Find counterfeit medicines before they find patients.
How one client's question about an implausible scan pattern became the intelligence layer now running on PharmaSecure's platform.
See psAnalytiQ live at PharmaSecure ↗PharmaSecure serializes medicine packaging. Every pack carries a unique code, and anyone holding a strip can verify it against the record to establish that the product in their hand is genuine. Billions of packs carry it, for manufacturers including Sun Pharma, Mankind and Abbott.
A code returned verified for its first five scans and over-verified thereafter. One code, one answer, assessed in isolation.
The question a client kept asking
Sun Pharma kept returning to the same anomaly. Particular codes were being verified again and again. Not twice, not a dozen times. Three thousand times.
The scale is what makes that figure impossible. A batch carries roughly forty thousand unique codes, of which only about 2 percent are ever scanned at all. A single code reaching twenty or thirty verifications already exceeds anything a shelf and a customer can account for. Three thousand is not an enthusiastic patient. It is one authentic code reproduced across a great many counterfeits, each of them returning genuine to the person holding it.
Interrogate the scanner, not only the code
The productive shift was to stop asking whether a code looks wrong and start asking who has been scanning it. A counterfeiting operation does not present as one suspicious code. It presents as a handful of devices and networks moving through thousands of them, in territories the genuine consignment never reached, at hours when no pharmacy is open.
So the system maintains a lifetime history for every network address and device it has encountered, and adjudicates those before it considers any individual code. Volumes no legitimate seller generates. Several moderate signals arriving in concert. And the pattern that proved most telling: a scanner that surfaces, works through a tranche of codes and vanishes within days, which no volume threshold on its own would ever register. A code touched by a scanner already known to be compromised is flagged outright, without recourse to a model. Provenance of that quality outranks anything inference can offer.
Rules a compliance officer can read
Each code is then characterised across more than 20 signals: the geographic separation between verifications, how many states it surfaced in simultaneously, how much of its life occurred in the first week after manufacture, activity in the small hours, concentration on a single device, and the interval between manufacture and first appearance, where a negative value means the code was verified before the medicine existed.
Those signals feed rules stated in plain language. Four hundred kilometres apart. Three states at once. Any one of them is dispositive on its own. Others are inconclusive individually and damning in combination, so they accumulate and trip as a group.
The decision I would defend hardest came next. Rather than wait for labelled fraud that did not exist, the rules became the training data. Domain knowledge was encoded as supervision, and the models learned to generalise beyond it.
A hybrid that learns two ways
Rules can only catch what somebody anticipated. Two models sit behind them, selected for opposing reasons.
The first is a gradient-boosted tree ensemble, trained on the labelled population. It suited the problem because the signals are counts, distances and ratios on entirely different scales, to which trees are indifferent; because it reads interactions rather than features in isolation; and because the class balance is severe enough that rare positives must be weighted heavily, or the model settles on the trivial solution of declining everything. It returns a probability rather than a verdict, which is what allows a threshold to be negotiated openly with a compliance team rather than asserted at them.
The second is an isolation forest, given no labels whatsoever. It infers the shape of normal from the population itself and reports how far a code sits outside it. That matters because counterfeiting is adversarial. Tactics change, and a system that knows only the patterns already codified begins to degrade the moment somebody invents a new one. The anomaly detector is what registers a code that violates no rule and still does not belong.
Neither is trusted in isolation. The two scores resolve into a single risk figure, weighted toward the supervised model because its probabilities are calibrated, whereas anomaly scores are only interpretable relative to the population that produced them.
Making it work at scale
The scaling problem here is not throughput. It is that normal is a different distribution for every manufacturer. An analgesic sold through every chemist in the country and a specialist therapy shipped to forty hospitals generate entirely different verification behaviour, and a model trained on the first and pointed at the second would raise alarms about nothing at all. Each client therefore carries its own trained pair, versioned jointly against the precise rule set they learned from, so that inference can never run against rules a model has never seen.
That arrangement is also what makes a new client viable on day one. The rules carry the system while there is no history to learn from, entity histories accumulate as verifications arrive, and the models are trained once a population exists worth learning from. The intelligence grows into the account rather than being a precondition for it.
Every alert accounts for itself
In pharmaceuticals an alert that cannot account for itself is not actionable. Somebody has to act on it: dispatch an inspector, write to a distributor, place it in front of a regulator. So every flag carries its reasoning in a sentence a compliance officer can read. Elevated verification count. Multiple distinct devices. Implausible geographic spread. Because the models are versioned against the rules they learned from, any alert can be reconstructed against what the system believed at the moment it fired.
It runs as a nightly pass rather than a live service for the same reason. The unit of judgment is the accumulated picture, not the individual scan.
What it does now
It ships as psAnalytiQ, the intelligence layer on PharmaSecure's platform. In testing it reduced the time to surface a suspect code by roughly 90 percent against reviewing codes individually after the fact, and it converts an undifferentiated mass of verifications into a ranked caseload: reasoning attached, hotspots mapped, repeat offenders named.
Making the copy worthless
Detection has an inherent ceiling. However early psAnalytiQ raises its hand, the counterfeit has already been printed, distributed and in some cases dispensed. The other half of the answer is to make copying the code worth nothing in the first place.
Serialization establishes that a number is valid. It cannot establish that the number belongs to the pack it is printed on, which is precisely how one authentic code comes to sit on thousands of counterfeits. Non-clonable approaches bind the code to something no counterfeiter can reproduce: a mark whose structure is random at a scale nobody governs, including the press that produced it. Capture it at manufacture, verify it in the field, and a reproduction fails, because it carries the image and not the physical disorder beneath it.
I drove that programme end to end, and it is the work I would put forward if someone asked whether I can carry an idea from the literature into something that exists. It began as a literature review and an assessment of what the field had already attempted, became a product definition, and then the logic and the algorithms underneath it. It is a working prototype today, running pilots.
The difficult problem is not the physics. It is tolerance. Two captures of the same mark are never identical, because the second is taken on a consumer handset, off axis, under pharmacy lighting, on a pack that has spent a week in somebody's pocket. So the governing question is how much divergence still constitutes the same mark, and where that boundary sits. Set it too tight and a pharmacist is telling a patient that their genuine medicine has failed authentication. Set it too loose and the mechanism is ceremonial. That boundary is a product judgment as much as a technical one, and it is where most of my time went.
Asking the data in plain English
Separately, I built a natural-language query layer for analysts, so that a question could be posed in plain English rather than assembled as a query. Building it in-house was a deliberate constraint: pharmaceutical supply-chain data is not material to hand to a third-party model, and nothing needed to leave the network for an answer to come back.
The other half of the job
Counterfeit intelligence was one thread. The remainder of the role was the product authentication business itself, where I was the point of contact for every stakeholder, internal and external. That meant running serialization programmes for three of India's five largest pharmaceutical manufacturers, with Sun Pharma, Mankind and Abbott among the accounts I managed, and being the person both sides called when something required a decision.
I also built the company's inventory management system from the ground up, covering the full stock lifecycle the serialization business depends on. It is the least glamorous item on this page and among the most used.
What it taught me
Pharma taught me respect for process. The industry is exacting about documentation and procedure, and I came to read that discipline not as bureaucracy but as the thing that makes trust auditable. The model was the easy half.








