We are at Vitafoods Asia.

Come and say hello, or reach us from here.

Get in touch

The platform

Three records, a middle that does arithmetic, and a receipt for every rule.

This is the page for the question a careful buyer asks before handing regulated documents to a small company: is any of this real. Everything below is either a mechanism that is in the product today, or a sentence that says on its face that it is not. The few numbers here are counted at page load from the same files the checks run against, and the ones that do not flatter us are the reason to trust the rest.

No card, no account, and no call to book. Tell us what you make and where you sell it, and we will come back to you.

The core

Three records, and the correspondence between them

Everything you read in the product is a projection of three records and the matching between them. There is no fourth thing, and there is nowhere an answer can come from that is not one of these.

Facts

What is true about a product. What it is, what is in it, what it claims, who makes it, where it is sold and through what channel. Every fact carries where it came from and how sure that source is, so a value you confirmed always outranks one inferred on your behalf. A fact nobody has given us stays absent rather than being filled in with a likely answer.

Rules

What anyone with power over that product demands. A national regulator, a state, a marketplace, a retailer, a certifier, and your own written specification, all in one shape. Each one carries the condition under which it applies, what would satisfy it, what happens if it is not met, and the citation it came from.

Evidence

What proves the demands are met. A measured value, a document, a registration, a written statement, a calculation. Evidence is not the same thing as a file: one test report carries dozens of separate assertions, and each of them answers, or fails to answer, its own rule.

The product keeps a correspondence between three records. Facts: what is true about a product, including what is in it, what it claims and where it is sold. Rules: what anyone with power over it demands, from a regulator, a state, a marketplace, a buyer, a certifier or your own written specification. Evidence: what proves those demands are met, such as a measured value, a document or a written statement. The middle is the matching: given these facts, which of these rules apply, and does this evidence answer them. That middle is ordinary code over stored records with no model call on the path, so the same records give the same answer every time and every line names the rule it came from. What comes out is one of a small set of named states: answered, expiring, missing, waiting on a fact that has not been given, or not yet mapped.

Facts
Every fact carries where it came from and how sure that source was, so a value you confirmed always outranks one read on your behalf. A fact nobody has given us stays absent rather than being filled in with a likely answer.
Rules
A national regulator, a state, a marketplace, a retailer, a certifier and your own written specification all take one shape: the condition it applies under, what would answer it, what happens if it is not answered, and the citation it came from.
Evidence
Evidence is not the same thing as a file. One test report carries dozens of separate assertions, and each of them answers, or fails to answer, its own rule.

What comes out, in full

  • AnsweredThe evidence on file clears the rule, and the line shows both.
  • ExpiringIt clears today and stops clearing on a date, which is a scheduled event rather than a discovery.
  • MissingNothing on file answers the rule, and the thing that would is named.
  • Waiting on a factA fact the rule needs has not been given, so the answer names the fact rather than reading a blank as a pass.
  • Not yet mappedThis corner of the rule space has not been drawn yet, and the answer says which corner. Neither this nor the one above may roll up as green.
A drawing of the mechanism, not a screenshot. It shows no measured value, no count and no customer, because it is the shape of the machine rather than a run of it.

The correspondence

The matching is the middle. Given these facts, which of these rules apply, and does this evidence satisfy them. That is one question, answered by one function, over versioned copies of all three records and the instant you are asking about.

What happens between a file arriving and an answer

Six steps, in this order, every time. Nothing here is a summary of something more complicated happening elsewhere: this is the path, and each step leaves a row you can read afterwards.

  1. A document becomes values, with a confidence on each one

    A file arrives by forward, upload or request link. It is sniffed for what it actually is rather than trusted by its extension, read whatever its layout and whatever its language, and turned into named values with their measures, their dates and the place on the page each came from. Every value carries how sure the read was, and a value read below the threshold waits in your review queue instead of entering the record.

  2. What cannot be placed says so, in those words

    Placing a document against a kind and against a product is a decision, so it is allowed to fail. A document the classifier cannot place is filed as unrecognised, named on your queue, and left for you. It is never assigned to the nearest plausible kind, and an unreadable page is never treated as an empty one.

  3. A market becomes rules, each anchored to the issuer's own page

    A requirement is read out of the source the issuer publishes, never out of a consultancy note or an aggregator, and it is stored with the condition under which it applies, what would satisfy it, what happens if it is not met, a verbatim sentence in the source's own language, and a hash of the page that sentence came from. A machine translation may ride alongside the quote and is never allowed to be the quote.

