Supply Chain

Cryptographic chain of custody for physical goods.

Pharma RTR, cold chain, logistics — every handoff, every authorization, every deviation — a canonical leaf in an append-only log. No single party can release a compromised batch to meet a deadline.

EU GMP Annex 17FDA PATISO 28000

The problem

A product's memory is fractured across the databases of its raw material suppliers, manufacturers, freight forwarders, customs brokers, and retailers. Reconstructing its history for a dispute, a regulator, or a concerned customer is a forensic nightmare.

Internal quality systems (PAT, QbD, Continuous Quality Verification) produce valuable data — but it's siloed, operator-controlled, and unverifiable by external parties. A manufacturer can say "the cold chain was maintained." Today, no one can prove it without trusting the manufacturer's own records.

How the five gates map to supply chain

GateSupply chain applicationExample
G1 Semantic Validity Temperature, humidity, vibration data within statistical control limits (H ≥ 0.40) Vaccine batch: temp readings within 2–8°C with bootstrap CI confirming conformance
G2 Financial Validity A deviation is linked to a specific event, not a systemic failure (C ≥ 0.40) Temperature spike attributed to a specific door-opening event at warehouse B, not cold chain breakdown
G3 Operational Validity The deviation didn't compromise the product's critical quality attributes (E ≤ 0.60) Spike duration (47 seconds) within the product's validated design space — no CQA regression
G4 Policy Admission Data is from instrumented, tamper-evident sensors — not self-reported HOOKED evidence: temperature logger with sealed hardware attestation certificate
G5 Cryptographic Finalization A designated quality manager approved the release, committed to Merkle log Biometric sign-off on Sovereign Authority device — unforgeable, legally binding under EU GMP

How the validator quorum maps

The release of a batch isn't a single decision. It requires 3-of-4 quorum:

ValidatorRoleWhat they verify
Manufacturer's systemCustomerProcess data within specification
Logistics provider's systemAuditorHandling and transport conditions met
Independent quality auditorIndependentEvidence integrity and statistical validity
Regulatory nodeRegulatorCompliance with EU GMP / FDA requirements

Transparency log as chain of custody

Every event in the product's lifecycle — raw material sourcing, each manufacturing step (CQV data), transport handoffs, storage conditions, repair/return events — becomes a canonical leaf. The log is a cryptographic chain of custody more reliable than any paper trail or siloed database.

Monitors: customs, insurers, customers

Customs authorities, insurance companies, and end customers run monitors that continuously verify the log's consistency. They can prove a specific batch is authentic and was handled correctly without accessing the manufacturer's internal systems.

Deterministic settlement

The verified passage of goods through the final gate (acceptance by recipient, confirmed by inclusion proof) automatically triggers payment to the logistics provider. Months of invoicing and dispute resolution replaced by deterministic settlement against the log.

Replay as audit

A logistics provider can replay every handoff authorization for a specific shipment. No interviews, no document requests — just replay the exact chain of custody decisions, gate by gate, from origin to destination. Each replay is a permalink.

Closed loop in action

A vaccine batch is authorized for release at 2–8°C. During transport, the execution trace records a temperature spike to 9°C for 3 minutes.

Variance record: l2_distance: 0.12 classification: DRIFT omega_breach: false (batch remained within validated design space) drift_direction: { temperature: "degraded" } HCE nudge: -0.025 H, -0.020 C, +0.025 E (mild)

The next authorization cycle's observables reflect the drift — tightening governance for the following shipment.

If the spike had exceeded the design space: classification: BREACH, omega_breach: true — visible to every monitor watching the log, without the monitor needing access to the manufacturer's systems.

Regulatory alignment

EU GMP Annex 17

Real Time Release Testing — AGTS provides the cryptographic evidence infrastructure for RTRT gate decisions.

FDA PAT Guidance

Process Analytical Technology — AGTS records PAT measurement decisions as canonical leaves.

Falsified Medicines Directive 2011/62/EU

Serialization and verification — AGTS provides an independently verifiable proof chain per batch.

ISO 28000

Supply chain security management — AGTS produces the cryptographic audit trail ISO 28000 requires.

See the plugin API → Talk to us about supply chain →