Underwriting · V-track · 31 July 2026

Supplier Recall Lookup for Injectable Kit Assemblers

Small medical kit assemblers and packagers who source pre-filled injectables have no fast way to check whether a supplier or lot has a history of FDA recalls or quality actions before building it into a kit. They find out only after a recall forces a costly teardown and reissue. The minimum fix is a self-serve search tool that lets someone type a supplier name, NDC, or lot number and see aggregated FDA recall and enf…

42 ± 3.1 WATCH
REWORK
PROVE
BUILD
rubric w3.0-20260804 · interval ±3.1 at 95% (n=10, sd=1.6, measured 2026-08-04)
Stages run112
Cost to produce$0.00
Wall clock74 min
Confidence76/100

What an analysis cost to produce belongs beside it. A reader deciding whether to trust a verdict is entitled to know whether it came from twenty-six stages or one, and nothing else in this category will tell them.

every charge, every rebuttal, every ruling

The case against it

ChargeRebuttalRuling
Free functional substitutes already solve the exact stated queryCONCEDED — Conceded. The record itself lists NDC List, FDA.report, and FDA.gov enforcement dashboard as free tools with 'partial overlap' pulling from the same oupheld — FDA.report, NDC List and FDA's own enforcement dashboard already accept firm name/NDC/lot and return recall history in seconds from the same openFDA source — the marginal value of a paid wra
Task frequency too low to sustain a subscriptionCONCEDED — Conceded. Nothing in the record addresses check frequency, usage cadence, or retention data. The thesis describes a one-time pre-commit gate ('before partial — Fatal to the $39/mo SaaS framing, irrelevant to the $49-per-report concierge offer, which is priced correctly for an episodic pre-commit gate.
Addressable buyer population is uncountable and likely smaller than statedCONCEDED — Conceded. The buyer_population field explicitly labels its own count as 'inferred' with 'no direct FDA registry filter for injectable kit assembler asupheld — The record self-labels 85 as an inferred mid-point across overlapping directories with no FDA role filter; a pool that may be 15-40 qualified firms cannot support the 100-buyer reachability
Wrong buyer targeted — searcher has no purchasing authorityCONCEDED — Conceded. No role, title, or purchasing-authority data for the searcher is given anywhere in the record. The charges/channels sections reference 'packpartial — A $49 one-off on a personal card routes around procurement, but no title, budget line, or expense-authority evidence exists anywhere in the record for the QA tech who would actually search.
False-negative liability destroys trust irreparably after first missCONCEDED — Conceded. No data in the record on parser accuracy, false-negative rate, or ingestion lag exists to rebut this. The candidate's own data_moat section partial — Product bugs are baseline, but issuing a written 'clear' verdict on a lot in an FDA-regulated assembly chain converts an ordinary bug into a reputational and quasi-liability event inside an
Maintenance burden scales with usage, breaking low-touch economicsCONCEDED — Conceded. No founder-hour cost model, support-ticket volume, or automation plan is present in the record to counter the claim that heuristic lot-parsidismissed — Ordinary regex/parser maintenance is baseline for every data-wrapper business, and the tested MVP is manual concierge with no parser at all — this cost does not exist until the product is au
Buyer doesn't know they have this problem until after the damage is doneCONCEDED — Conceded outright — the thesis itself states the exact behavior the charge describes.upheld — The thesis itself concedes buyers only learn post-recall; selling a workflow step that nobody currently performs is evangelism, not demand capture, and evangelism is the slowest sale a solo
Channel costs exceed lifetime value given tiny TAM and low priceCONCEDED — Conceded. The channels field's own cost figures ($1k-4k per lead cycle) against an 85-firm TAM and the low implied price point are internally consistepartial — Healthpack/PDA/CPA at $1–4k per cycle are indefensible against a $39/mo price and should be discarded, but named-list cold outreach costs ~$0 cash, so the charge kills the plan's channels, n

A separate agent argued against this idea, a second answered, a third ruled. 8 of 8 charges were conceded rather than defended. Published in full because a score with the objections removed is a advertisement, and because the objections are usually more useful than the verdict.