  4. Facts and rules are matched by arithmetic, not by a model

    Which rules apply to this product, whether the evidence clears them, which of two limits is stricter, and what has expired: all of it is ordinary code over stored rows, with no model call anywhere on the path. Models turn mess into structure at the two edges and are never allowed to decide anything in the middle.

  5. The same inputs give the same answer, on any machine

    Every run records exactly what it read: the fact rows, the evidence rows, the rule pack versions, the engine version and the instant it was answering as of. Ask the same question of the same records tomorrow and the answer is identical, line for line, because it is a function of them rather than an opinion about them.

  6. When a source moves, the rule it fed is re-checked and can lose its tier

    Every anchored source is enrolled in monitoring with its own cadence and its own maximum tolerated age. A daily job fetches what is due, normalises it the same way every time, hashes it, and compares the stored quote against a fresh fetch. Drift opens a task naming the source and the rules it feeds; drift, an age past budget, or a recorded contradiction each lower a rule a tier the moment the rules load. Nothing rewrites a rule from a diff by itself.

The engine is not written per category. Rules are data, so a market or a category is a set of rule records with their own citations, and opening one is an addition to the library rather than a rebuild. Every rule that arrives faces the same anchoring, the same quote and the same gates as everything already in it, which is why nothing here is claimed before it is mapped.

The split

AI at the edges. Arithmetic in the middle.

This is the one design decision the rest of the platform rests on, and it is the reason an answer here can be checked instead of believed.

What the models do

Turn mess into structure, at both edges. A test report in a layout nobody has ever seen becomes named values with their measures and their dates. A regulation becomes a rule record with a condition, a citation and a verbatim quote. Every output of that carries a confidence and a source, and anything read with low confidence waits for a person instead of entering the record.

What the middle does

Nothing a model touches. Which rules apply, whether the evidence clears them, which of two limits is stricter, what expires and when: all of it is ordinary code over stored records, with no model call anywhere on the path. A model answer cannot be reproduced and cannot be audited, so the model builds the map and is never allowed to be the map.

Why that makes an answer checkable

  • Every run keeps its own inputs

    A check records exactly what it read: the fact rows, the evidence rows, the rule pack versions, the engine version (today 0.4.0), and the instant it was answering as of. What we said on a given day is therefore a function call rather than an excavation, and the same inputs give the same answer on any machine, forever.

  • Unknown is a value, never a quiet no

    A rule's condition can answer three ways: yes, no, or unknown. Unknown travels: the answer names the fact it is waiting on rather than reading a blank as a pass or a failure.

  • Two answers exist to stop a false all-clear

    A check can land in nine states. One of them says a fact is missing and names it. Another says this part of the map has not been drawn yet and names the cell. Neither is allowed to roll up as green, which is what keeps a readiness figure from being a decoration.

  • Measures are never converted across families

    Two limits stated in measures that do not compare are not turned into each other. The row goes to review with both numbers shown, because a guess that looks like arithmetic is worse than an open question.

  • Stricter wins, and the loser is kept

    Where two authorities bound the same value, the stricter one is applied and the other is recorded beside it rather than discarded. Your own written specification competes as an issuer and is allowed to beat the public limit.

  • Nothing is edited

    Facts, evidence, answers and decisions are superseded, never overwritten. That is what makes the history worth reading and what makes a replay of an old answer honest.

One file

The same path, drawn on a single document

Read, placed as a kind, values taken with the position each one came from, matched against the rules that select the product, and the field that could not be read named rather than guessed. The last stage is the one the rest of it rests on.

What happens when a document arrives, in five stages. One: it arrives, at an address generated for your account or dropped on the page. Two: it is placed as one of the kinds the classifier knows, and anything it cannot place is filed as unrecognised rather than guessed at. Three: values are read from their positions on the page and stored with those positions and a confidence. Four: the readings are matched against the rules that select this product, and every line comes back with the authority that set it and the citation to read it. Five: anything read with low confidence is named and sent to a person, and the row stays without a reading rather than being filled with a guess.

  1. 01

    It arrives

    A file lands at the address we generate for your account, or you drop it on the page. There is no form to fill in first.

    • Attachmentexample-test-report.pdf

    Forwarding an email is the whole intake step.

  2. 02

    It is placed as a kind

    Before anything is read, the document is placed as one of the kinds the classifier knows. That decides which reader runs and which rules it can ever answer.

    • Placed asTest report

    Anything the classifier cannot place is filed as unrecognised rather than guessed at.

  3. 03

    Values are read, with where they came from

    Each value is read from its position on the page and stored with that position and a confidence, so a reading can be opened back to the spot it was taken from.

    • ProductMagnesium Glycinatepage 1
    • Lot codeL-0000-EXAMPLEpage 1
    • Test dateexample datepage 2

    Example values, invented for this drawing.

  4. 04

    It is matched against the rules that apply

    The readings meet the rules that select this product, and each line comes back with the authority that set it and the citation to read it.

    • Heavy metals limitanswered
    • Report ageexpiring
    • Serving sizewaiting on a fact

    Named here without their limits on purpose: the real limits and citations come from the shipped rule library, which you can read without an account.

  5. 05

    What could not be read is named

    A field read with low confidence never enters the record as a value. It goes to a person, and the row stays empty until one answers it.

    • Expiration statementFlagged for review

    This is the whole difference between a reader you can trust and one you cannot.

A labelled drawing of the real pipeline. The file name, the readings and the lot code are invented for the drawing; the stages, and the refusal to guess at the last one, are the product.

The roster

Meet the team that runs your compliance department

There are more agents in build. They get named here when you can run them, and not before. A roster is a promise, and this buyer can check.

Intake

Reads every document on arrival

Reads any document a supplier sends, in whatever layout it arrives, and files it against the right product and lot.

Automatic
Classification, extraction and filing run on arrival. No folder structure, no data entry, no template per manufacturer.
Needs you
Anything read with low confidence, or in a unit that could be two things, waits in your review queue instead of entering the ledger. “We could not read this” is always an available answer.

How a document travels

Verify

Checks every value against the rules

Checks every extracted value against the requirements resolved for that product and against your own specification, stricter limit applied, each line carrying its citation.

Automatic
Resolution and the comparison. Where two authorities bound the same analyte, the stricter limit is applied and the other is recorded, not discarded.
Needs you
Rows where no public authoritative number exists are shown as advisory and can never be reported as a failure. Verify checks the values, the specification leg, and the label leg: a label version's artwork against the required elements for its market, with an element it could not read held for a person rather than passed.

The requirements library, with its citations

Keep

Holds the record and hands it back

Holds every document traceable back to the original bytes, answers questions from the file with citations, and hands the whole thing back whenever you ask.

Automatic
Filing, indexing, and the append-only history. Every change is written; nothing is overwritten and nothing is hard-deleted.
Needs you
Nothing. Keep does not decide anything. It is the record the deciding is done against, which is why it is append-only.

Collect

Asks your partners for what is still owed

Turns every document a partner still owes you into a request that is already written: a no-login upload link and a message you can paste straight into your own thread.

Automatic
Drafting the request, minting the upload link, and filing whatever arrives. The manufacturer never makes an account and never sets a password.
Needs you
Sending is yours. Follow-ups on day 5 and 12 exist, but they are off until you turn them on, per manufacturer or per request. Most brands would rather run their own factory relationships.

Audit

Says what is ready and what is not

The full-stack readiness picture on demand: what is present, what is stale, what is missing, what is unreconciled, and what fixing it costs. This is the free check.

Automatic
The whole check, in about a minute, for a stranger who has not told us their name.
Needs you
You decide what to do with it. It names what a reviewer would find; it never calls a product a pass or a fail on anyone’s behalf.

Get in touch

Assemble

Builds the pack a reviewer asks for

Builds the outbound pack a reviewer accepts, from templates, complete, ordered the way the recipient expects, and pre-flighted before it goes.

Automatic
Staging, ordering and the pre-flight. A pack missing a document the recipient requires is refused before it is generated, with the reason.
Needs you
The signature is always a named person at your company. Nothing leaves without it. The three templates are there, and so is a fourth way to build one: a buyer’s own layout, learned from what they send you, checked once by somebody here, and reused every time.

Where a card says a leg is still in build, believe the card

One of the six is honest about an unfinished half on its own card rather than in a footnote: checking what a label and its claims say is not part of what the checker ships today. It is named where a reader is actually looking, and the day it ships the card loses the words rather than keeping them out of caution.

