The unit of trust is the bag.
Not the lot or the shipment, but the specific bag a grower is holding. Every bag that leaves our facility gets its own record in IPAC, its own unguessable token, and its own printed code. Scan it three years later and it still resolves.
No login. No app. A phone in a field.
The code opens a public verification page. It works for the grower who bought the bag, the buyer deciding whether to stock it, and the inspector asking how we know.
- What's in the bag
- Product, formulation, lot number, and production date.
- Where it came from
- Origin, processing plant, the supplier who provided the input material, and that supplier’s approval status.
- Proof it meets spec
- The certificate of analysis for that lot, with pass or fail against the product specification and any out-of-spec field called out by name.
- Certifications
- Organic or whichever regime applies, with issuing body and validity dates.
- Chain integrity
- Confirmation that none of the underlying documents changed since upload.
Every scan is logged. We see which bags get verified, where, and when.
Claims you can check yourself.
Anyone can print a claim on a bag. The difference between a tracking system and a trust system is whether the claim can be tested by the person reading it.
- Certificate of analysis
- Previous
- 0000…genesis
- This entry
- a41f…9c02
- Supplier certification
- Previous
- a41f…9c02
- This entry
- 7be3…14da
- Altered document
- Previous
- 7be3…14da
- This entry
- f09c…22b7
Nobody can quietly backdate a lab result or swap a certificate, including us. That constraint is deliberate.
Where the bag has been, and who had it.
Each bag carries a custody trail: who held it, when it transferred, where it was scanned. Status moves through production, in transit, and delivered, with every transition timestamped and attributed. If a bag turns up somewhere it shouldn't be, the trail shows where it diverged.
Scan location gives us two things past compliance. Diversion shows up when product appears in territory it was never sold into. And we get real distribution visibility, based on where bags actually end up instead of where they were invoiced.
Minutes, not weeks.
This is where per-bag identity pays for itself. Whether it starts with a contamination signal, a failed retest, or a customer complaint, the question runs in both directions.
Start with a bad lot
Every bag from it, where each one went, and who to call.
Start with one complaint and one bag
The lot, the input supplier, the production run, and every sibling bag at risk.
The recall is scoped to the bags actually affected instead of everything that left the building that month. At our size, pulling 400 bags is an incident. Pulling a month of production would end the company.
A photocopied label gives itself away.
Each code is unique and unguessable. A fabricated one doesn't resolve at all. A copied one scans repeatedly from scattered locations, which is a pattern IPAC surfaces on its own. By the time this brand is worth imitating, the check is already in place.
What we run day to day.
An admin interface for recording production runs and printing label batches, uploading certificates of analysis and supplier certifications, managing the approved supplier list, and watching scan activity and custody status. Suppliers get portal access to upload their own certificates, so compliance paperwork stops arriving as email attachments.
Starting per-bag while we're small is what makes it affordable. The identity model, the label, and the verification page are the same at five thousand bags and five million; only the print volume changes. Retrofitting bag-level identity onto years of lot-level records is the expensive version of this project. Doing it now costs almost nothing.
Ask us to walk you through it