dimension by dimension

How it scored

DimensionScoreReasoning
D138A recall teardown is genuinely expensive, but the pain is rare, retrospective, and the pre-commit check is not currently in anyone's SOP — acute in hindsight, dormant at
D242Real money exists for FDA quality intelligence at the enterprise tier (Redica ~$50k, Atlas ~$30–80k named-user), but zero evidence anyone has ever paid anything for this
D336Buyers are nameable via ThomasNet/Qmed/KokoQuest and phoneable for free, which is real, but the enumerable qualified pool is likely 20–60 firms — you cannot get in front
D410Pure wrapper on a public federal feed already wrapped by two free competitors and the regulator itself; nothing accumulates from ingestion.
D585Two days to a landing page, Stripe link, and manual openFDA cross-check — the operator's stack does this with no new infrastructure and ~$0 cash.
D638$39/mo subscription is mismatched to episodic use with a self-declared 10% monthly churn; the $49 per-report transaction fits the behavior but produces no recurring reven
D715Even at 100% penetration of the stated 85 firms at $39/mo the ceiling is roughly $40k/yr gross, and the honest pool is smaller than that.
D852openFDA plumbing, Postgres search, and a Stripe page are squarely in his wheelbase; zero standing or credibility in FDA-regulated parenteral packaging where a written cle
D945The concierge report is sellable in 2 days of build, but cold-calling QA staff at regulated shops with no referral realistically lands the first $49 nearer 30–45 days tha
named, priced, and dated

Who already does this

CompetitorPricingFundingLaunchedOverlap
NDC List – Drug Recalls LookupFreeNot disclosed / appears bootstrapped content sNot disclosedpartial
FDA.reportFree (public database aggregator)Not disclosedNot disclosedpartial
FDA Enforcement Report / Data Dashboard (official)FreeN/A (government)Ongoing since ~2012 (dashbpartial
Atlas (Atlas Compliance)Named-user annual subscription, undisclosed exact figure — pNot disclosedRecent entrant (content daadjacent
Redica Systems (the 'incumbent' Atlas undercuts)Enterprise, not disclosed in resultsNot disclosedNot disclosedadjacent
The Orange Report (FDA Quality and Regulatory Consultants / Solar Compliance)Subscription, price not disclosedNot disclosed2019partial
Qualityze QMS (representative of general medical device QMS suites)Enterprise/quote-based, requires implementationNot disclosedNot disclosedadjacent
PharmData (UK)Subscription (community pharmacy tool)Not disclosedNot disclosedadjacent

Where the buyers actually are

ChannelWhy it reaches them
Manual outreach to named ThomasNet/Qmed/KokoQuest-listed kit assembler
thePACKout / Healthpack annual conference (healthcare packaging)
PDA (Parenteral Drug Association) meetings/newsletter
CPA (Contract Packaging Assoc.) Associate membership + RFQ directory
"[supplier name] FDA recall" / NDC lookup search queries
what stands in the way

Regulatory gates

GateFinding
G1Aggregating and displaying publicly available FDA recall and enforcement data via search interface has no identified legal violation. Not practicing medicine, not making claims, not storing
G2Search tool runs autonomously. No per-customer service, no sales calls, no physical work, no human review of outputs required. Data refresh and indexing can be automated. Zero structural man
G3Regulatory compliance and supplier quality verification is a paid category. Competitors exist: Veeva Vault, MasterControl, TraceLink all charge for supply chain compliance and recall managem
G4Thin MVP: scrape/ingest FDA OpenData (Enforcement, Recalls, Adverse Events), index by supplier name and NDC, build search UI in React, store in Postgres. No novel research, no heavy infrastr
G5Medical device kit assemblers and packagers are reachable: LinkedIn, industry directories (RAPS, AAMI), trade shows (MD&M, BioProcess), regulatory affairs forums, device manufacturer supply
written before the outcome is known

The pre-registered test

TermValue
days14
offerOne-page 'Supplier & Lot Recall Clearance Report': you email a supplier name, NDC, or lot number; within 24 hours you get a PDF verdict (CLEAR / FLAGGED / INCONCLUSIVE) with every matching FDA drug and device enforcement
price99
metricCompleted Stripe payments at $99 from firms with no prior relationship to the operator
channelDirect cold email + phone to 60 named US medical contract packagers / kit assemblers pulled by hand from ThomasNet, Qmed and KokoQuest medical-packaging directories, addressed to the QA/quality or packaging-engineering c
threshold2 paid orders, or 1 paid order plus 2 written 'send me an invoice' commitments, within 14 days of the first email going out — anything less than 1 paid order is a kill

