Vitalpax Inc.
Quotation Tool CRM
Development Updates
Third Party ingredients arrive - ingredients sourced from custom vendors outside Acctivate can now be added, priced, and vendored from a new Settings hub, then pulled straight into formulations and carried through the R&D Lab, Sourcing, and Pricing tabs with color-coded TP markers - laying the foundation for auto-scraped ingredients. Capped by a three-part security hardening push around account activation links, administrative role changes, and profile saves.
July 1 - 7, 2026
Section
New Features &
Enhancements
A full Third Party ingredients system - a dedicated Settings hub to add, price, and vendor custom ingredients that live outside Acctivate, flowing end to end through the R&D Lab, Sourcing, and Pricing tabs.
Major Enhancement
A New Third Party Ingredients Hub
- Custom-Vendor Ingredients -- Third Party (TP) ingredients are ingredients sourced from custom vendors outside the standard Acctivate catalog, now managed in their own place.
- New Settings Area -- Admins get a Settings to Third Party screen to add, edit, and manage TP ingredients alongside their vendors and pricing.
- Full Detail On Add -- Each ingredient captures an SFP name, specification, E Number, and UOM when created.
- Manual or Scraped Source -- A Source field marks each ingredient as Manual or Auto (Scraped) - the hook for the upcoming online-sourcing feature.
Feature Update
Vendors & Pricing per Ingredient
- Dedicated Detail Page -- Every TP ingredient has its own page showing its E Number, UOM, source, specification, and record dates.
- Multiple Vendors -- A Product Vendors table lets admins attach one or more vendors to an ingredient, each with its own unit and price.
- Best-Price Flag -- The cheapest vendor is tagged Best price, and each vendor row carries price history and edit controls.
Feature Update
Third Party in the R&D Lab
- Pulled Into Formulations -- TP ingredients can be added to a formulation straight from the R&D Lab tab, just like standard Active ingredients.
- Clear Row Details -- The ingredient's Row Details show a Third Party pill and a Switch to Acctivate option, with its target label claim and connected vendor.
- Marked At A Glance -- Each tab uses a distinct color and a TP badge to flag Third Party rows, so users can instantly tell them apart from Active ingredients.
Feature Update
Carried Through Sourcing & Pricing
- Vendors in Sourcing -- Vendors for a TP ingredient are selected in the Sourcing and Pricing tabs, keeping the whole quote on one workflow.
- Color-Coded Everywhere -- The Ingredient Pricing table marks TP rows with the same orange TP badge, so Third Party entries stand out from Acctivate items at every stage.
- Foundation For Scraping -- This system is the groundwork for an upcoming feature that pulls ingredient data from online sources directly into formulations as Third Party entries.
Section
Security Hardening
Three server-side patches tighten the account lifecycle: activation links are confined to internal logs, administrative role changes are validated at the database layer, and profile saves are separated from core system settings.
Security Patch
Data Minimization on Account Activation
- The Risk -- Single-use invitation and activation links could, in rare background delivery-failure states, surface where a browser session or client-side log might capture them.
- The Fix -- Extra server-side filtering now confines those links strictly to internal delivery logs, even when a send fails.
- The Result -- Activation links can never reach browser sessions or client-side logs, keeping every invitation truly single-use.
Security Patch
Server-Side Validation for Admin Roles
- The Risk -- Without a backend guard, a crafted request could in theory push a role or permission change without going through an administrator.
- The Fix -- Permanent, hard-coded permission checks now sit directly in the database routing layer, so admin-level changes only process for a verified Administrator account.
- Defense In Depth -- Role changes can no longer bypass official administrative channels, even if a front-end check were ever circumvented.
Security Patch
Profile Layer Protection
- The Risk -- A routine profile save could, without separation, be used to smuggle in a change to sensitive fields like account status or permissions.
- The Fix -- Save-time validation logic now programmatically separates ordinary profile edits from core system settings.
- The Result -- Standard profile updates stay verified and self-contained, keeping user data and account controls secure at the code level.
Summary
What We Shipped
1
Major Feature
3
Security Patches
Third Party ingredients now flow end to end - added and priced from a new Settings hub, then pulled into formulations and carried through the R&D Lab, Sourcing, and Pricing tabs with color-coded TP markers, laying the groundwork for auto-scraped ingredients - while a three-part security push confined activation links to internal logs, validated admin role changes at the database layer, and separated profile saves from core system settings.