Labels

Shipped

The record is real: a label version per product per market, with statuses, parallel drafts, and lots pinned to the version they were printed under. That is the part a recall or a border check asks for.

So is the engine. Each market resolves its own required-element checklist from the library, with the section behind every element, and the artwork is read into evidence the same way a certificate is: low-confidence reads go to review rather than into the record, and an element we could not read comes back unclear rather than present or missing. Generation runs the same rules in reverse. Your profile, your market and your numbers come back as a complete content specification and a clean draft, with every element carrying its citation and every gap naming the record it still needs.

Artwork is not generated. There is no layout, no typeface and no print file: what comes out is the words and the numbers for whoever sets the artwork. Typography, type sizes and where on the package a statement sits are not checked either, and every report says so on its face.

The library

How a rule gets in, and how it stays current

A rule is not typed in once and then trusted because it is old. It is anchored, quoted, attacked, and watched, and each of those is a mechanical step that leaves a record you can read.

Where it may be anchored

The anchor is the issuer's own site. A consultancy note or an aggregator may point us at a rule; neither is ever allowed to be the source the rule is anchored to. Which domains count as an issuer's own is a registry, per market, rather than a judgement made per rule.

What has to be quoted

The citation carries a verbatim sentence in the source's own language, stored with a hash of the page it came from. A machine translation may ride alongside it and is never the citation. The quote is then string matched against a fresh fetch of the source, which is a literal comparison rather than a second opinion.

Who is watching it

Nothing counts as verified while nobody is watching its source. Promotion enrols the source in monitoring with its own cadence and its own maximum tolerated age, and the clock starts at that moment.

The registry today names 36 watched sources from 17 issuers. The fastest is looked at every 1 day, and the tightest maximum age before the rules it feeds start degrading is 7 days. Read at page load from the same registry the daily job runs from.

The six gates a rule has to clear

All six are mechanical and all six are logged. No signature grants anything: not the founder's, not a consultant's, not yours. A human review can be recorded beside a rule as a marker, and it is never an input to any of these.

The six promotion gates, what each one asks, and how the shipped library answers today
GateWhat it asksClears it today
Primary-source anchoringIs the anchor URL on the issuer's own official domain?30 of 57
Quote verificationDoes the verbatim quote still appear in an independent re-fetch of the source?0 of 57
Cross-language agreementDo the English-channel and native-channel readings state the same parameters?44 of 57
Adversarial refutationDid the rule survive a pass whose only job was to kill it?0 of 57
Structural completenessIs the rule checkable: closed predicates, real evidence contract, consequence and dates stated?0 of 57
Freshness registrationIs the source enrolled in monitoring, with a staleness budget that is not blown?17 of 57

A gate that could not run is not a pass. It answers “could not be checked”, it says why, and it blocks promotion exactly as a failure would.

Where the library stands today

57 rules carry a receipt. 0 of them clear all six gates, which is the only tier allowed to report a failure. 57 sit one tier below that: shown, cited, and unable to report a failure at all.

Publishing that number is the point of having the gates. They are mechanical, so they hold our own library back exactly as hard as they would hold anyone else's, and the honest reading of a young library is that most of it is still advisory. A rule below the top tier is downgraded in the engine before it ever reaches your product, so the tier is not a label on a page, it is what the code will let the rule do.

Receipts last evaluated 2026-09-02, against the real dataset. Counted at page load from the committed receipt file, which is the same file the checks read.

Watched daily, hashed, and diffed

Every source has its own cadence and its own maximum age. A job runs daily, fetches the sources that are due, normalises the text the same way every time, hashes it and stores the snapshot. A hash that moved is drift: it opens a task naming the source, its address and the kinds of rule it feeds. It never rewrites a rule by itself, because a machine that edits law from a diff is the one thing this design will not have.

Demotion is automatic and symmetric

Trust going up is slow and mechanical; trust coming down is immediate. Drift in the source, an age past its budget, or a recorded contradiction each lower a rule a tier at the moment the rules are loaded, with the reason attached. Trust only rises again by running the gates again. That is what makes promotion worth anything.

The same library, in the screen that uses it

This is the product's own comparison table, running on this page. Every limit and every citation in it is read from the library above at page load. The measurements beside them are an invented example, labelled as one.

Lot L-0000-EXAMPLE

Example product, one market

Example data

Scroll the table sideways for the reading, its citation and its note.

