The second signature is already required.
On paper it proves nothing.
When a nurse wastes part of a controlled substance, DEA rules require a second licensed person to witness it and sign. That signature lands in a paper log or a text field — where it can be scribbled by the same person, added later, or simply invented. The requirement is real. The proof isn’t. We’re building the version that is.
Two credentials · one sealed record · verifiable by an auditor without trusting the hospital
Waste event · sealed
● 2 of 2 signedMorphine 4 mg wasted of 6 mg vial
19 Jul 2026 · 10:00:00 UTC
A. Rivera · releasing
RN · TX-4471 · signed 10:00:00J. Okafor · witnessing
RN · TX-9982 · signed 10:00:30Sealed — both signatures verify
Editing anything breaks it visiblyWhy the paper version fails.
Nobody is being careless. The control was designed for a world of physical logbooks, and it never got the upgrade the rest of the pharmacy did.
One person can produce both signatures
A signature line accepts whatever is written on it. The most common diversion pattern is not a forged record — it’s a real one where the witness never actually watched.
It can be completed afterwards
Paper and free-text fields have no honest sense of time. A log filled in at the end of a shift looks identical to one filled in at the sink.
The record lives with the accused
When an investigation starts, the evidence is held by the same institution being investigated. That is exactly the position no one wants to defend from.
What a real two-person seal looks like.
Both people sign the same record, at the moment it happens, each bound to their own licence. Neither can produce it alone.
Both parties sign the same thing
Not two separate entries — one record, signed twice. That’s what makes them co-signers of a single fact rather than two people making claims that happen to sit near each other.
The licence is captured, not asserted
Each signature carries the signer’s credential and the role they signed in, recorded as part of what gets sealed. A credential typed in afterwards isn’t a credential.
You cannot witness yourself
If both signatures resolve to the same credential, the record refuses to seal. That check is the entire control, so it lives in the cryptography rather than in policy or training.
Any edit breaks it, visibly
Change the drug, the amount, the time, or either name, and the seal fails. Not “an audit flag” — the record stops verifying, and anyone can confirm that independently.
Who this is actually for.
The nurse who did it right
Most people caught up in a diversion investigation did nothing wrong. A signed record they couldn’t have altered protects them far better than a colleague’s memory of a Tuesday.
The pharmacy director
Reconciliation stops being a hunt through logs. Gaps surface as broken chains rather than as discrepancies someone has to notice.
The auditor
Verification without trusting the institution being audited — which is the only kind of verification that means anything in that room.
Where this actually stands.
We’d rather tell you this plainly than let you find out on a call.
What exists today
- The two-person seal is built and tested in our signing library
- Self-witnessing is refused at the cryptographic layer, not by policy
- Tamper-evidence and independent verification work the same way they do for our live review product
- The signing key is published, so anyone can verify a sealed record without an account
What does not exist yet
- A nurse-facing capture flow at the point of waste
- Integration with any dispensing cabinet or EHR
- Per-signer keys — credentials are captured, but signing runs on a service key today
- Any deployment in a live clinical setting
So this is a pilot conversation, not a product you can buy this afternoon. If the problem is real where you work, that’s exactly who we want to build the first one with.
Talk to us about a pilot.
The founder reads every message and will tell you honestly whether this is ready for what you need.