Keystone
by CloudVoro
Batch traceability

Batch traceability without the spreadsheet acrobatics.
Full upstream + downstream chain in under 30 seconds.

Every batch carries its full chain inside Keystone, supplier deliveries upstream, dispatches and customer branches downstream. Two clicks, signed PDF, done. No more Vlookup chains, no more 'which version of the Excel was current that week.'

  • Forward trace: batch → dispatch → customer → retailer branch (incl. private-label re-codes)
  • Backward trace: dispatch line → batch → supplier delivery → raw-material lot
  • Mock-recall in 90 seconds (BRCGS compatible)
  • Immutable audit log, every change, signed, who/when/why
How it works

Every batch is a node in a chain. We hold the chain.

When a batch is created in Keystone, every input, supplier delivery, raw-material lot, QC record, transformation step, is recorded as an upstream link. When that batch is dispatched, every customer and retailer branch it reaches is recorded as a downstream link. The chain is cryptographically signed at every write, so neither side can be tampered with after the fact.

What you can answer

The questions auditors actually ask.

Where did this batch end up?
Forward chain: every dispatch line, every customer, every retailer branch, every private-label code.
What went into this dispatch?
Backward chain: every batch, every supplier delivery, every QC test along the way.
Which batches share a supplier delivery?
Cross-trace: pick any supplier delivery and see every batch that used it, typical recall trigger.
Who changed the spec mid-run?
Audit log: every spec change with user, timestamp and reason, immutable.
Intermediates & rework

The chain survives silos, brines and rework, where spreadsheets break.

The hard part of batch traceability is never the happy path; it's the intermediate stages. Milk from three farms pools into one silo. Offcuts from Tuesday's batch fold into Thursday's. A brine bath touches six batches a week. In spreadsheet systems these commingling points are exactly where lot identity dies, and why mass balances refuse to close during the annual traceability test. Keystone models intermediates as first-class links in the chain: a silo run knows its contributing deliveries, a rework entry names its source and destination batches with weights, so the chain passes through every commingling point intact, in both directions.

The mass balance

Produced = dispatched + stock + waste + samples. Computed, not reconstructed.

BRCGS expects the annual traceability test to close a mass balance within 4 hours, and unexplained quantity gaps fail the exercise regardless of how fast the trace ran. Because Keystone's dispatch lines, stock counts, waste entries and sample logs all reference batch identity, the reconciliation for any batch is arithmetic the system already knows: quantity produced against every documented destination, with the variance percentage on screen. Producers who used to spend the afternoon hunting for missing kilograms now spend it writing the two-paragraph narrative report.

From spreadsheets

What actually changes when you switch.

Trace time
From hours of VLOOKUP archaeology to under 30 seconds, any batch, either direction, benchmarked on the founding-customer dataset.
Key-person risk
Anyone with the right role can run the trace. The system holds the map, not one production manager's memory.
Re-keying errors
Batch codes flow from production to dispatch note to trace report without a human transcribing them, the transposed-digit findings disappear.
Audit posture
The vertical audit (auditor picks a lot, watches you trace it) becomes a live demonstration instead of the tensest hour of the year. New to the exercise? Read our free step-by-step mock recall guide.
FAQ

Questions buyers actually ask.

How is Keystone different from a generic ERP?
A generic ERP treats batches as inventory line items. Keystone treats them as nodes in a directed chain with cryptographic signing, built for traceability first, accounting second.
What about variable-weight production (e.g. cheese wheels)?
Native support. Each unit can carry its own weight, with case-level and pallet-level rollups that reconcile against your dispatch totals.
Can I trace by customer SKU code, not just mine?
Yes, bidirectional mapping is built in. Search by your code or by the retailer's private-label code.
How far back does the audit log go?
Forever. Nothing is ever truly deleted in Keystone, soft-deletes with restore, hard-deletes blocked.

Ready to see if Keystone fits your floor?

20-minute discovery call. No sales pitch. Written scope within 48 hours if we fit, referral to someone better if we don't.

Talk to us
Compliance & trust

How we keep your
data and your audits safe.

Enterprise-grade controls as standard, encryption, MFA for every user, tenant isolation and immutable audit trails, on EU cloud or your own servers. Privacy queries go to privacy@cloudvoro.com. Sub-processor list at /legal/sub-processors. Full security posture at /site/security.

Live
Hosted in EU / Ireland, or on-premise
Customer data resides on AWS Ireland (eu-west-1) and never leaves the EU. Local on-premise deployment available where policy requires it.
Live
GDPR · Privacy Contact named
Internal Data Protection Lead handles subject access requests. Owner is ADPO Ireland member.
Live
MFA for every user
TOTP multi-factor authentication across all roles, with rate limiting, brute-force lockout and reCAPTCHA bot protection on public forms.
Live
ISO 27001 · aligned controls
Security controls mapped to the ISO/IEC 27001:2022 Annex A framework, access management, encryption, logging, incident response.
Live
NIS2 · supporting evidence
Tenant isolation, MFA and immutable audit trails give customers in NIS2 scope direct supporting evidence for their obligations.
Live
Encryption · at rest & in transit
TLS 1.3 in transit, industry-standard symmetric ciphers at rest, KMS-managed keys.