Can I trust the record?
A spreadsheet can be corrected after the fact, and often is, for good reasons. But that also means a failed control could be quietly softened, and nothing in the file shows it. The record cannot vouch for itself.
Home / Resources / Provable QC
Quality & governance · Inspection readiness
At inspection, "trust me, the QC was fine" is not evidence. This guide explains how tamper-evident QC receipts let an assessor confirm your quality trail is intact, offline, with no login and no need to trust us.
Published 20 July 2026 · Last reviewed: July 2026 · 7 min read
An assessor's job is to distrust your word and check the evidence. If your quality-control history is a spreadsheet you maintain and a system you control, then "the QC passed" is an assertion, not proof. The problem is not bad faith. It is that a record which can be edited without a trace cannot, on its own, show that it was not edited. Provable QC closes that gap: it lets an independent person confirm that the QC evidence you present is exactly the evidence that was captured, unchanged.
This guide covers the ordinary QC work first (capturing controls, charting them, checking the rules, locking out a device that fails), then the part that makes the evidence stand up to scrutiny: a tamper-evident receipt on every record that anyone can verify for themselves.
The problem
Three things an assessor asks that a hand-kept QC log struggles to answer.
A spreadsheet can be corrected after the fact, and often is, for good reasons. But that also means a failed control could be quietly softened, and nothing in the file shows it. The record cannot vouch for itself.
Accreditation expects each control result tied to a named operator, a device and a timestamp. Typed logs lose that chain: a row of numbers rarely proves who entered them or whether the date is the date the control was actually run.
"It was in range" begs the question: which range, which rules, decided when? Evidence that the correct evaluation ran at the time of the control, not reconstructed for the visit, is what turns a number into a defensible decision.
Before any of the verification story matters, the routine has to be right. Catenix captures quality control the same way it captures patient results: electronically, from the analyser, at the moment the control is run. There is no separate spreadsheet to keep and nothing to re-type, which removes the most common source of a missing or mistyped QC entry. Our guide to QC software for point-of-care devices covers the day-to-day workflow in depth; here is what sits underneath the receipts.
This is statistical data-quality monitoring and process control. It is not interpretation of any patient result, which stays with the clinician and the analyser's instructions for use. For the statistics behind the rules, see our field guide to Levey-Jennings charts and Westgard rules.
The idea
The step that turns a QC log into evidence: every record carries proof that it has not changed since it was written.
When Catenix records a QC run, it also writes a small tamper-evident receipt alongside it, using standard public-key cryptography. Think of the receipt as a seal over the record: the control values, the operator, the device, the timestamp and the rule outcome. If any of those change later, even by a single digit, the seal no longer matches, and an independent check will say so.
The important word is independent. The receipt can be verified by a tool that has nothing to do with Catenix and never contacts us, so the maths, not the vendor, does the vouching. That is what separates it from an audit log inside a system, which an assessor still has to trust the vendor about.
There are two ways an assessor or a lab manager can check a record, and both work without a Catenix account:
In both cases the answer is a straightforward yes or no: this record is the record that was captured, or it has been altered. No login, no trust in us required.
Two honest limits. First, this is tamper-evident, not tamper-proof: it makes any change to a stored record detectable, rather than making change impossible, and we do not claim that fraud is impossible. Second, it proves the integrity of the QC record and the rule evaluation that ran, not the clinical correctness of any patient result. It shows that your process trail is intact, which is precisely what an assessor needs to see.
How verification runs
ISO 15189:2022, the standard for medical laboratory quality and competence, expects a laboratory to run quality control appropriate to its methods, to keep records of that control, and to be able to show those records are reliable and traceable. Provable QC is built to sit comfortably against those expectations, without claiming to grant accreditation, which no software can do.
Catenix produces and preserves this evidence. It does not interpret clinical results and provides no clinical decision support: it does not re-calculate values, re-classify results, derive estimated quantities, or auto-flag. Interpretation, validation and authorisation stay with your clinicians, exactly where accreditation expects them.
Verifiable QC receipts are one instance of a pattern that runs through the platform. The same tamper-evident approach underpins the audit trail (every login, edit, review and report release recorded against the authenticated actor) and the signed completeness manifest that ships with released reports. The result is a quality story an assessor can follow from a single control run all the way to a signed report, with each link checkable. To see how the quality and governance layer holds together, read the quality and governance overview or the security and trust approach behind it.
Questions, answered
Provable QC means your quality-control evidence can be checked by someone who does not trust the system that produced it. Each QC record carries a tamper-evident receipt: an assessor or lab manager can confirm the record has not been altered since it was written, without logging in and without taking Catenix's word for it. It is a way to show your QC held, rather than simply asserting that it did.
They drag the exported file into a verification page in a web browser, or run a small offline checker. Either tool re-computes the receipt using standard public-key cryptography and reports whether the record is intact and unchanged. No account, no connection to Catenix and no trust in Catenix is required, because the check runs entirely on the assessor's own device.
No. It proves that the QC record you present is the record that was captured, unaltered, and shows the rule evaluation that was applied at the time. It is evidence of an intact process trail, not a judgement about any patient result. Interpretation, validation and authorisation of clinical results stay with your clinicians.
We describe it as tamper-evident and independently verifiable, not tamper-proof. The point is that any change to a stored QC record is detectable by an independent check, so an altered record cannot quietly pass as genuine. It is designed to make quality evidence trustworthy to an outsider, not to make change impossible.
Bring your analyser list. We'll show a control run, rule-checked and independently verifiable, live.