No black boxes. Full transparency.
Every check ScriptSafe runs, every finding tier, and every decision point. Documented here for processors, acquirers, and anyone who needs to understand what accreditation actually means.
What ScriptSafe verifies
Licensure and Registration
- State pharmacy license, active, not expired, not suspended
- DEA registration, active, schedule authorizations verified
- State board of pharmacy standing, no pending disciplinary actions
- Pharmacist-in-charge license, active and matching state of operation
- NPI registration, valid and matching pharmacy identity
- NCPDP registration, verified
- State controlled substance registration (where applicable)
- Multi-state license cross-check for mail-order operations
Website and Digital Presence
- Prescription requirement: site must require a valid prescription for all Rx products
- No OTC-to-Rx substitution language or implied workarounds
- No controlled substance advertising without appropriate context
- Physical address displayed and verifiable
- Licensed pharmacist contact information present
- No prohibited product categories
- Privacy policy present and compliant
- Terms of service present
- SSL certificate valid and properly configured
- No deceptive pricing or bait-and-switch language
- No misleading health claims
- Domain registration age and history review
- WHOIS data consistency check
Compounding (503A and 503B)
- State compounding license, active
- 503B outsourcing facility registration with FDA (if applicable)
- No bulk substance advertising to the general public
- No patient-specific compounding claims that imply mass production
- PCAB accreditation cross-reference (if claimed)
- Compounding-specific website language review
- No advertising of compounded products as FDA-approved
Identity and Corporate
- Business entity registration, active in state of operation
- DBA registration (if applicable)
- Physical address verification, not a P.O. box or virtual office
- Phone number verification, active, answered
- Prior enforcement history: FDA warning letters, DEA actions, state board actions
- Litigation history review
Payment and Compliance History
- Prior merchant account terminations (MATCH list cross-reference)
- Chargeback history indicators
- Prior processor compliance flags
- Prior accreditation denials or revocations (ScriptSafe internal)
How findings are classified
Every finding carries a severity, a deadline, and a consequence. The same ladder applies whether a finding surfaces at accreditation or during continuous monitoring.
A low-severity issue, such as an approaching license renewal or a small website copy change. Documented, tracked, and given a short window to resolve.
A material change worth a closer look, such as prescription-requirement language being removed. The pharmacy is asked to remediate before the window closes.
A serious compliance failure, such as a lapsed state license or a filed disciplinary action. Accreditation is suspended if it is not resolved in time.
A disqualifying failure, such as a lapsed DEA registration or a confirmed sale of controlled substances without a valid prescription. Accreditation is revoked.
Every decision is documented
ScriptSafe maintains a complete audit trail for every accreditation decision: what was checked, when it was checked, what was found, and what action was taken.
Processors and acquirers can request the full compliance package for any accredited pharmacy, which includes a summary of all checks performed and findings at the time of accreditation.
What we publish, and what we hold back
Transparency for the people who must trust the accreditation. Discretion for the details a bad actor could tune around. Three tiers, one principle.
The framework
This page and How It Works: what we check, how findings are classified, the evidence model, and aggregate results. Public, free, and no account required.
The full document
A deeper, formal methodology for vetted processors, acquirers, and platforms. Issued as a tracked, watermarked copy after we confirm the requester.
The detection internals
Keyword dictionaries, model prompts, exact thresholds, and per-source implementation stay private, so non-compliant operators cannot tune around our detection. Withholding them protects you, not us.
Available to vetted processors, acquirers, and platforms. Each copy is issued as a tracked, watermarked document.
Questions about the methodology?
Our team is available to answer detailed questions from processors, acquirers, and platforms evaluating ScriptSafe.