How it works

A document repository tells you what you have. DOSSA tells you whether you are covered.

Most supplier-compliance systems do two things: store documents and remind you about dates. That leaves the hardest question unanswered — does the paperwork you hold actually satisfy the obligations you have, for this supplier, for this product, today? DOSSA models the whole chain, and the connections between the links are the product.

Request access
Step 1 — the supplier sends it

The link that removed the reason suppliers do not comply.

Every other step depends on this one, and it is where the industry has a known, chronic failure. Supplier portals ask a grower, a haulier or a subcontractor to create an account, remember a password and navigate a dashboard built for somebody else's business — so they don't. They email the PDF instead, or they send nothing, and your compliance system is confidently wrong. DOSSA sends a link. No account, no password, nothing to learn: the supplier sees what they owe, drops the file, and gets an answer in seconds. Others ask suppliers to work their way through a system to reach compliance. We deleted the system they had to work through.

  • No login — the link is the whole thing, and there is nothing behind it to get lost in
  • Built for a phone in a packing house, not a desk
  • One drop zone: your supplier should not have to guess which requirement their certificate satisfies
  • "That certificate expired in August" — said while they still have the folder open, not three emails later
  • Send it however you already chase people: your own email, a reply in an existing thread, a message
A supplier opens the DOSSA link and sees exactly what is outstanding, with nothing to log into
DOSSA reading a folder of supplier documents and proposing what each one is
Step 2 — the AI reads it

It works out what the document is. It does not decide what counts.

The AI identifies the document, the supplier it belongs to, the certificate number and the expiry date — from clean PDFs and from photographs of paper. Then it stops. It cannot create a new kind of document to make something fit, and it cannot mark anything compliant. That restraint is what makes the output usable in a file somebody may have to defend.

  • Reads messy scans, phone photos and Office files, not just tidy PDFs
  • Never invents a document type — your catalogue is defined by you
  • Low confidence surfaces as a question, not as a decision
  • A read that fails says why and offers a retry, instead of pretending to still be working
Step 3 — it lands against an obligation

The document meets the requirement it was meant to satisfy.

A certificate on its own is a file. A certificate matched to a requirement scoped to that supplier — or to the specific product they ship you — is an answer. DOSSA resolves obligations at whichever level they belong: everyone, a group, one supplier, one product.

  • Requirements scope by supplier, group, product or product group
  • One supplier can be fully covered for one product and uncovered for another — and DOSSA says so
  • An exemption is a recorded decision with a reason, not an unexplained blank
  • A supplier nobody has written requirements for reads as unmeasured, never as compliant
Requirements scoped by supplier group and product group
The compliance overview showing review state and expiry as separate facts
Step 4 — a person verifies it

"Verified" means somebody accepted it. With a name and a date.

The review act and the document's validity are kept apart, permanently. A certificate that lapsed last month still shows it was verified — because it was, by a named person, on a date an auditor can ask about. Nothing rewrites that history when the calendar moves.

  • Verification is a human act, recorded as one
  • Review state and expiry are two separate columns, never merged into one misleading word
  • A replaced certificate supersedes its predecessor, so the queue can actually reach zero
  • Every state change is on the audit trail
Step 5 — the record stands on its own

What you can show, and when you can show it.

Compliance is computed from evidence rather than typed in, so it is current by construction and it changes when the world does. Your ERP can read it and stop a purchase order before it is raised. And for US food importers, the same chain continues into FSVP — hazard analysis, supplier evaluation, verification activities, corrective actions and an inspection-ready package.

  • One screen for the whole book of business, expiring items ahead of the lapse
  • Your ERP can read verdicts and block a PO before it goes out — we never write to your system
  • FSVP is a module on top for US food importers; everyone else never sees it
  • The evidence behind any answer is one click away, for the day somebody asks
The DOSSA dashboard showing compliance across every supplier

Frequently asked questions

What actually makes this different from a document management system?

A document system stores files and tracks dates — the first two links of the chain. DOSSA connects documents to the obligations they satisfy, for the supplier and the specific product, then to a human verification, then to a decision, then to a record you can show. The answer to "can I buy from this supplier today?" needs every link, which is why storing files has never been enough.

Why is there no supplier login?

Because logins are why supplier compliance fails. Your suppliers already have ten or twenty customer portals and no appetite for another account — so when a portal feels optional, they email the PDF and your system stops matching reality. The link removes the step they refuse to take. It is our simplest decision and our most important one.

How much do you trust the AI?

For reading, a lot. For deciding, not at all. The AI identifies documents, extracts dates and proposes matches; it cannot create a document type, cannot verify anything, and cannot move a supplier's status. Every decision that would matter in an audit is made by a person and recorded as theirs.

Do we have to change how we work?

No. Point DOSSA at the folder your documents already live in and it reads the whole tree. Chase suppliers however you already chase them — the upload link works pasted into your own email or a message thread. The product fits around the way the work already happens.

Is this only for food importers?

No. The chain above has no industry in it — supplier, product, document, requirement, verification. Property managers, contractors, franchisors and staffing agencies run the same problem with different certificates. FSVP is an add-on for US food importers under 21 CFR 1.500–1.514.

Limited Early Access

See if DOSSA is a fit.

Tell us about your operation and we'll show you exactly how DOSSA fits in.

Request access

No commitment. Reply within one business day.

No credit card required
FSVP-ready in days
Dedicated onboarding