Recorded at the moment the verdict was issued and not editable afterwards. If this is launched, the result lands on the ledger whether it passes or fails.

and what moves it forward

Where this idea is

Phase nowAnalysed — Underwritten, with the argument against it on the record.
What you do hereRead the case against it first. An upheld charge you cannot answer is the verdict, whatever the score says.
To leave this phaseYou have read the upheld charges and decided the idea survives them.
Gate statusThis gate is a judgement, not a query. The system will not rule on it and will not pretend to — you decide, and the reason is recorded.
Next phaseValidating — A pre-registered test is live and running.

This gate is a judgement rather than a query, so the system states it and refuses to rule on it. Pretending software can decide whether a business "can take money from somebody who is not you" would make every gate on this site meaningless. Advancing an idea needs its link — the one handed back when it was submitted. Founder-owned ideas are advanced from the console. See the whole pipeline.

What to do in this phaseWhat it provesFrom which part of the analysis
Answer the upheld charge: Free functional substitutes already solve the exact stated queryThe verdict survives its strongest objection, or it does not and you have learned that before spending.arbitration
Answer the partial charge: Task frequency too low to sustain a subscriptionThe verdict survives its strongest objection, or it does not and you have learned that before spending.arbitration
Answer the upheld charge: Addressable buyer population is uncountable and likely smaller than statedThe verdict survives its strongest objection, or it does not and you have learned that before spending.arbitration
Answer the partial charge: Wrong buyer targeted — searcher has no purchasing authorityThe verdict survives its strongest objection, or it does not and you have learned that before spending.arbitration
Answer the partial charge: False-negative liability destroys trust irreparably after first missThe verdict survives its strongest objection, or it does not and you have learned that before spending.arbitration
Answer the upheld charge: Buyer doesn't know they have this problem until after the damage is doneThe verdict survives its strongest objection, or it does not and you have learned that before spending.arbitration
Answer the partial charge: Channel costs exceed lifetime value given tiny TAM and low priceThe verdict survives its strongest objection, or it does not and you have learned that before spending.arbitration

Every step traces to a field this idea's own underwriting produced — not generic best practice, which is free everywhere. 0 of 7 complete. Mark them off in the console.

and what did not complete

How this was produced

MeasureValue
Wall clock74 minutes

A verdict produced by 22 of 23 stages is not the same artefact as one produced by all of them, and which stages failed was recorded on every run and shown nowhere until now. If a stage that feeds a section died, the section came from somewhere else or nowhere — and you are entitled to know which is in front of you before you act on it.

The money

price pointanchor: Positioned far below Atlas Compliance's enterprise tier, which runs $30K–80K per named-user annual license and is itself pitched as roughly one-third the cost of the ~$50K/license incumbent (Redica-class tools) it displaces; monthly: 39; rationale: Target buyer is a small assembler with no compliance team and a free alternative already available at $0; the only defensible price is a low self-serve SaaS tier that beats the time cost of manually searching multiple free databases, not one that competes with enterprise compliance suites priced two to three orders of magnitude higher
current spendamount: $0/month on a dedicated recall-lookup tool; source: Candidate's own price_floor note confirms free public alternatives exist; no evidence in search results of small kit assemblers paying for a dedicated recall-lookup product today; on what: Manual, unpaid searches of FDA's free public tools (Enforcement Reports database, openFDA, NDC List, FDA.report) before committing a lot to production
funding routereinvest
revenue modelsubscription
churn monthly pctwhy: Point-solution with a single narrow use case, no workflow integration, no data lock-in, and a free substitute always available (FDA.gov itself); usage is likely episodic (only before a production run) rather than daily, which historically produces high monthly churn in niche B2B SaaS with no switching cost — this is an inferred rate based on category norms for un-integrated compliance point tools, not a sourced figure; value: 10
cash to first dollar600
marginal cost per unitvalue: 0.05; components: openFDA/FDA Enforcement Report API calls are free and rate-limited; incremental cost per user session is essentially hosting/bandwidth on the existing VPS plus Postgres query load and Supabase auth calls — no per-lookup licensing fee exists because the underlying data source is public. Fixed cost (data ingestion/normalization pipeline to keep the aggregation current) is real but not marginal per unit.

