EVIDENCE REVIEW 26·09·27 Research-peptide vendor recordsArchive snapshot: 27 September 2026 · FDA/A2LA/security pages rechecked: 1 October 2026
Evidence review · Research-peptide commerce
Peptide vendor evidence audit
A dated review of a 160-row vendor register, archived certificate observations, public issuer checks, access records, and regulatory sources. The purpose is to separate what the record directly supports from what remains unverified.
Prepared from the supplied audit HTML and its embedded registerArchive evidence through 27 Sep 2026Public FDA/A2LA/security sources rechecked 1 Oct 2026Standalone HTML5 · no external code libraries
Scope summary: The embedded register contains 160 domain rows. Seventy rows contain follow-up history; two are marked as completed bounded reviews, 68 remain open, and 90 retain legacy numerical scores pending revalidation. These are dataset states, not certifications of businesses, products, sterility, clinical safety, or suitability for human use. [C1][C2]
160
historical domain rows; not a count of distinct legal entities
70
rows with saved follow-up history in the embedded register
2
rows marked as completed bounded reviews
68
follow-up reviews still open
90
legacy numerical scores retained as historical metadata
70
formerly unresolved rows with saved follow-up records
2
completed bounded assessments; 68 follow-up reviews remain open
90
legacy numerical scores awaiting revalidation
0
fully verified vendors in the current checkpoint
Closed 3Offline 20Scored 90Unscored 47
01 / SCOPE
Executive findings
The file is best treated as a dated evidence register, not a vendor ranking or product-safety study. Its strongest claims concern the structure of the embedded dataset and public regulatory records; many certificate-level observations still depend on project-relative source files that are not contained in this standalone HTML.
160 rows
Domains are not companies
The register is organized by domain. A domain row should not be treated as a distinct legal entity unless ownership or continuity is established with primary evidence. Similar names, redirects, and branding overlap are leads to investigate, not proof of common ownership. [C1][C2]
2 complete
Completion does not equal verification
Two rows are marked as completed bounded reviews in the embedded data. For AIO Peptides, public pages show conflicting branding claims and an automated security-reputation report records warnings; ownership, copying direction, and current security status remain unresolved. For Pure Peptide Labs, the embedded audit notes record selected issuer-document matches, but the underlying case package is not included in this standalone file. Neither status establishes product quality, safety, fulfillment, or fraud. [C3][C4][C20]
1,069 vs 1,122
The historical report denominator is unresolved
The internal editorial record cited as C5 says an earlier v3.1 headline used 1,069 certificates. In the embedded register in this file, the row-level legacy_reads values sum to 1,122, including 1,121 among scored rows. Those figures are not a reconciled count of unique analytical reports. [C5]
Legacy ≠ current
Old scores are historical metadata
The 90 legacy scores are internally arithmetically consistent with their stored component values, but that does not revalidate the underlying evidence or make the scores current. They should not be read as present-day measures of authenticity, safety, or vendor quality.
Scope of conclusion. A certificate image, issuer lookup, access error, warning letter, security-provider flag, business-registry entry, or vendor statement answers only the narrow question it directly addresses. None of these evidence types, alone, establishes that a vendor or product is safe, sterile, authentic, lawful in every jurisdiction, or suitable for human use.
02 / REGISTER
Interactive vendor register
The table joins each of the 160 original domain rows to the follow-up history embedded in this file. Legacy scores are reproduced as historical values, not re-endorsed. Identity aliases remain separate unless primary evidence establishes a relationship. [C1][C2][C7]
How to read the expandable notes. The detailed row narratives are archived audit notes. They may contain transcriptions of vendor pages, laboratory reports, browser observations, or prior source checks. Retention in the register does not convert those notes into independently reverified current facts. Where a claim matters to a decision, follow the saved source and confirm the exact lot, report, domain, date, and method.
Loading register… Filter or expand a row to inspect its archived evidence trail.
Domain
Original status
Legacy score
Review state
Archived notes
Source trail
03 / ARCHIVE
What the archive counts mean
File integrity is not document authenticity. Machine-readable text is not the same as a manually reviewed certificate, and a stored “read” value is not a reconciled count of unique analytical reports.
