How to read a peptide COA — and how to spot a fake one.
A certificate of analysis (COA) is supposed to be the document that lets you trust a vial without trusting the person who sold it to you. In practice, most peptide COAs are just PDFs — and a PDF is easy to edit, easy to reuse for a batch it was never run on, and easy to fake outright. This guide is how to read one properly, and how to tell a real result from a forged one.
We're an independent third-party peptide testing lab, and we issue COAs for a living, so a caveat up front: we have an interest in you taking certificates seriously. We've tried to write this so it's useful even if you never send us a thing.
What a COA actually is
A COA is a lab's written report of what it measured on a specific sample. A good peptide COA answers four questions: What is it? How pure is it? How much of it is there? And who says so — verifiably? Everything below is about reading those answers and checking whether you can believe them.
The three numbers that matter
Identity. Does the certificate confirm the compound is what the label claims, and how? The credible way to establish identity is by comparing the sample against a certified reference standard for that exact peptide — matching retention time and UV spectrum (or, at some labs, mass). “Identity: confirmed” with no reference to a standard is a claim, not evidence.
Chromatographic purity (%). This is the area-percent of the target peak versus everything else the analysis resolved — the “how pure” figure. Watch for a purity number with no chromatogram, no method, and no wavelength behind it. Purity of what, measured how?
Net-peptide assay / content (mg per vial). This is how many milligrams of actual peptide are in the vial. It is not the same as purity, and this is the single most common gap on peptide COAs. A vial can read 99% pure and still be significantly underfilled — because purity describes the quality of what's there, and assay describes the quantity. If a COA gives you a purity percentage but never tells you the milligrams, it has answered half the question. (More on that distinction in purity vs. net-peptide content.)
The red flags of a fake or misleading COA
- No verification method, and no way to check it. If you can't independently confirm the lab issued the document and that it hasn't been altered, the COA is only as trustworthy as whoever emailed it to you.
- A purity number with no chromatogram or method context. Real results come from a real run. A bare “99.2%” floating on a page with no trace behind it is unfalsifiable.
- Purity but no milligram assay. Sometimes an honest gap, sometimes a convenient omission — either way, it leaves the underfill question open.
- Identity “confirmed” with no reference standard named. Confirmed against what?
- A mismatched or missing batch/lot number. The COA should tie to a specific batch. A certificate that doesn't name a batch — or names one that doesn't match your vial — is a certificate for someone else's material, at best.
- Reused COAs. One genuine certificate photocopied across an entire product line. The document might be real; it just wasn't run on your vial.
- Capabilities that don't add up. Be skeptical of a single certificate claiming a stack of unrelated tests — mass spec, sterility, endotoxin, heavy metals, residual solvents — with no method detail. Labs are honest about their scope; a COA that quietly implies it can do everything usually can't.
- Edited PDFs. A number changed after the fact — a purity bumped up, a milligram figure inflated. Without a way to detect tampering, you'd never know.
How a verifiable COA closes the gap
Most of the red flags above come down to one weakness: an ordinary PDF can't prove it's genuine or unaltered. That's the problem a verifiable certificate solves.
Every COA KMD issues carries a unique QR code and a SHA-256 hash — a cryptographic fingerprint of the exact PDF. Anyone can take the certificate to our verifier, and the check confirms two independent things: that KMD issued it, and that not one character has changed since we did. Alter a single digit of a purity result or a milligram figure and the fingerprint no longer matches — the tampering is detectable, not hidden. A QR code that merely links to “yes, this is real” proves the certificate exists; a hash proves this exact file wasn't touched. Those are different guarantees, and the second is the one that catches an edited number.
You don't need to take our word for the honesty of a KMD certificate. You can check it — and so can whoever you forward it to.
A quick checklist before you trust a COA
- Does it name the compound and the batch/lot, and does that match your vial?
- Is identity established against a named reference standard?
- Is there a purity percentage with a method behind it (technique and wavelength)?
- Is there a net-peptide milligram figure, not just a purity percentage?
- Is the lab independent of whoever sold you the vial?
- Can you verify the certificate is genuine and unaltered — or are you just trusting the sender?
If a COA can't clear that list, it isn't necessarily fake — but it hasn't earned your trust yet.
About KMD Analytical
We're an independent, third-party peptide testing lab in Chatsworth, California. We test peptides for identity, chromatographic purity, and net-peptide assay (mg/vial) by RP-HPLC-UV, and we issue SHA-256-verifiable COAs. We don't sell peptides, we're transparent about our scope — RP-HPLC-UV, not LC-MS or sterility testing — and every certificate we write can be checked by anyone. That's peptide testing you can verify.