Skip to main content

CertaScan

Verification, and what it can honestly tell you.

CertaScan confirms that a COA came from CertaSafe, that the copy in front of you is unaltered, and what it was tested for. Everything else is outside what verification can establish.

Three ways to verify

  1. 1

    The secure code

    Printed on the COA, in the form CS-XXXX-XXXX-XX. Type it in, or follow the QR destination that carries it, and the record resolves.

  2. 2

    The COA identifier with its lot

    Both are printed on the COA, and both are needed. An identifier on its own resolves nothing, which is deliberate: a lookup should require something only a holder of the document has.

  3. 3

    The file itself

    The strongest check. Your browser computes the fingerprint of the exact bytes you hold and sends only that, so the document never leaves your device, and the comparison is byte for byte against what CertaSafe released.

Each one requires something only a holder of the document has. There is no way to browse COAs, no public client directory, and no lookup by company name.

A COA is verifiable only if its customer says so

Testing is confidential. A COA becomes publicly verifiable only when the customer who holds it authorizes that, one COA at a time, from their portal account. They can withdraw the authorization at any time, and the lookup stops resolving when they do.

So a code that does not resolve is not evidence of a forgery. It can equally mean the customer has not authorized that COA, or has withdrawn it. If you hold a COA and expected it to resolve, ask the company you received it from: only they can authorize it.

What a lookup reveals, and what it never reveals, is set out in the privacy policy. It never shows who the customer is, what else they have ordered, or any COA they have not authorized.

Revisions, and why an old one still resolves

A COA is revised only to correct an error in it. The revision is a new version and the one it replaces is marked superseded, but the superseded version stays identifiable, and so does a COA CertaSafe has withdrawn.

That is the point. Someone presenting a corrected or withdrawn COA as current is exactly the thing a holder needs to be able to find out, and a lookup that quietly resolved nothing would hide it.

What verification is not

Verification confirms provenance and integrity. It does not restate the conclusions on the COA, and it never means a product passed anything.

  • A verified COA is not a statement that a product is safe, suitable for any use, lawful to sell, or compliant with any standard.
  • It describes one sample, from one lot, on the date tested. Another vial, unit, batch, or lot has its own record, including other units from the same lot.
  • It covers the tests named on it and nothing else. A COA for purity says nothing about sterility, endotoxins, or metals.
  • CertaSafe offers no badge program and authorizes no badge use. Verification is by COA through CertaScan, and that is the only form of verification CertaSafe authorizes anyone to present.

The full terms of use for COAs and verification are in the terms of service.