How a vendor is checked
The same steps, in the same order, for every vendor. Each finding on a card can be traced to a step below and to an exhibit with a hash and a UTC timestamp.
Eight steps, every time
- Step 01
Enter the site
We open the vendor storefront the way a customer does, pass any research-use gate, and record the pages visited with a UTC timestamp.
- Step 02
Collect every COA
Every Certificate of Analysis linked from a product page, a COA page or a downloadable file is saved as published. Nothing is sampled; the set is complete at the time of capture.
- Step 03
Verify at the issuing laboratory portal
Each report names a laboratory. We look the report up at that laboratory's own verification portal using the identifiers printed on the document, and record the portal response verbatim.
- Step 04
Compare fields with the laboratory original
When the portal returns the original, we compare it field by field with the vendor copy: client, manufacturer, sample, batch, dates, tests requested and results. Every difference is recorded with both values.
- Step 05
Capture evidence with SHA-256 and UTC timestamps
The vendor copy, the portal response and the laboratory original are each stored with a SHA-256 hash of the untouched file and the capture time in UTC.
- Step 06
Right of reply, 7 days
We send the findings and the evidence to the vendor's published contact address and wait 7 days. Anything the company sends back is published with the card.
- Step 07
Publish
After the window closes the card goes live: verdict, findings, exhibits, hashes, the contact record and the company response. Verified vendors receive a score.
- Step 08
Re-check on a schedule
Verified vendors are re-checked every 90 days and whenever new reports appear. Re-checks append to the timeline; earlier results stay visible.
What decides a verdict
Sourcing
We collect every Certificate of Analysis the vendor publishes, from product pages, COA pages and linked files. Each file is stored with its source URL, the capture time in UTC and a SHA-256 hash of the file as downloaded. Reports sent to us privately are checked the same way and marked as supplied by the sender.
Verification at the issuing laboratory
Each report is checked at the laboratory named on it, using that laboratory’s own verification path and the identifiers printed on the document, for example a task number and a unique key. The portal response is the finding. We record what the laboratory database returned, in its own words, with the request and the time.
Comparison
When the laboratory returns its original, we compare it with the vendor copy field by field: client, manufacturer, sample, batch, order, receipt and analysis dates, tests requested, results and comments. A difference is recorded with both values. A difference that changes who the report is about or what was tested is marked material.
A single failed report fails the vendor
A report returned as not found by the laboratory database, or returned as an original that differs from the vendor copy (edited), fails the vendor. One such report is enough. The card states which report, which portal, which response and when.
Unverifiable laboratories
When the laboratory shown publishes no verification path, or the report carries no identifier we can look up, the report is unverifiable. An unverifiable report does not fail the vendor. It counts against the authenticity category in the score, and a vendor with any unverifiable report is not ranked until every report has been authenticated. The labs page lists what each laboratory offers.
Evidence
Every exhibit is stored as captured. We never crop, annotate or recompress an original. The SHA-256 shown beneath each exhibit is computed over the stored file at ingest, so a reader can download the file and confirm it is unchanged. Raw portal responses are kept beside their screenshots.
Right of reply
Before a card is published we send the findings and the evidence to the vendor’s published contact address and record the date. The company has 7 days to respond. Whatever it sends is published verbatim in the company response block, with the date received. If nothing arrives, the block says so with the deadline that passed. Publication does not wait beyond the window.
Scoring
A score is computed only after every report has been authenticated. Scores are withheld for vendors with a failed verification and for vendors whose response window is still open. The seven categories and their weights are listed in the weights table below; the weights are fixed in code and every score on the site is computed from the same table.
Re-audit cadence
Verified vendors are re-checked every 90 days, and sooner when a new report appears or a reader reports a change. Failed vendors are re-audited on request after the vendor has addressed the finding. Each re-check adds an entry to the timeline on the card; the earlier entries stay.
Re-verification after a fix
A vendor that removes or replaces a failed report can write to audits@coawatchdog.com and ask for a new audit. We rerun the full process on the current site. If every report authenticates, the card’s verdict changes to verified with the date of the new audit, and the earlier finding remains on the timeline with its date and evidence.
Corrections
When we get something wrong, we say so on the card with a dated note beneath the finding, and the original text stays readable. The process for requesting a review, and what evidence we accept, is in the corrections policy.
What we never do
- No affiliate links. A link to a vendor site is a plain link.
- No paid placement. A vendor cannot pay to appear, to rank, or to be removed.
- No vendor relationships. We do not consult for, test for, or accept product from vendors.
- No edited exhibits. Evidence is published as captured.
- No silent removal. A published finding is corrected or updated with a dated note; it is not deleted.
Seven categories, one table
Rendered from the same constants the scoring code uses. Weights sum to 100%.
| # | Category | Weight | What it measures |
|---|---|---|---|
| 01 | COA authenticity | 30% | Can the issuing laboratory independently verify each report? |
| 02 | Testing coverage | 20% | What share of listed products and sizes have current testing? |
| 03 | Testing quality | 15% | Identity and purity, quantity, sterility and endotoxin where applicable. |
| 04 | Pricing | 15% | Price per milligram relative to comparable vendors and products. |
| 05 | Product selection | 10% | Number and breadth of products. |
| 06 | Website and UX | 5% | Navigation, COA accessibility, product information. |
| 07 | Transparency | 5% | Contact information, policies, lot and batch traceability. |
Each category is scored 0 to 100 and multiplied by its weight; the total is the sum. Authenticity is scored from the share of reports the laboratory authenticated. A vendor with any failed report receives no score, per M-04 and M-08. Ranked vendors appear on the rankings page.
What a verdict does and does not say
- A verdict describes the reports published at the time of capture. A vendor can add, remove or replace reports afterwards; the capture time on every exhibit tells the reader when we looked.
- An authenticated report shows that the laboratory issued that report for that sample. It says nothing about any vial shipped later, and we do not test products ourselves.
- A portal lookup depends on the laboratory keeping its portal online and its records complete. A lookup that fails because the portal is down is retried and recorded as pending, never as not found.
- Field comparison reads text from images and PDFs. Where the read is uncertain the field is shown to a person before a difference is recorded.
- Pricing, selection and website categories are snapshots taken during the audit and can change daily. They carry 35% of the score between them for that reason.
- We check the reports a vendor publishes. Reports a vendor shares only by private request are outside the audit unless a reader sends them to us.