Source boundary. The 1,625/1,624/618/87/919/242 figures below are carried forward from the internal reconciliation record cited as C6. That project-relative reconciliation file is referenced by this HTML but was not included inside the supplied standalone file, so these figures should be treated as internal archive metadata rather than independent external validation.
1,625
Internal file rows
The cited reconciliation record reports 1,625 certificate-file rows and 1,624 unique byte hashes. Even if those counts are correct, a unique hash proves only that stored bytes differ; it does not establish that each file is an authentic, current, correctly attributed certificate. [C6]
618 / 87 / 919
Extraction status
The same internal record reports machine text for 618 PDFs, 87 PDFs awaiting OCR or visual review, and 919 non-PDF files awaiting classification or OCR. These are workflow states, not evidence-quality grades. [C6]
242
Selected examples
The internal reconstruction reports 242 retained examples against 1,122 row-level legacy reads. Selected examples can overlap, duplicate, or represent different renderings of one report; they do not resolve the historical 1,069 headline. [C6]
Original register status (historical labels)
These counts come directly from the embedded 160-row dataset. They describe how rows were labeled in the older register; they are not live business-status findings.
Legacy score distribution (90 scored rows)
The embedded score median is 95. Each stored score equals the sum of its seven stored component values, which confirms arithmetic consistency only.
Older denominators conflict: the internal source map says a separate draft used 256 vendor websites and 3,148 product listings, while this embedded register contains 160 domain rows. Because no reconciled mapping is supplied in this standalone file, those older denominators are not combined with this register. [C8]
Why the legacy score should not be treated as current verification
The 90 stored scores are mathematically reproducible from their component values, but the evidence behind those components has not been revalidated as a complete set.
Five positive-score rows in the embedded dataset have only one or two legacy_reads entries. That does not prove the scores are wrong, but it shows that read counts were not applied uniformly enough to support simple cross-vendor comparisons.
Historical labels such as “offline,” “closed,” and “unscored” are dated register states. An access failure, maintenance page, security gate, or DNS problem should not be converted into a durable claim that a business is closed.
A deep link, laboratory name, QR code, or certificate image is not equivalent to a successful issuer-hosted lookup or an independently controlled sample.
04 / DOCUMENTS
What certificate and laboratory records can establish
A report can support a narrow statement about the sample, fields, method, and results printed on that report. It cannot, by itself, establish the quality of every lot, the contents of a buyer’s vial, current inventory, chain of custody, sterility, clinical safety, or suitability for human use.
What a report-level match can support
An issuer-hosted record exists for a specific identifier or accession.
Selected fields on a vendor copy and issuer copy match for that named record.
A stated analytical result was reported for the described sample and method.
A dated discrepancy can be documented when visible fields do not agree.
These conclusions are record-specific and should not be generalized beyond the named sample.
What it cannot support without more evidence
That the tested sample came from current retail stock.
That the sample was independently purchased or maintained under documented chain of custody.
That testing covered sterility, endotoxin, metals, identity, purity, and content unless those endpoints were actually tested.
That a laboratory’s accreditation covers the exact method used.
That a displayed “Pass” establishes human-use safety.
Item-level source limitation. The embedded vendor register preserves detailed audit notes about report matches, lot-number differences, quantity discrepancies, assay-range issues, unnamed laboratories, incomplete report pages, and failed or successful lookups. The underlying batch files cited as C9–C14 are project-relative and are not included inside this standalone HTML. For that reason, this cleaned version retains those details as attributed archived notes in the expandable register rather than presenting every transcription as an independently reverified publication finding. [C9][C10][C11][C12][C13][C14]
Analytical scope matters. “Purity,” “content,” “identity,” “endotoxin,” “microbial screen,” and “sterility” are not interchangeable endpoints. A reported “Pass” applies only to the stated method, sample, units, detection or quantitation limits, validation range, and acceptance criterion. A vendor’s phrase such as “third-party tested” remains a vendor claim until the exact report, issuing laboratory, and method scope are identified. [C15]
How discrepancies are handled
A mismatch is evidence that two records differ. It is not, by itself, evidence of deliberate falsification, product-wide failure, or intent. Before assigning significance, resolve report identity, lot mapping, units, sampling basis, rounding, method range, acceptance criteria, and whether two documents actually describe the same sample.
