Identity
Identity testing checks whether the tested material matches the labeled compound. The certificate names the method and reports the laboratory's result.
Three core tests: identity, purity, and net content. Additional tests vary by the testing laboratory and are listed on each individual certificate. Purity Analytics reviews the results and digitally signs the final PDF.
Identity, purity, and net content are the three core tests. The performing laboratory is named, and each certificate lists the additional tests that laboratory actually ran. Missing results are never filled with assumptions.
Identity testing checks whether the tested material matches the labeled compound. The certificate names the method and reports the laboratory's result.
The certificate reports the laboratory's measured purity percentage and the method used.
Net content states the measured peptide amount and its units, including individual component amounts when the laboratory reports them for a blend.
Additional tests vary by the testing laboratory and are listed on each individual certificate. They are not a fixed or guaranteed panel.
Current blend reports can list net peptide content separately for each named component. Purity Analytics preserves those component rows exactly as reported and does not infer a component from the product name, chromatogram, or a single unlabeled amount.
The library expands each peptide test into a deeper article: what the method measures, how it works, what a result can support, and what it cannot claim.
The performing laboratory owns the analytical source report. Purity Analytics owns evidence retention, independent transcription review, release status, branded rendering, and the final document signature. Those facts are stored separately so no importer is represented as the laboratory and no unsigned or ineligible result becomes public.
The performing laboratory issues its report. Purity Analytics retains the original PDF, file hash, accession and lookup identifiers, acquisition record, and reported product and lot details.
An importer creates structured result candidates, then a separate reviewer compares identity, purity, component amounts, appearance, screening results, and missing fields with the retained source report. Extraction output is never published as fact without review.
A versioned release rule evaluates every required result. Identity failure, a missing blend component, an unsupported panel, or a required test that was not reported cannot be rescued by a high purity percentage.
Only an approved canonical snapshot is rendered with the authorized YPB or client brand. Purity Analytics then signs those final bytes with its Sectigo document-signing certificate and records the signed-file hash and signing evidence.
The approved signed artifact becomes the active COA for its exact product, lot, and brand. The verification page re-hashes the served bytes, while compatible PDF software validates the embedded document signature. Retired artifact bytes return 410 Gone.
Every COA issued through the current signing workflow carries reviewed source provenance, an approved release decision, and an independently verifiable PDF signature. The PDF names the performing laboratory and preserves research-use-only limitations. Adobe Acrobat Reader verifies the cryptographic seal; the public verify website re-hashes the served PDF bytes.
Before a COA can show as valid, its structured record must be linked to the retained laboratory report and independently reviewed. The final PDF names the performing laboratory while keeping the importer, reviewer, Purity Analytics issuer, and document signer roles distinct.
Every Purity Analytics COA issued through the current signing workflow is signed in-house with a Sectigo-issued certificate stored on a FIPS-certified USB hardware token. The private key never leaves the token and is PIN-gated. The signature uses RSA-SHA512 and is timestamped by Sectigo's RFC 3161 trusted timestamp authority.
The signing cert chains to a root in the Adobe Approved Trust List (AATL), which Adobe Acrobat Reader ships with. Opening a signed COA in Reader produces a blue "Signed and all signatures are valid" banner with zero configuration. The same standards-based PKCS#7 envelope (ISO 32000-2, RFC 5652) is what every PDF tool with signature support reads.
Source provenance, independent review, the performing-lab page, the signing pipeline, the chain of trust from your COA to the AATL root, the per-request Tier-1 hash binding, and how to verify the signature offline yourself.
The performing laboratory creates the source report. Purity Analytics retains that evidence, reviews the structured record against it, applies the approved brand, and digitally signs only the final rendered PDF. The roles remain separate and visible.
The signature is document metadata plus cryptographic validation data. It does not replace the analytical method rows, specifications, or measured values printed on the COA.
The analytical report content remains the basis of the final package. The signature layer is applied after the Purity Analytics COA is prepared for delivery.
A PDF digital signature records signer certificate metadata and lets compatible PDF viewers report whether signed bytes changed after signing.
The COA reports identity, purity, and net content, alongside any additional tests the named laboratory performed. Each result retains its own method and scope.
Tell us what products need testing, expected batch volume, and the COA format you need for results produced through the Purity Analytics workflow.
tests@purityanalytics.com