Case Study · Independent Testing

Two Vials, Two Failures: Why Your Customers Don't Trust PDF COAs

I bought two products from a vendor advertising 99% purity and sent both to an independent lab. Neither met the claim. Here is why the standard PDF COA is failing honest vendors, and how to actually prove your product is what you say it is.

BL BatchLedger Engineering
5 min read

If you sell products that require Certificates of Analysis, you already know the industry has a trust problem. Customers are increasingly skeptical of vendor claims, and for good reason.

To demonstrate why, I recently bought two products from a vendor advertising 99% purity and shipped both vials to an independent analytical lab. Both certificates came back showing significant issues.

Independent laboratory results for two vials purchased from the same vendor
Sample Label claim Independent result Verdict
Vial 1 99% Correct compound, 85.78% purity 13 pts under
Vial 2 99% No trace of the target compound Not detected

Both vials carried the same lot number: 2026-06-30.

I am not naming the vendor, because this isn't a takedown of one company. It's a clean illustration of a structural industry problem: the standard PDF COA is a document nobody can truly verify, which leaves honest vendors indistinguishable from bad actors.

The Problem with PDFs: Ambiguity and Manipulation

The lab tests themselves were accurate. The failure is in how COA data gets shared — as static PDF files — which creates vulnerabilities that hurt buyers and legitimate vendors alike. Here is what goes wrong when trust rests entirely on a PDF.

1. PDFs can be quietly edited

A PDF is just a digital piece of paper. Nothing structural stops a bad actor from changing an 85% purity result to 99% before uploading it to their website. A downstream buyer has no way to detect that the file was altered after the lab issued it.

2. Failed tests can be silently deleted

When my second vial failed completely, the result was a PDF that a dishonest vendor could simply choose not to publish. In a folder-of-PDFs model, missing records are invisible. Buyers only ever see the tests that passed.

3. No binding between lot and certificate

Both of my vials shared the same generic lot number: 2026-06-30. When lot numbers are just dates — or worse, reused across different products — buyers cannot confirm whether their specific vial was ever tested. It becomes trivial to stretch one good lab report across an entire year of production.

4. Skimming humans miss contradictions

A PDF relies on tired humans to read it. One of my certificates said "Identity confirmed" on page two, even though page one clearly stated "No compound detected." When data isn't structured, contradictions like that slip through and bad product ships.

The Business Cost of Unverifiable COAs

Bad lots happen in every industry that makes physical things. That part is survivable. What's hard to survive is having no mechanism by which a skeptical customer can check your claims.

Imagine a customer has a bad reaction, or independently tests your product and gets a bad result, then posts their findings on Reddit or a forum. Because your COAs are just PDFs, there's no verifiable lot record for anyone to look up. You can't prove their specific vial came from a clean batch, and they can't definitively prove it didn't. It becomes a permanent stain on your brand.

The vendor who publishes verifiable, per-lot certificates can survive a bad batch. The vendor who publishes static PDFs cannot survive a public accusation.

How BatchLedger Closes the Trust Gap

If you're a vendor doing things right, you already spend thousands of dollars on legitimate lab testing. BatchLedger exists to make sure your customers actually believe those results.

BatchLedger doesn't do the chemical testing — that's what your lab is for. It takes your lab's results and turns them into structured, tamper-evident records:

  • Fingerprinted integrity. Every COA gets a unique SHA-256 hash. If even one number changes after issuance, the fingerprint breaks, proving to your customers that the document is exactly what the lab provided. We covered the cryptography in detail here.
  • Lot-level binding. Certificates are tied strictly to specific lot numbers, which prevents old COAs from being reused for new batches. Customers search their exact lot and see the exact test.
  • Blockchain anchoring. Optional on Pro: COA fingerprints are anchored to a public ledger at the moment of creation, giving cryptographic proof of existence that cannot be retroactively edited or deleted.

You already do the hard, expensive work of independent testing. Don't let the weaknesses of PDF files undermine it. Make your claims checkable, and separate your brand from the bad actors.

BatchLedger is a self-hosted WordPress plugin that turns Certificates of Analysis into structured, hash-verified, optionally blockchain-anchored records.