Example requirements comparison for one lot, using limits and citations from the shipped rule library
AnalyteRequiredFoundMethodStatus
Lead (Pb)lead≤ 0.5 µg/day0.21 µg/dayTitle 27 CCR §25705/§25805Two issuers bound this one. The stricter is applied, the other (10 µg/day) is kept beside it.ICP-MSPass
Cadmium (Cd)cadmium≤ 4.1 µg/day0.80 µg/dayTitle 27 CCR §25705/§25805ICP-MSPass
Arsenic, inorganic (As)arsenic_inorganic≤ 10 µg/day-Title 27 CCR §25705/§25805Not on the example report, so the row is missing rather than passing.-Missing
Mercury, total (Hg)mercury_total≤ 15 µg/daynot detected, detection limit 20 µg/dayUSP <2232>A non-detect clears a limit only when its detection limit sits at or below it. This one sits above, so the row goes to a person.ICP-MSNeeds review
Total Aerobic Microbial Count (TAMC)total_aerobic_microbial_count≤ 1000 cfu/g240 cfu/gUSP <2023>USP <2021>Pass
3 pass · 1 missing · 1 needs review
This is the product's own comparison table, the component itself and not a picture of one. The limits, the measures, the authorities and the citations are read at page load from the rule library that ships with the product, last verified 2026-07-24, so nothing in the required column or the citations is typed here. The measured values are invented for the example, and they always will be: publishing a customer's readings is the one thing this site promises never to do.

You can read the same tables, with every citation, in the requirements library, and the reasoning behind how a market gets mapped in how it works.

Reliability and security

Your formulas are trade secrets. We treat them that way.

Four commitments that are in the terms rather than only on a page, and four facts about where the data actually sits.

Never used to train AI
Your documents and your formulas are never used to train any model, ours or anyone else's.
Never visible to another customer
Every read is scoped to your account. Another customer cannot reach your files, and neither can their agents.
Partners see only what you share
A manufacturer, an importer or a buyer sees the slice you hand them and nothing else, for as long as you leave it open.
Export everything, any day
One click produces every document, every value we read and the whole history, on any plan and after you leave.
One place enforces isolation
Every read and every write against account data goes through a single scoping layer that binds the query to your account. Pages and routes never filter by account themselves, which is what makes the rule testable instead of a habit: the suite builds two accounts, fills both, then tries to read one through the other and asserts that not a single row crosses.
The history refuses to be rewritten
The activity record is append-only, and it is the database that refuses updates and deletes rather than the application politely declining to make them. There are no hard deletes, which is why an old answer can be replayed and still mean something.
Where the data lives
United States regions for the database, the file storage and the hosting. Encrypted in transit on every connection and at rest by the managed database. Uploaded files are never publicly addressable: every download passes an authenticated, authorised check on the server first.
Getting everything back out
One export produces every document, every value we read, and the whole history, on any plan and on the free product, whether or not you stay. It is written into the terms rather than offered as a courtesy.

The subprocessor list, the retention windows and the deletion route are all on the security page, named rather than summarised.

The meter

What you are never charged for

One thing is counted, and it is products you actively manage. Four things are never counted, and they happen to be the four a tool like this is usually sold by.

Markets

The same product sold into one country or into twenty is one product. Opening a market carries no add-on and no opening fee, and looking at what a market would require of you is free on every plan, the free product included.

Seats

Everybody at your company, plus the people you bring in from outside: your ops person, your consultant, your counsel. Nobody is priced out of the record they are supposed to be checking.

Partners

Every manufacturer, importer, buyer and lab you connect. They are not charged either: the upload link they use needs no account and no password on their side.

Documents

Every certificate, specification, registration, statement and photograph you send, and every value read out of them. Sending us more of your paperwork is the product working, not a bill arriving.

The whole ladder, the calculator, and the date each figure took effect are on the pricing page. Every price on this site is produced by the same function that charges the card.

Compliant Always organises and checks compliance documents. It is not legal or regulatory advice, and it does not guarantee the outcome of any review by any platform, retailer, or agency. You remain responsible for your products and your submissions.

See the engine on your own paperwork.

Every market, all six agents, the whole record and full export, on the products you tell us about. Get in touch and we will walk you through it.

No card, no account, and no call to book. Tell us what you make and where you sell it, and we will come back to you.