Built on proof, traced to its source.
We do not ask processors to take our word for it. Every ScriptSafe accreditation is built on primary-source verification, AI-assisted analysis, and continuous monitoring, with a complete evidence trail behind every decision.
Verified against the source, not self-reported
Every claim is checked against the authority that issued it. A pharmacy telling us it is licensed is not evidence. The state board confirming it is.
Licensure and registration
- State pharmacy license status, verified against the issuing board
- DEA registration, active with schedule authorizations confirmed
- Board disciplinary standing across all 50 states
- NPI identity matched through the NPPES registry
Sanctions and exclusions
- OIG List of Excluded Individuals and Entities
- SAM.gov federal exclusion records
- OFAC, EU, UK and UN sanctions screening
Enforcement and litigation
- FDA enforcement actions, warning letters and recalls
- Federal court dockets through the PACER record system
Physical location
- Address geocoded and confirmed to a real storefront
- Storefront, satellite and street-level imagery in the compliance package
- Flags P.O. boxes and virtual offices
Documents
- 47 fields extracted and validated across 8 document types
- Expiration and effective dates checked
- Cross-document consistency on name, address and ownership
Domain and infrastructure
- WHOIS and RDAP registrant and registrar tracking
- DNS record monitoring for silent redirection
- SSL certificate validity and issuer continuity
Candidate to verified
No raw match supports an accreditation decision on its own. A hit in any source begins as a candidate; only after it is confirmed against the issuing authority does it count toward a decision. The gate is the difference between a name collision and a fact.
AI does the work humans cannot do at scale. Humans stay accountable.
No company can review every page of every pharmacy site, in two languages, on a continuous cadence, by hand. Our deterministic layers scan every page we fetch; Anthropic's Claude models then judge the pages they flag and the content that has changed. What makes this defensible is not the model. It is that the machine-checkable facts come first, a human confirms the consequential calls, and every judgment is logged.
Classification
Classifies the pages our deterministic layers flag as legitimate, bypass, or concerning, with its reasoning recorded, in English and Spanish.
Synthesis
Combines licensure, documents, web content and domain signals into a single internal recommendation.
Human confirmation
High-risk categories and every early-stage decision require a person. The model recommends; a human decides.
Every model call is captured with its model version, prompt version, and a frozen snapshot of its inputs. Any AI judgment can be re-run and reviewed later. An AI decision here is reviewable evidence, not a guess you are asked to trust.
The model never overrides a failed primary-source check. License status, DEA registration, sanctions and exclusions are machine-checkable facts. AI interprets the gray areas; it does not get a vote on the black-and-white ones.
Accreditation is the start, not the finish
A pharmacy that is clean on approval day can change the next week. We watch for that, continuously, and we measure change from a baseline we control.
The tri-check baseline
3 baselines × 4 layersLocked at the moment of accreditation. It never changes, so drift is always measured from a known-clean state.
The last reviewer-approved clean state. It advances only through human review, never automatically.
Today's capture of the site, compared against both baselines on every scan.
Three baselines across four layers produce twelve independent drift signals on every scan. The system then classifies the pattern: legitimate evolution, a sudden material change, or slow drift accumulating in small steps. Drift is never read as guilt; it is read as a reason to look closer.
The detection pipeline
Every layer runs in English and Spanish. The specific dictionaries, prompts and thresholds stay private, so that a bad actor cannot tune around them.
Cadence scales with record
The stronger the standing, the lighter the touch. The more concerning the signals, the closer the watch. When a site blocks our crawler or a source is down, we record a coverage gap rather than silently pass it. We tell you when we cannot see, instead of guessing.
We hold ourselves to the standard we hold pharmacies to.
An accreditation is only as trustworthy as the operation behind it. So we instrument our own platform the way we monitor pharmacies, and we publish what we find.
Reviewed before it ships
Platform code is reviewed by multiple independent AI systems, Anthropic Claude and OpenAI, alongside human engineers. This is how we build the platform; it is kept separate from the accreditation decision itself.
We instrument ourselves
Every monitored pharmacy carries a four-part Signal Health heartbeat: crawler coverage, compliance checks, state-board surveillance, and observability validation. These roll up into a portfolio monitoring-uptime metric, kept deliberately separate from the Trust Score.
We publish the numbers
Time-to-detection, time-to-remediation, coverage and freshness, and how often we had already caught an issue before anyone outside ScriptSafe raised it.
Findings have teeth, and a paper trail
Every finding carries a severity, a deadline, and a consequence. Pharmacies can contest one, and every step is recorded.
A license renewal approaching, or a small copy change flagged for review.
A material website change, such as prescription-requirement language being removed.
A state license lapsed, or a disciplinary action filed against the pharmacy.
DEA registration lapsed, or a confirmed sale of controlled substances without a valid prescription.
Disputes pause the clock
A pharmacy can contest any finding. The SLA clock pauses, a reviewer issues a determination, uphold, re-tier, or dismiss, and every message and decision is timestamped and permanent. Fairness is built into the workflow, not granted by exception.
The receipt chain
Any accreditation status resolves back to the evidence behind it. A processor can trace a decision down to the source.
Everything above, synthesized into one internal decision.
The Trust Score is our internal synthesis of all 152 checks across five weighted components. It lets us clear clean applications quickly while holding rigor for the complex ones.
What you and your processor see is binary: accredited or not. The score itself stays internal, so a single number can never misrepresent a pharmacy. Processors also receive the full compliance package and a direct line for any question.
- Document validity Pass
- Deterministic verification checks Pass
- Website compliance Pass
- Cross-document consistency Pass
- Business-profile fit Pass
Evaluating ScriptSafe accreditation?
Verify any accredited pharmacy in seconds, or read the full methodology behind every decision. Our team is available for processor and underwriting questions.