You found this in your access log
Something crawled your certificate pages and left a link to this page in its User-Agent. This is that crawler, in full, with the limits it runs under and the way to turn it off.
PeptoraCollector/1.0 (+https://peptoraai.com/about-collector; neutral COA verification; contact: collector@peptoraai.com)What it collects
Certificates of Analysis that vendors publish openly on their own COA pages — the PDF or image of the certificate itself, and the URL it came from. Vendors publish these so buyers can verify a batch. That is exactly what we use them for.
What it never touches
- Anything behind a login, a paywall, or a checkout.
- Customer data, order data, pricing, or inventory.
- Any page your
robots.txtdisallows — including wildcard rules that do not name us.
It also runs with stealth mode, proxy rotation, and CAPTCHA solving deliberately switched off. The crawler library we build on ships all three. Using them to get around a block on someone else’s server is not a thing a company whose only asset is being trusted gets to do.
The limits it runs under
These are configuration values the crawler reads at startup, not intentions:
- robots.txt is obeyed
- check_robots_txt = true — no exceptions, no override flag
- One request per 2 seconds, per domain
- delayMsPerDomain = 2000
- Never more than two requests at once
- maxConcurrent = 2
- Shallow, not a site rip
- maxDepth = 2, maxPagesPerTarget = 40
- Only hosts on a reviewed allowlist
- Suffix-matched — evil-clone.com of an allowed host is rejected
- Requests time out rather than hang
- timeoutMs = 30000
How to stop it
Any one of these works. None of them require a reply from us.
- Add a rule to robots.txt. Disallow
PeptoraCollector, or disallow all agents from your COA path. It is checked before every request. - Block the User-Agent at your edge. If you block us, we stay blocked. We will not change the string, rotate addresses, or route around it.
- Email and say stop. collector@peptoraai.com. Your domain is removed on request, without argument and without asking why. Already-collected certificates from your site are removed with it if you ask.
What happens to what it collects
A collected certificate is read for its published values — compound, batch code, purity, mass, testing lab — and fingerprinted so the same document cannot be quietly reused under a second seller’s name. That produces a public verification record.
Two consequences worth stating plainly. A record can reflect badly on the vendor whose certificate it came from, and every record is reproducible from its own audit log rather than an opinion — so if you think one is wrong, contest it and it gets reviewed on the facts.
The lab we deliberately do not crawl
Janoshik Analytical is the reference lab most of this market tests with. We link out to their verification and never mirror or poll their database. The vendor pages already carry the same certificates, so crawling the lab would add nothing and cost them bandwidth.
Personal data
This page covers documents collected from public vendor pages. For what the service stores about people — accounts, uploads, cookies, retention, deletion — see the privacy policy.
Peptora reports on documents and data for research-use-only materials. It makes no human-use, dosing, or therapeutic claims.