05 / REGULATORY
FDA warning letters: scope and date matter
The public FDA pages were rechecked on 1 October 2026. The eight letters below identify the listed firms/domains and named products and state FDA’s findings as of the letter dates. They are primary sources for what FDA communicated, but they should not be expanded into claims about unrelated products, similarly named domains, criminal liability, or a firm’s current compliance status. FDA states that later communications and corrective actions may change the regulatory status of issues described in a warning letter. [C16][C17]
Letter date
Firm / reference
Domain reviewed by FDA
Products named by FDA (brief)
Primary source
2024-12-10
Prime Vitality, Inc. dba Prime PeptidesFDA ref. 695156
Identity-mapping rule: regulatory findings are mapped to the domain and entity named in the source. For example, the letter for milehighcompounds.is is not automatically assigned to milehighcompounds.com, and the Peptide Partners letter for peptide.partners is not automatically assigned to peptidepartners.com. The letters describe products FDA characterized as unapproved new drugs in the circumstances documented by FDA; those findings are not extended here to unrelated products or different domains. [F1][F2][F3][F4][F5][F6][F7][F8]
FDA also issued a separate warning letter to Peak Performance Peptides, ref. 735127, for pppepz.com on 24 August 2026. The embedded register contains a different domain, peakresearch.co; without primary evidence linking those entities, the FDA letter is not assigned to that register row. [F9]
Accreditation is laboratory- and method-specific
A2LA’s directory, rechecked on 1 October 2026, identifies Olympic Analytical, LLC dba Vanguard Laboratory under certificate 6377.01 for ISO/IEC 17025:2017, with an expiration date of 30 September 2027. The published scope lists specified biological tests plus chemical testing for preservatives, trace elements, and residual solvents. Peptide HPLC purity, peptide content, and peptide identity are not listed in that scope. This does not establish that an out-of-scope assay is invalid or that no other accreditation exists; it means this certificate should not be generalized beyond the methods it lists. [C18][C19]
06 / ACCESS & SECURITY
Access failures and security signals are not vendor-quality verdicts
Internal audit notes record account gates, consent gates, HTTP errors, DNS failures, TLS errors, anti-bot pages, indexed-only pages, and security warnings. These observations can explain why a source was unavailable at a particular time. They do not, by themselves, establish fraud, product quality, permanent closure, or global site availability. [C2][C7]
Access observation
An HTTP 403/5xx response, DNS failure, account gate, or security page describes what one route returned in a particular environment and time. It should be recorded with the date and method rather than converted into a durable business-status claim.
Automated reputation signal
Gridinsoft’s public report for aiopeptides.com, dated 6 March 2026, labels the site “Suspicious Shop” and lists four provider warnings, including BitDefender as “Warned,” while many other providers on the same page are shown as clean. Gridinsoft states that its method is automated and that the scan is older than 30 days. This is a dated reputation signal, not an event-level malware analysis or proof of fraud. [C20]
Domain-identity conflict
The public aiopeptides.com page states that it is the only official AIO Peptides website and calls other uses of its branding unaffiliated. Separately, aiopeptidesusa.com uses AIO Peptides branding and links the text “AIO Peptides” to aiopeptidesstore.com. These pages establish conflicting public branding claims; they do not establish which party owns the brand or copied another. [C20]
Accordingly, this report treats security warnings, access states, and branding conflicts as separate evidence classes. None is used as a substitute for analytical testing, business-identity proof, or a legal finding.
Evidence status: unresolved security and domain-identity questions
Public sources support a narrow finding: aiopeptides.com claims to be the only official AIO Peptides site; aiopeptidesusa.com uses the AIO name and links to aiopeptidesstore.com; and Gridinsoft’s dated automated report lists several provider warnings, including BitDefender as “Warned.” Those facts do not establish brand ownership, copying direction, malware activity, product quality, or fraud. The internal audit also records selected Freedom Diagnostics document checks, but the underlying completed-case files are project-relative and are not contained in this standalone HTML. [C3][C20]
The embedded audit notes record three Freedom Diagnostics issuer reports and two vendor-image comparisons with successful lookups for selected records. Because the underlying completed-case files and report images are not included inside this standalone HTML, this publication-ready version does not independently restate the detailed values as verified facts. Even if the recorded matches are accurate, they would not establish current-stock linkage, independent sample custody, comprehensive testing, method-scope accreditation, sterility, clinical safety, or fulfillment reliability. [C4]
“Completed” is an internal workflow state: it means a bounded question was reviewed and remaining unknowns were documented. It does not mean a vendor, product, or lot is fully verified.
