TRUST AND VERIFICATION

Trust, accreditation and verification

What we hold, what we do not hold, and how to check a certificate without trusting us.

SOURCES LAST REVIEWED 2026-08-27

Is Axiom ISO 17025 accredited?

Axiom Analytics does not currently hold ISO/IEC 17025 accreditation. The platform identifies method status beside each result and blocks conformance and COA release when reopenable signed method/QMS evidence is absent; controlled accession remains distinct. Software controls are not a substitute for physical laboratory qualification. This statement will be updated only when the corresponding evidence is filed.

If you are not accredited, why should I trust a result?

Because the result is checkable and each reported layer carries its method status. Validated in-house and verified-compendial are historical/controlled vocabulary that require reopenable signed evidence; research/qualification-held is not a validated release claim. Descriptive software records alone never authorize a conformance decision or COA release. Accreditation is separate, and Axiom does not currently hold ISO/IEC 17025 accreditation. If accreditation is required for your use, choose an appropriately accredited laboratory.

How do I verify an Axiom certificate?

Look the report ID up against the laboratory record rather than trusting the copy you were sent. Scan the QR on the certificate, enter the report ID at axiomanalyticslab.com/verify, or call the public JSON endpoint. All three resolve to our servers, not to the vendor's, which is the property that makes verification worth anything.

Can I verify a certificate without trusting your website?

Yes. Every released certificate carries an Ed25519 signature over a SHA-384 digest of a canonical payload. We publish the exact canonicalisation and digest recipe and the public keys as a JWKS, so you can reproduce the digest and verify a certificate you already hold entirely offline with a standard crypto library. If our site were compromised tomorrow, that archived certificate would still be verifiable against keys you already have.

Can a vendor edit their certificate?

No. The certificate is signed over its own contents, so any change breaks the signature. A genuine correction goes through an amendment, which produces a new version, re-signs it, retains the superseded version, and records the reason. Authenticity and standing are two separate checks: a withdrawn certificate is still authentically signed, and our verification endpoint reports the signature and the state separately rather than collapsing them into one word.

Do you sell peptides, or take money from brands you test?

No. We own zero retail brands and zero inventory. We are a data-verification laboratory, and the only thing we sell is the analysis.

Are your certificates public?

A released certificate lives at its own public URL and anyone holding the report ID can retrieve and verify it. We deliberately do not publish a browsable directory or a per-brand index, because enumerating one client's whole testing history is that client's decision and not ours. The layout at axiomanalyticslab.com/example-coa is explicitly illustrative, unsigned, and non-verifiable; it is not a laboratory record.

Can I put my certificate on my own product page?

Yes. There is an embeddable widget and a public API, so a certificate can render on your site while still resolving against our servers. That is the point: an image of a certificate hosted by the seller proves nothing, and an embed that resolves to the laboratory does.

Need a person?
Call or text (279) 236-4800, start a site chat, or open a tracked ticket.
← ALL HELP ARTICLES