What has to be built

wedgesegment: Small FDA-registered convenience-kit assemblers; evidence: FDA guidance explicitly states assemblers of convenience kits are considered 'manufacturers,' which means 'any person who manufacturers, prepares, propagates, compounds, assembles, or processes a device.'; why they switch: Kit assemblers are legally classified as manufacturers under FDA rules and are on the hook for the same quality obligations as full manufacturers, including lot traceability and recall readiness, but most are small shops with no compliance department — they need one fast yes/no answer on a specific supplier or lot before they commit it to a kit, not a subscription or an audit workflow; incumbent failing th
data moatNone. The underlying data is openFDA's public enforcement database, already free and already aggregated by at least two direct competitors (NDC List, FDA.report) and the FDA's own dashboard. Nothing proprietary accumulates from ingestion alone. The only path to a moat would be layering user-submitted supplier quality reports or incident history on top of the public feed over time, which this candidate as scoped does not include.
componentsopenFDA ingestion pipeline (drug enforcement + device enforcement endpoints, schema normal: risk: med; units: 3; Lot/NDC extraction from unstructured recall text: risk: high; units: 4; Postgres schema + fuzzy search index (pg_trgm on supplier/manufacturer, exact match on NDC: risk: low; units: 2; Flask search API (supplier/NDC/lot endpoints, pagination, rate limiting): risk: low; units: 2; React search UI (search box, result cards, filters, empty states): risk: low; units: 3; Auth + Stripe paywall (free tier limited, paid unlimited/API access): risk: low; units: 2; Cron scheduler + ingestion monitoring/alerting: risk: low; units: 1; Deployment (VPS/Vercel/Supabase config, backups): risk: low
total units18
smallest offerwhat: Manual concierge report: customer emails a supplier name, NDC, or lot number; operator manually cross-checks openFDA drug/device enforcement data, FDA enforcement reports, and GUDID/NDC directory, delivers a one-page PDF verdict (clear / flagged / inconclusive) within 24 hours, sold via a Stripe Payment Link on a single landing page — no login, no software, no integration; price: 49; format: service; days to build: 2
wedge strengthworkable
hardest unknownFDA enforcement reports store lot numbers inside free-text 'reason for recall' and 'product description' fields, not structured fields, and format varies wildly by manufacturer (dashes, alpha-numeric, multiple lots per report, sometimes omitted). Reliable extraction and normalization so a user's typed lot number actually matches is the core promise of the product and the part most likely to silently produce false negatives — someone checks a recalled lot and gets 'no results' because the parser missed the format. This isn't a solved NLP problem here; it needs custom regex/heuristics tuned against real historical data and ongoing maintenance as new formats appear.
days to first dollar12
the verdict is not the end of the process

If you decide to do this

StepWhat it meansWhere it happens
1 · Read the case against it firstCharges the arbiter upheld are the ones to answer before committing. If an upheld charge is fatal for you, the verdict is not.on this page
2 · Commit the pre-registered testThe test is already written: Completed Stripe payments at $99 from firms with no prior relationship to the operator at 2 paid orders, or 1 paid order plus 2 written 'send me an invoice' commitments, within 14 days of the first email going out — anything less than 1 paid order is a kill. Committing freezes it with a date, and it cannot be edited afterwards.promote it →
3 · Stand up the offerA landing page, a price, and an instrumented link. Nothing is proven until somebody who does not know you is asked to pay.ventures →
4 · Run distribution and let it resolveThe test resolves mechanically on its deadline: actual against threshold, no judgement. A test never distributed resolves VOID rather than FAIL — inaction is not evidence.automatic, daily
5 · The outcome grades this verdictWhatever happens is written back against this prediction and scored. That is what makes the next verdict better, and it is the only honest basis for ever claiming an accuracy.the ledger →

Not now. Something specific would have to change first, and it is named in the ruling. Steps 2 and 3 open the operator console, which lives under this same domain at /account and requires a log-in — the public record is readable by anyone, and committing a prediction against it is not. Step 5 happens automatically: this prediction is already frozen with its score, its confidence, and every dimension as it stood, waiting for an outcome to grade it against.