A sensor kit engineered around your chemistry and your CMO's reactor, recording at full resolution and signing each record at the source — so you hold a record of how the batch actually ran that neither the CMO nor I can alter afterward.
Today, what you know about your supplier's process comes through a paper trail — batch records, certificates of analysis, quarterly reports. All of it arrives after the reaction is over. When a problem shows up downstream months later, the paper trail is what you have to answer it with.
Every CMC team has read this line in a deviation report. Without process-level data captured at the time of the event, root cause analysis becomes archaeology.
The CoA tells you the batch met spec on the parameters that were tested. It says nothing about the ones that weren't — or about what happened during hours 3 through 7 of the reaction.
Everything above "the CMO said so" costs money and access — a person in the plant, a for-cause audit, a data request the quality agreement may or may not cover. And none of it gives you the continuous record after the fact.
By the time a batch-to-batch variability issue reaches your clinical sample, the affected material has been consumed, the process drift has already completed, and you're investigating a ghost.
The deployment is designed around four steps.
You know your chemistry; I don't. Your process chemists tell me which continuous signals matter for this molecule — the cooling ramp through crystallization, the exotherm shape, agitator load as solids form. I make sure those signals are captured at full resolution and can't be altered afterward.
The output of this step is a short, explicit list. It won't catch everything. It will mean that the parameters you already believe matter are actually there when someone asks.
I ship a sensor kit engineered against your parameter map — temperature, charge rate, mechanical load, and whatever else your chemistry demands. Each kit uses industrial-grade, non-invasive sensing matched to the specific reactor and process. Physical install is coordinated with your supplier; electrical and data isolation ensure I never touch their control system.
Sensor data is written to a hardware-signed log at the point of measurement — the private key is generated on the chip and never leaves it.
A hash commitment covering each window of records is published to a public layer that neither your CMO nor I control. This does something signing alone can't: it bounds when the records existed, and it makes retroactive editing detectable by anyone — including editing by me. The commitment is a fingerprint — it carries none of your process data.
You verify it without me. The records check against the device's public key and the public anchor, using a standalone script. An independent record that requires calling my server to validate isn't independent.
The limit. Cryptography can establish that a record came from a specific device and wasn't altered. It can't establish that the device was still on the reactor it was supposed to be on. Tamper-evident sealing, continuity monitoring, and periodic recalibration are partial answers. This is the weakest link in the design, and I don't have a clean solution for it yet.
The full-resolution profile for that batch, a side-by-side against any prior batch you name, and an integrity attestation you can verify yourself. If you've given me an explicit threshold — a maximum cooling rate, a temperature window — I'll flag when it was crossed. Your chemists will tell you what it meant for your product.
Not a control system. Not a replacement for the CMO's historian. Not PAT — no CQA inference, no model-based prediction. atomtruth makes sure the record exists and can be shown unaltered.
atomtruth exists because of a gap inside pharmaceutical manufacturing itself. The batch record took its shape from the 1978 GMP regulations, written for companies that manufactured in their own plants: quality proven by finished-product testing, process governed by written procedure.
Two things happened after that. FDA's own PAT guidance, in 2004, made the case for measuring the process rather than testing quality in at the end. And the industry moved to outsourcing, so the plant — and the process data it generates — is no longer the sponsor's. Twenty-two years later, what a sponsor receives is still the batch record. Consumer electronics closed the same gap, and not because a regulator asked.
At Apple, a 0.1% defect rate meant millions of failed devices. The only way to survive that math was to instrument every supplier process down to the shift and the machine — to treat quality as a measurable, traceable, enforceable signal rather than a trust-based claim. That discipline is what I'm bringing to the APIs and intermediates going into clinical trials.
I'm building this for North American biotechs. If you've ever had a deviation investigation end with "root cause undetermined," that's the conversation I'd like to have.
A first version of the trust chain is written. It has not been independently verified yet.
There is no reactor deployment yet, and no hazardous-area hardware. The measurement list above is a considered proposal, not a fixed selection.
I'm talking to people who run external manufacturing and quality assurance before building the rest, rather than after.
20-minute conversations. No pitch deck. I come with three specific questions about your current process-evidence workflow, and share what I'm learning across other conversations.