08 / METHOD
Evidence hierarchy, attribution, and limits
Evidence categories used
Public primary source Official FDA pages, the A2LA directory and scope, issuer-hosted report services, and official entity records. These support only the entity, date, sample, method, or regulatory statement they directly document.
Internal archive record Project-relative reviews, ledgers, images, hashes, and reconciliation files. These may preserve useful provenance, but an internal note is not independent confirmation of the source it describes.
Automated reputation/security signal Security-provider or reputation-platform output. It can justify further review but does not, by itself, prove fraud, malware, product quality, or business identity.
Access observation HTTP, DNS, TLS, anti-bot, login, consent, or indexed-content results recorded with a date and environment. These are access states, not vendor-quality conclusions.
Counter-review questions
Does the cited source directly observe the claim being made?
Is the source independent, or is it a vendor copy of the same underlying report?
Does the report identify the sample, lot, method, units, limits, and acceptance criteria needed to interpret the result?
Is the tested sample linked to current stock through a documented chain?
Could a mismatch reflect lot mapping, date fields, units, rounding, sampling, or method range rather than intentional misstatement?
Was the exact domain or legal entity reviewed, or is an alias being inferred?
Is a regulatory or security record being described as of its actual date rather than as a timeless status?
Confidence: highest for counts directly reproducible from the embedded dataset and public primary sources rechecked for this edition; lower for internal report transcriptions whose underlying project files are not included in the standalone HTML; unknown for current stock, fulfillment, independent chain of custody, and unproven business aliases.
Sampling was not random. The archived report set was assembled through public availability, library navigation, indexed leads, issuer searches, and targeted follow-up questions. It cannot be used to estimate the prevalence of compliant, noncompliant, authentic, counterfeit, sterile, or unsafe products across the market.
What this paper does not establish
It does not certify vendors or products, infer safety for human use, establish GMP compliance or FDA approval, determine whether a particular vial is sterile, estimate fraud prevalence, predict delivery, recommend a vendor, or provide medical advice. A laboratory report can characterize the sample and method described on that report; it cannot substitute for clinical evidence or a controlled supply-chain audit.
09 / NEXT EVIDENCE
What remains before stronger vendor-level verification
The next useful work is source-level revalidation: resolve exact entities, exact reports, exact methods, and lot-to-stock linkage. Missing evidence should remain missing evidence rather than being converted into either reassurance or suspicion.
Priority 1
Revalidate legacy scores
Recheck the 90 scored rows against original source records. Record report identifiers, issuer-hosted lookup outcomes, source type, observation date, and the rule used for each component. Do not treat an old numerical score as a current vendor conclusion.
Priority 2
Reconcile report identity
Resolve the 1,069-versus-1,122 discrepancy at the accession/report/sample level, not by file count alone. Distinguish unique reports from vendor copies, issuer copies, screenshots, QR images, and duplicate renderings. [C5][C6]
Priority 3
Map exact entities and regulatory lifecycle
Use legal names, exact domains, and primary registry records. For FDA warning letters, check for later responses or close-out records and preserve the date of the agency’s finding. Do not assign a letter to a similarly named domain without evidence linking the entities. [C16][C17]
Priority 4
Establish lot-to-stock linkage
For each selected analytical report, record issuer, client, accession, dates, product, printed lot, sample count, method, units, results, uncertainty or validated range where stated, and a dated source showing whether that lot maps to current stock.
Priority 5
Verify laboratory scope method by method
Capture the active accreditor certificate and full scope, then map each claimed identity, purity, content, sterility, endotoxin, or metals assay to the exact listed method. Accreditation in one field does not automatically cover every assay offered by a laboratory. [C18][C19]
Priority 6
Refresh access and security observations
Preserve date-stamped screenshots or event exports for warnings, record the product/version that produced them, and recheck ordinary access without bypassing security controls. Keep automated reputation scores separate from direct security analysis.
