Installation & Administration

CardIQ Deployment Guide

Plan a CardIQ managed, shared-hosting, VPS, dedicated-cloud or self-hosted deployment with verified boundaries.

Deployment models

Deployment models

Managed SaaS is operated by CardIQ while customers administer company identities and entitlements. Dedicated cloud and self-hosted arrangements are contract-scoped: topology, data location, availability, support access, update ownership and service levels must be agreed rather than inferred. A generic self-managed shape is Web Server → PHP → MySQL-compatible Database → Persistent Storage.

Shared hosting and server choice

Shared hosting and server choice

The repository follows a traditional PHP/MySQL hosting shape and includes .htaccess, so compatible Apache/shared hosting can be evaluated. It must provide the required PHP capabilities, database, HTTPS, private configuration, writable persistent paths and outbound access needed by enabled integrations. Nginx is not currently validated by repository evidence and requires separate web-server configuration and validation.

Scheduling and operations

Scheduling and operations

Schedule only the maintenance and reconciliation jobs required by the deployed release using authenticated or CLI-safe operational procedures. Some enterprise functions, including scheduled Microsoft Entra lifecycle reconciliation, require an external scheduler. Do not expose maintenance scripts publicly. Monitor private PHP, web, database and application logs.

Production security checklist

Production security checklist

Require HTTPS; prevent direct config.php and backup access; disable directory listing; use database least privilege; secure cookies and secrets; disable public error display and log privately; restrict admin surfaces; protect upload directories; verify minimal file permissions; encrypt and protect backups; rotate compromised credentials; enable privileged-user MFA where supported; and validate lifecycle governance and audit records.

Responsibility considerations

Responsibility considerations

In customer-operated environments, the customer should plan infrastructure, OS, database, firewall, certificates, persistent storage, backups and monitoring. Application guidance, updates, support and migration assistance depend on the agreed CardIQ arrangement and are considerations rather than promises in this guide.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing