Keystone
by CloudVoro
Allergen management

Allergen management with batch-level evidence.
Because "the label was right" needs proof, per batch.

Undeclared allergens are the most common cause of food recalls in Ireland and the UK, and almost every case traces to the same gap: the label said one thing, the batch contained another, and no record connects the two. Keystone closes that gap structurally: every batch carries its recipe version and the actual ingredient lots consumed, so the declaration on the label has a per-batch evidence trail behind it.

  • Every batch records its recipe version + actual ingredient lots consumed
  • Supplier allergen alert → affected batch and customer list in minutes
  • Versioned specs: historic batches resolve against the recipe current when made
  • Supports FIC (Reg. 1169/2011) declaration diligence with real records
See it in action

Real screens, from our Public Sandbox.

Every screenshot below is captured from the Public Sandbox demo tenant with sample Irish dairy data. No mockups, no client data, no NDAs.

Keystone Traceability Events (Public Sandbox demo data), audit evidence pack with QC, mass balance, mock-recall history and signed PDF export.
The audit binder assembled itself. You just tell it what date range.
Keystone Mock Recall report (Public Sandbox demo data), full forward trace from a supplier lot to every affected batch, customer and dispatch.
One click. Every customer, every branch, every quantity, ready as a signed PDF.
Keystone Reports (Public Sandbox demo data), make-day summary with milk usage, ingredient / packaging usage and batch counts by supervisor.
Reports built for QA managers and auditors, not for looking pretty in board meetings.
Where allergen incidents start

Not in the kitchen, in the paperwork gap.

The classic undeclared-allergen incident isn't a rogue ingredient; it's drift. A supplier reformulates and the new spec carries mustard. A recipe changes but the label artwork doesn't. A substitution happens on the floor at 6am and nobody writes it down. Each is a records problem before it's a labelling problem, and the investigation afterwards asks precisely what your records can't answer: which batches were made with the new spec, from which date, and who received them? Keystone answers it structurally: ingredient lots link to supplier specs, batches record actual consumption, and spec changes are versioned with effective dates.

The working controls

Allergen control as records, not vigilance.

Batch-level consumption
Not "this product contains", "this batch consumed these lots". The difference is what an investigation, an auditor or a retailer technical team actually asks for.
Supplier alert response
A supplier reports undeclared sesame in a lot: pick the lot, see every batch that consumed it (directly or through sub-assemblies), every customer, every quantity, in minutes.
Versioned recipes and specs
Reformulations carry effective dates. Batches made before the change resolve to the old spec; after, the new, so historic declarations stay defensible.
QC checkpoints
Label-verification and changeover checks record against the batch, building the due-diligence file as a by-product of production.
Scope, honestly

Evidence engine, not artwork management.

Keystone is the record layer: what each batch contained and where it went. It does not generate label artwork or legally validate your declarations, your labelling process and technical review remain yours. What it removes is the terrifying question in every allergen investigation: 'can we prove what was actually in it?' Prepared food, bakery and dairy producers feel this most; the batch-consumption model is the same across all of them.

Keep reading

Related pages on this stack.

FAQ

Questions buyers actually ask.

Does Keystone generate allergen labels?
No, it holds the evidence behind them: per-batch recipe versions and actual ingredient lots. Batch codes and dates flow to your labels; artwork and legal declarations remain with your labelling process.
What happens when a supplier reformulates?
The ingredient spec is versioned with an effective date. Batches record which version they consumed, so "which batches carry the new allergen profile, from when" is a lookup, not an investigation.
Can it handle allergen alerts through sub-assemblies?
Yes, if the affected lot went into a sauce that went into a meal, the trace follows the whole tree to finished product and customers, with quantities.
Does this help with a BRCGS or retailer audit?
Allergen management is a standing item in both. Batch-level consumption records, versioned specs and attached QC checks are exactly the evidence those audits sample.
What about cross-contact / "may contain"?
Scheduling and changeover controls stay physical, but Keystone records the checks (changeover cleaning, line clearance) against batches, the documented diligence behind your cross-contact policy.

Ready to see if Keystone fits your floor?

20-minute discovery call. No sales pitch. Written scope within 48 hours if we fit, referral to someone better if we don't.

Talk to us
Compliance & trust

How we keep your
data and your audits safe.

Enterprise-grade controls as standard, encryption, MFA for every user, tenant isolation and tamper-evident audit trails, on EU cloud or your own servers. Privacy queries go to privacy@cloudvoro.com. Sub-processor list at /legal/sub-processors. Full security posture at /site/security.

Live
Hosted in EU / Ireland, or on-premise
Customer data resides on AWS Ireland (eu-west-1) and never leaves the EU. Local on-premise deployment available where policy requires it.
Live
GDPR · Privacy Contact named
Internal Data Protection Lead handles subject access requests. Owner is ADPO Ireland member.
Live
MFA for every user
TOTP multi-factor authentication across all roles, with rate limiting, brute-force lockout and reCAPTCHA bot protection on public forms.
Live
ISO 27001 · aligned controls
Security controls mapped to the ISO/IEC 27001:2022 Annex A framework, access management, encryption, logging, incident response.
Live
NIS2 · supporting evidence
Tenant isolation, MFA and tamper-evident audit trails give customers in NIS2 scope direct supporting evidence for their obligations.
Live
Encryption · at rest & in transit
TLS 1.3 in transit, industry-standard symmetric ciphers at rest, KMS-managed keys.