|
| Report identity | Which document, which batch, which run, and the software and source versions behind it. |
| Final outcome | One of four: accepted, conditional, non-compliant, or insufficient data. |
| Client decision summary | What a decision-maker needs, in plain language. |
| Comparison against requirements | Each test, its printed limit, the official limit, the result, and the outcome. |
| Supplementary evaluation | Document-level checks that are not a single test row. |
| Open findings | Everything unresolved, each with the action that closes it. |
| Scores and sources | The scoring, and every source cited with its version. |
Outcomes are a closed set
The distinctions carry weight. A result meeting a limit is not the same as a printed limit being at least as strict as the official one. Evidence being absent is not the same as evidence being present and bad. Collapsing either pair gives exactly the wrong answer.
Ambiguity is an outcome too
Where a damaged scan supports two readings that disagree on the verdict, the report names both and refuses a decisive answer rather than picking one silently.
Where a person signs
An automated analysis is a starting point. A qualified reviewer can examine the certificate and the findings, confirm or correct them with cited sources, and issue an Expert-Reviewed Analysis. Corrections are recorded rather than overwritten, so the reasoning behind a change stays visible.
Limitations, stated plainly
A compliance tool that hides its edges is worse than one that names them.
- It analyses the document in front of it. It cannot tell you whether the document is genuine, or whether the laboratory that signed it did the work.
- It does not test material. Nothing here replaces a laboratory result.
- It works from a controlled source register. A requirement not in that register cannot drive a finding, and the report says when it could not establish one.
- Automated analysis may contain errors and may not detect every problem. Qualified review is required before a decision that matters.
- It does not certify compliance and does not grant regulatory approval.
Questions
Does PharmaTrust certify that a batch is compliant?
No. It produces an analysis for a qualified person to act on. It does not certify compliance, does not act as a pharmacopoeia and does not grant regulatory approval. That boundary is enforced in the product, not just stated in marketing.
What happens when the certificate does not contain enough information?
The report says so. An absent value produces NOT_VERIFIED with the evidence that is missing named, and a document that cannot be read at all produces a hard stop rather than a page of empty fields. It never fills a gap with an assumption.
Can I see why a particular finding was reached?
Yes. Every finding names the requirement it rests on, the evidence observed on the certificate, the reasoning, the source and the version of that source, and the action that would close it.
Will two runs of the same certificate agree?
Judging is deterministic, so re-judging a stored reading gives the same result. Each run also records the engine, template, reader model, source versions and rule-registry fingerprint, so an older report resolves to exactly the software and sources that produced it.
Which pharmacopoeias and guidance does it work against?
The controlled source register holds the requirements the engine is allowed to cite, each with its version. A requirement that is not in the register cannot drive a finding.
Validate a certificate now
Five automated analyses every month, free. No card required.