Keystone
by CloudVoro
Recall management · Incident response

Recall management software for food producers.
Scope it in seconds. Manage it with evidence.

A real recall is two problems at once: scoping (which lots, which customers, how much) and managing (decisions, notifications, documentation, follow-through, all under Article 19 obligations and a ticking clock). Most software only helps with the first. Keystone does both: the 30-second chain trace scopes the event, and the Traceability Events module manages it, status workflow, audit trail, customer communication drafts, and a single exportable response pack for the FSAI, your retailer or your certifier.

  • Scope in seconds: affected batches, dispatches, customers and quantities from one starting point
  • Event workflow: draft → under review → closed, every status change logged with who/when/why
  • Customer communication drafts generated per affected customer
  • One-click Response Pack PDF: summary, affected chain, notes, status history, draft notices
The first hour

Scoping decides the size of your bad week.

When a supplier alert or a positive test lands, the scope question, exactly which lots and customers are affected, determines everything downstream: how many phone calls, how much product destroyed, how public the event becomes. Imprecise records force a wide scope 'to be safe', which multiplies cost. Keystone's trace starts from any point (a supplier lot, a batch, a dispatch) and returns the full affected chain with quantities in under 30 seconds, so your scope is exactly right, and defensible, from the first phone call. Article 19 of EU food safety regulations requires notifying the competent authority without delay; walking in with a precise, documented scope changes that conversation entirely.

Beyond the trace

Managing the event, the part spreadsheets never covered.

Traceability Events
Open an event from any trace. It snapshots the affected make-days, batches, dispatches and customers, and becomes the single record of the incident.
Status workflow with audit trail
Every transition (draft, under review, closed) is logged, who, when, and the note explaining why. The timeline auditors reconstruct by interview elsewhere, you export as a table.
Customer communication drafts
Per-customer draft notices generated from the affected chain, reviewed and sent by humans, never auto-sent.
The Response Pack
One PDF: event summary, full affected chain with quantities, internal notes, status history and communication drafts. The document you hand the FSAI, the retailer technical team, or your certifier.
Practice like it's real

The same machinery runs your mock recalls.

Because scoping and event management are the same tools in rehearsal and in reality, your BRCGS-required mock recalls (§3.11) stop being a parallel paperwork exercise: run the trace, open an event, walk the decision chain, export the pack, timed, documented, done. Producers who drill quarterly with the real machinery are the ones for whom the real event, if it ever comes, is a bad day instead of an existential one. Our free step-by-step mock recall guide covers the full procedure.

FAQ

Questions buyers actually ask.

Does Keystone notify the FSAI or customers automatically?
No, deliberately. Keystone scopes the event, manages the record and drafts the notices; decisions and sending stay with named humans. Automated external notifications during a live food incident are a liability, not a feature.
What exactly is in the Response Pack PDF?
Event reference and status, trigger summary, the affected chain (make-days, batches, dispatches, customers with quantities), internal notes, the full status history with who/when, and the per-customer draft communications.
Can we re-open and update an event as it develops?
Yes, events are living records. Refresh the affected chain against current data, append notes, and every status change adds to the audit trail.
Does this satisfy BRCGS incident-management requirements?
Keystone provides the documented procedure evidence §3.11 expects: recall capability, tested exercises with timings, decision logs and retained results. Your written recall plan and named roles remain yours; the system evidences their execution.
How is this different from your mock recall feature?
Same engine, different lifecycle. Mock recall is the drill: trace + signed PDF. Recall management adds the persistent event record, workflow, notes, history, drafts, response pack, for incidents that live longer than an afternoon.

Ready to see if Keystone fits your floor?

20-minute discovery call. No sales pitch. Written scope within 48 hours if we fit, referral to someone better if we don't.

Talk to us
Compliance & trust

How we keep your
data and your audits safe.

Enterprise-grade controls as standard, encryption, MFA for every user, tenant isolation and immutable audit trails, on EU cloud or your own servers. Privacy queries go to privacy@cloudvoro.com. Sub-processor list at /legal/sub-processors. Full security posture at /site/security.

Live
Hosted in EU / Ireland, or on-premise
Customer data resides on AWS Ireland (eu-west-1) and never leaves the EU. Local on-premise deployment available where policy requires it.
Live
GDPR · Privacy Contact named
Internal Data Protection Lead handles subject access requests. Owner is ADPO Ireland member.
Live
MFA for every user
TOTP multi-factor authentication across all roles, with rate limiting, brute-force lockout and reCAPTCHA bot protection on public forms.
Live
ISO 27001 · aligned controls
Security controls mapped to the ISO/IEC 27001:2022 Annex A framework, access management, encryption, logging, incident response.
Live
NIS2 · supporting evidence
Tenant isolation, MFA and immutable audit trails give customers in NIS2 scope direct supporting evidence for their obligations.
Live
Encryption · at rest & in transit
TLS 1.3 in transit, industry-standard symmetric ciphers at rest, KMS-managed keys.