Security

How a Traceabl certificate stays sealed

A Traceabl COA is more than a static PDF. Public results are built so anyone can re-check what was issued — without exposing customer identity.

Research use only. Not for human or animal use.

Integrity Seal · Poster (240px) · sonar + short hash · full orbit

Full Integrity Seal guide →

Security pillars

  • Sample ID — unique key linking the sample, lab records, COA, and verify page (format PP-YYMMDD-XXXX).
  • Lab-owned loop — Traceabl is the laboratory that issues the Sample ID, runs the method, and hosts the verify record.
  • Integrity Seal — SHA-256 fingerprint of public fields only (Sample ID, peptide, purity, method, test date).
  • QR → public verify — opens the verify page so the result can be re-checked anytime. The QR is a door; the seal is the fingerprint.
  • Optional Base ledger — when published, the same fingerprint can be recorded on Base (Ethereum L2). No customer names or private order data go on-chain.
  • Scope honesty — HPLC-UV purity is not mass-spec identity, safety, or clinical approval.

Integrity pipeline

  1. Collect public fields only (never customer PII in the hash)
  2. Normalize and join in fixed order → canonical payload
  3. SHA-256 seal stored with the sample
  4. Optional: register the same hash as calldata on Base
PP-260803-0001|BPC-157|98.7|TM-HPLC-001|2026-08-03

Public vs private

Public

  • Sample ID
  • Peptide name
  • Purity (area %)
  • Method · test date
  • Integrity hash (± chain tx)

Never public

  • Customer names
  • Email / phone
  • Shipping address
  • Payment details

How to verify

  1. Find Sample ID on vial label, Result Card, or PDF
  2. Open Verify or scan the QR
  3. Confirm peptide, purity, method, date, and integrity hash
  4. If a chain transaction is listed, compare explorer input data to the hash

More questions? See the FAQ.