Publication scope: this document is suitable only as a dated evidence audit and source navigator. It is not a peer-reviewed market study, a prevalence estimate, a vendor ranking, a product-safety assessment, or a clinical-use guide. Stronger vendor-level conclusions require the missing source archive to be published or independently rechecked at the report and entity level.
10 / SOURCE REGISTER
References and archive map
External primary sources are linked directly. Internal sources C1–C14 and parts of C19 resolve relative to the original project folder and are not embedded in this standalone HTML. If this file is published by itself, those local links will not allow an outside reader to reproduce the underlying certificate-level review.
C1 Original v3.1 report and embedded 160-row register. Local snapshot: open original HTML; row data: original-rows.json. Internal archive; not independent evidence.
C2 Batches 01–06 continuation findings and checkpoint. Resume handoff; source notes are linked from each vendor row. Internal AI-assisted research notes; use preserved originals where available.
C3 AIO Peptides bounded review. Full report · structured file · user warning captured in case notes. The Bitdefender message is first-party reported, not an event export.
C5 Editorial findings on v3.1 totals, scores, read counts, and missing pipeline inputs. Open editorial audit. Internal analysis, dated 23 September 2026.
C6 Archive reconciliation. Open structured reconciliation. Hash counts and extraction-status inventory; does not certify the file contents.
C7 Local evidence manifest and original status register. Manifest; local audit; HTTP archive. Retrieval metadata is not a business or quality verdict.
C8 Earlier alternative draft, “The Peptide Paper Trail.” Open draft in this reports folder. Its 256/3,148 claims are retained for discrepancy review and not adopted as this paper’s denominator.
C15 Freedom Diagnostics issuer report service. Official issuer domain. Issuer publication of a sample record does not prove lab accreditation, chain of custody, or product safety.
C16 Eight FDA warning letters. Individual primary-source links F1–F8 in the table and below. Domain mapping in each letter is preserved exactly; conclusions are limited to each dated letter.
F1 FDA, Prime Vitality, Inc. dba Prime Peptides warning letter 695156 (2024-12-10). Domain under FDA review: primepeptides.co; scope: Semaglutide; retatrutide. Official FDA letter ↗
F2 FDA, Swisschems warning letter 695663 (2024-12-10). Domain under FDA review: swisschems.is; scope: Semaglutide; retatrutide. Official FDA letter ↗
F3 FDA, Mile High Compounds LLC warning letter 721600 (2026-03-31). Domain under FDA review: milehighcompounds.is; scope: GLP-1 SM, GLP-2 TRZ, GLP-3 RT; BAC water. Official FDA letter ↗
F4 FDA, Gram Peptides warning letter 721806 (2026-03-31). Domain under FDA review: grampeptides.com; scope: Retatrutide; tirzepatide; bacteriostatic water. Official FDA letter ↗
F5 FDA, Wholesale Peptide warning letter 729447 (2026-06-17). Domain under FDA review: wholesalepeptide.com; scope: Prostamax; gonadorelin. Official FDA letter ↗
F6 FDA, Royal Peptides LLC warning letter 734884 (2026-08-24). Domain under FDA review: royal-peptides.com; scope: Tirzepatide; semaglutide; retatrutide; SS-31; PT-141; tesamorelin; BIMORELIN. Official FDA letter ↗
F7 FDA, NuScience Peptides LLC warning letter 733652 (2026-08-24). Domain under FDA review: nusciencepeptides.com; scope: GLP products; survodutide; mazdutide; PT-141; tesamorelin; blend; BAC water. Official FDA letter ↗
F8 FDA, Peptide Partners LLC warning letter 735063 (2026-08-24). Domain under FDA review: peptide.partners; scope: GLP products; SS-31; tesamorelin; PT-141; reconstitution solution. Official FDA letter ↗
F9 FDA, Peak Performance Peptides warning letter 735127 (2026-08-24), concerning pppepz.com. Official FDA letter ↗. Not mapped to the register’s peakresearch.co row without entity-linkage evidence.
Citation policy: internal audit notes preserve provenance but are not independent confirmation of the sources they summarize. Public regulatory and accreditation claims are linked to primary sources. Vendor statements, search-index snippets, access failures, and automated reputation outputs remain explicitly attributed and are not promoted to proof of product quality, fraud, or safety.