Skip to content
COAWatchdog
Methodology12 rules · 7 score categories

How a vendor is checked

The same steps, in the same order, for every vendor. Each finding on a card can be traced to a step below and to an exhibit with a hash and a UTC timestamp.

Process

Eight steps, every time

  1. Step 01

    Enter the site

    We open the vendor storefront the way a customer does, pass any research-use gate, and record the pages visited with a UTC timestamp.

  2. Step 02

    Collect every COA

    Every Certificate of Analysis linked from a product page, a COA page or a downloadable file is saved as published. Nothing is sampled; the set is complete at the time of capture.

  3. Step 03

    Verify at the issuing laboratory portal

    Each report names a laboratory. We look the report up at that laboratory's own verification portal using the identifiers printed on the document, and record the portal response verbatim.

  4. Step 04

    Compare fields with the laboratory original

    When the portal returns the original, we compare it field by field with the vendor copy: client, manufacturer, sample, batch, dates, tests requested and results. Every difference is recorded with both values.

  5. Step 05

    Capture evidence with SHA-256 and UTC timestamps

    The vendor copy, the portal response and the laboratory original are each stored with a SHA-256 hash of the untouched file and the capture time in UTC.

  6. Step 06

    Right of reply, 7 days

    We send the findings and the evidence to the vendor's published contact address and wait 7 days. Anything the company sends back is published with the card.

  7. Step 07

    Publish

    After the window closes the card goes live: verdict, findings, exhibits, hashes, the contact record and the company response. Verified vendors receive a score.

  8. Step 08

    Re-check on a schedule

    Verified vendors are re-checked every 90 days and whenever new reports appear. Re-checks append to the timeline; earlier results stay visible.

Rules

What decides a verdict

M-01

Sourcing

We collect every Certificate of Analysis the vendor publishes, from product pages, COA pages and linked files. Each file is stored with its source URL, the capture time in UTC and a SHA-256 hash of the file as downloaded. Reports sent to us privately are checked the same way and marked as supplied by the sender.

M-02

Verification at the issuing laboratory

Each report is checked at the laboratory named on it, using that laboratory’s own verification path and the identifiers printed on the document, for example a task number and a unique key. The portal response is the finding. We record what the laboratory database returned, in its own words, with the request and the time.

M-03

Comparison

When the laboratory returns its original, we compare it with the vendor copy field by field: client, manufacturer, sample, batch, order, receipt and analysis dates, tests requested, results and comments. A difference is recorded with both values. A difference that changes who the report is about or what was tested is marked material.

M-04

A single failed report fails the vendor

A report returned as not found by the laboratory database, or returned as an original that differs from the vendor copy (edited), fails the vendor. One such report is enough. The card states which report, which portal, which response and when.

M-05

Unverifiable laboratories

When the laboratory shown publishes no verification path, or the report carries no identifier we can look up, the report is unverifiable. An unverifiable report does not fail the vendor. It counts against the authenticity category in the score, and a vendor with any unverifiable report is not ranked until every report has been authenticated. The labs page lists what each laboratory offers.

M-06

Evidence

Every exhibit is stored as captured. We never crop, annotate or recompress an original. The SHA-256 shown beneath each exhibit is computed over the stored file at ingest, so a reader can download the file and confirm it is unchanged. Raw portal responses are kept beside their screenshots.

M-07

Right of reply

Before a card is published we send the findings and the evidence to the vendor’s published contact address and record the date. The company has 7 days to respond. Whatever it sends is published verbatim in the company response block, with the date received. If nothing arrives, the block says so with the deadline that passed. Publication does not wait beyond the window.

M-08

Scoring

A score is computed only after every report has been authenticated. Scores are withheld for vendors with a failed verification and for vendors whose response window is still open. The seven categories and their weights are listed in the weights table below; the weights are fixed in code and every score on the site is computed from the same table.

M-09

Re-audit cadence

Verified vendors are re-checked every 90 days, and sooner when a new report appears or a reader reports a change. Failed vendors are re-audited on request after the vendor has addressed the finding. Each re-check adds an entry to the timeline on the card; the earlier entries stay.

M-10

Re-verification after a fix

A vendor that removes or replaces a failed report can write to audits@coawatchdog.com and ask for a new audit. We rerun the full process on the current site. If every report authenticates, the card’s verdict changes to verified with the date of the new audit, and the earlier finding remains on the timeline with its date and evidence.

M-11

Corrections

When we get something wrong, we say so on the card with a dated note beneath the finding, and the original text stays readable. The process for requesting a review, and what evidence we accept, is in the corrections policy.

M-12

What we never do

  • No affiliate links. A link to a vendor site is a plain link.
  • No paid placement. A vendor cannot pay to appear, to rank, or to be removed.
  • No vendor relationships. We do not consult for, test for, or accept product from vendors.
  • No edited exhibits. Evidence is published as captured.
  • No silent removal. A published finding is corrected or updated with a dated note; it is not deleted.
Score weightsTotal 100%

Seven categories, one table

Rendered from the same constants the scoring code uses. Weights sum to 100%.

Score categories, weights and what each measures
#CategoryWeightWhat it measures
01COA authenticity30%Can the issuing laboratory independently verify each report?
02Testing coverage20%What share of listed products and sizes have current testing?
03Testing quality15%Identity and purity, quantity, sterility and endotoxin where applicable.
04Pricing15%Price per milligram relative to comparable vendors and products.
05Product selection10%Number and breadth of products.
06Website and UX5%Navigation, COA accessibility, product information.
07Transparency5%Contact information, policies, lot and batch traceability.

Each category is scored 0 to 100 and multiplied by its weight; the total is the sum. Authenticity is scored from the share of reports the laboratory authenticated. A vendor with any failed report receives no score, per M-04 and M-08. Ranked vendors appear on the rankings page.

Limitations

What a verdict does and does not say

  • A verdict describes the reports published at the time of capture. A vendor can add, remove or replace reports afterwards; the capture time on every exhibit tells the reader when we looked.
  • An authenticated report shows that the laboratory issued that report for that sample. It says nothing about any vial shipped later, and we do not test products ourselves.
  • A portal lookup depends on the laboratory keeping its portal online and its records complete. A lookup that fails because the portal is down is retried and recorded as pending, never as not found.
  • Field comparison reads text from images and PDFs. Where the read is uncertain the field is shown to a person before a difference is recorded.
  • Pricing, selection and website categories are snapshots taken during the audit and can change daily. They carry 35% of the score between them for that reason.
  • We check the reports a vendor publishes. Reports a vendor shares only by private request are outside the audit unless a reader sends them to us.