We will be undergoing planned maintenance on Oct 7th 6:00AM UTC / Oct 7th 2:00AM ET

RecallLens — Find the source, not the secrets

Inspiration

This project became personal for me.

In July 2026, the United States faced a major Cyclospora outbreak linked to iceberg lettuce. The CDC reported more than 1644 illnesses and 94 hospitalizations across five states. I was one of the people affected. I recently recovered after dealing with the illness myself. CDC outbreak report

While I was sick, I kept thinking about how something as ordinary as eating lettuce could affect so many people. I also wondered whether the warning could have come earlier.

Food safety investigations have a coordination problem.

A grower may hold harvesting records. A processor may have private quality assurance results. A distributor may know that a shipment experienced a temperature problem. A retailer may observe an unusual cluster of consumer reports.

Each signal may seem small on its own. Together, they could reveal an emerging risk days earlier. The problem is that companies may need to expose supplier relationships, customers, routes, quantities, invoices, and other private business records to connect them.

This creates a dangerous choice. Companies can protect their private data or share it quickly to protect consumers.

RecallLens came from one simple question.

What if companies could prove that their private records point to the same food safety risk without revealing the records themselves?

That is what I wanted to build. A system that could detect warning signs earlier, help investigators trace affected food faster, and warn consumers before more people experience what I did.

RecallLens eliminates that tradeoff.

It allows independent organizations to prove that their private records relate to the same hidden supply lineage—without publishing the records or revealing the complete supply chain.

What it does

RecallLens supports the complete food-safety lifecycle:

Detect → Verify → Hold → Trace → Act → Protect

1. Detect risks earlier with Sentinel

RecallLens Sentinel combines independent private signals such as:

  • Processor quality-assurance anomalies
  • Cold-chain temperature excursions
  • Aggregated consumer-exposure reports

Each organization submits its own proof. Midnight verifies that the signals:

  • Come from distinct credentialed organizations
  • Represent multiple signal categories
  • Share the same hidden lineage
  • Fall within the required time window
  • Cannot be submitted twice

When the configured threshold is reached, Sentinel reports early risk convergence. It does not diagnose a pathogen or declare an outbreak—it provides a privacy-preserving reason to investigate sooner.

2. Issue a confidential precautionary hold

An authorized investigator can anchor a precautionary-hold commitment on Midnight.

Matching partners can respond without revealing their complete inventories, while consumers scanning a signed RecallLens Product Passport can learn that their item intersects an active hold.

The result clearly distinguishes a private precautionary hold from an official FDA recall.

3. Trace the shared lineage privately

Investigators cannot generate another company’s proof.

They send a private-match request, and each supply-chain partner independently:

  1. Opens its private vault
  2. Locates its own committed EPCIS record
  3. Reviews the requested predicate
  4. Approves or rejects the request
  5. Generates its own zero-knowledge proof

The investigator sees anonymous proof results—not the partner’s raw records.

When three distinct organizations prove the same hidden lineage, RecallLens reports Shared Supply Lineage Verified. This narrows the investigation without falsely claiming that contamination or causation has been proven.

4. Disclose only what is necessary

After verification, a partner can selectively disclose individual fields such as:

  • Origin facility
  • Shipment lot
  • Shipment date
  • Destination facility

Approved fields are encrypted in the partner’s browser using ECDH P-256 and AES-GCM. Only ciphertext leaves the partner’s device, and the investigator decrypts it with their own key.

Unchecked fields never enter the plaintext payload.

5. Authorize targeted action

Once the relevant shipment is identified, the investigator reviews an exact recall predicate and anchors the authorized RecallLens action on Midnight.

Consumers can scan the same signed Product Passport again and see that it now matches the targeted recall scope.

RecallLens also compares a broad response with the targeted scope using clearly labeled synthetic inventory data, demonstrating how private coordination could reduce unnecessary disposal while reaching affected products faster.

6. Check official recalls

Consumer Check also evaluates ordinary product identifiers against live official FDA information.

Our demonstration includes a real FDA advisory for frozen blueberries. The scan produces an Exact Official Recall Match using the lot, product, package size, and best-by date published by the FDA.

Official FDA results and RecallLens network actions are deliberately separated so users can always understand who authorized an action and what evidence supports it.

Why Midnight is essential

A conventional shared database would require every participant to trust its operator with commercially sensitive supply-chain information.

Midnight gives RecallLens a different architecture:

  • Private state: supplier identities, customer identities, lot codes, routes, quantities, QA results, temperatures, invoices, and raw lineage tokens
  • Public state: opaque commitments, anonymous case tags, one-time nullifiers, verified organization counts, hold commitments, and authorized-action hashes
  • Zero-knowledge proofs: establish that private records satisfy an investigation predicate without revealing those records
  • Nullifiers: prevent one organization from inflating the result with duplicate submissions
  • Selective disclosure: allows proof to happen before any identifying information is revealed

Privacy is not an optional feature of RecallLens. It is what makes cooperation between independent—and sometimes competing—organizations possible.

How we built it

RecallLens is a TypeScript monorepo containing:

  • A React and Vite web application
  • An interactive Three.js outbreak globe
  • A role-separated Investigator Workspace and Partner Vault
  • Local browser-based QR decoding
  • Signed RecallLens Product Passports
  • GS1/EPCIS-inspired trace records
  • Live CDC and FDA source adapters with transparent provenance
  • Browser-native encrypted selective disclosure
  • A Midnight Compact smart contract
  • A local Midnight node, indexer, and proof server
  • Automated simulator, unit, integration, and Playwright tests

The Compact contract contains nine circuits covering credentialed participation, Sentinel signals, precautionary holds, trace relevance proofs, duplicate prevention, and targeted-action authorization.

During the end-to-end demonstration, genuine Midnight transactions are generated for the final Sentinel signal, precautionary hold, third lineage proof, and targeted-action authorization.

Challenges we faced

Preserving privacy without destroying usefulness

Publishing too much would expose a company’s supply graph. Publishing too little would leave investigators unable to act. We designed each workflow around a precise predicate and explicitly show what stays private, what becomes public, and what may be selectively disclosed.

Maintaining real role separation

An earlier workflow allowed one interface to trigger another organization’s proof. We replaced it with a request-and-approval model: investigators request, record owners review, and only the owning partner can generate the proof.

Communicating different levels of evidence

A matching lineage does not prove contamination. A precautionary hold is not an FDA recall. A no-match result does not guarantee safety.

RecallLens uses distinct evidence levels and receipts so every result explains its source, authority, matched fields, Midnight involvement, and limitations.

Making cryptography understandable

We transformed proof generation into a visible product workflow: independent signals converge, a hold becomes active, a physical package is scanned, anonymous partners prove a shared lineage, selected fields are decrypted, and the same consumer scan changes when an action is authorized.

Accomplishments

  • Built and compiled a working Compact contract with 43 passing simulator tests
  • Executed genuine proof-backed state transitions on a live local Midnight devnet
  • Implemented independent-organization and signal-category thresholds
  • Prevented duplicate submissions with per-organization nullifiers
  • Built role-correct investigator and partner workflows
  • Implemented browser-native encrypted selective disclosure
  • Connected a physical QR scan to live Midnight-anchored state
  • Integrated live official FDA and CDC information with explicit provenance
  • Completed an automated browser suite covering desktop and mobile workflows
  • Produced an end-to-end product rather than an isolated proof-of-concept circuit

What we learned

The most valuable public data is often not the underlying record—it is a narrowly defined, verifiable fact about that record.

Midnight allowed us to build a system where organizations can coordinate around shared risk while retaining control of their data. We also learned that privacy products must communicate uncertainty as carefully as they implement cryptography.

Business value

RecallLens is designed as privacy-preserving coordination infrastructure for growers, processors, distributors, retailers, restaurants, regulators, and food-safety investigators.

Its value is straightforward:

  • Detect correlated risk signals earlier
  • Reduce hesitation caused by competitive-data exposure
  • Trace affected inventory with greater precision
  • Reduce the blast radius and cost of broad recalls
  • Warn consumers using product-level evidence
  • Preserve an auditable record of proofs and authorized actions

The product could be offered as a B2B integration layer for existing GS1 EPCIS and food-safety systems, with pricing based on participating facilities, monitored events, or active investigations.

What’s next

A production version would add:

  • Enterprise identity and organization credentialing
  • Direct GS1 EPCIS connectors
  • In-circuit membership proofs for hold and recall sets
  • Governed threshold policies for different product categories
  • Encrypted partner notifications
  • Cryptographically verifiable removal attestations
  • Production Midnight deployment and wallet integration
  • Retail and consumer notification integrations

Demonstration transparency

The supply-chain organizations, Product Passports, partner records, early signals, and blast-radius comparison in the demo are synthetic and visibly labeled.

The Compact proofs, Midnight state transitions, passport signatures, encryption workflow, browser scanning, and official FDA/CDC source retrieval are functional.

RecallLens does not diagnose disease, prove that an individual product is contaminated, or replace FDA, CDC, laboratory, or epidemiological investigations.

Built With

Share this project:

Updates

Submission history