QR & NFC trust model

A QR code can be copied. The authoritative identity behind it is what matters.

CardIQ does not treat the visual QR code or NFC tag itself as proof of identity. These surfaces are routes to a company-controlled identity record whose current state can change when the organization updates or deactivates the employee.

What the QR or NFC surface actually does

The QR or NFC interaction opens or references the CardIQ identity experience. Trust comes from the company-controlled record and its current lifecycle state, not from possession of the printed code, image, sticker, badge, or NFC tag.

QR is a route, not a secret

A public employee QR is expected to be scannable and therefore copyable. CardIQ does not rely on keeping the visible QR secret.

NFC is a route, not possession-based proof

Where NFC is used, the tag is a convenient way to open the public identity destination. It should not be interpreted as a private credential that proves the person physically holding the tag is the employee.

Current server-side state remains authoritative

The organization can update approved identity data or deactivate an employee. CardIQ then reflects the current company-controlled state rather than trusting an old screenshot, printout, or copied code by appearance alone.

What happens if someone copies a legitimate QR?

The copy still points to the same authoritative destination

If someone reproduces the exact legitimate QR, the copied QR should still resolve to the same CardIQ destination. Copying the image does not give the copier administrative control over the employee record.

Lifecycle changes still apply

If the company later changes or deactivates the employee record, the same legitimate QR route reflects the new current state. An old copy of the code does not freeze the identity in its old status.

Copying appearance is not copying authority

A copied QR, card image, logo, title, or profile photo can imitate appearance. It does not copy the company’s control of the authoritative CardIQ record.

What about a fake QR?

A fraudster can generate a different QR that points to another website. That is a destination-trust and phishing problem, not proof that the fake QR became a CardIQ identity.

Check the destination

Users should confirm that the destination is the expected CardIQ/company-controlled identity experience rather than trusting a printed code only because it looks branded.

A logo inside a QR is not a security guarantee

Branding can improve recognition, but a logo or visual design can also be copied. Trust should come from the resolved destination and current company-controlled identity state.

Offboarding and revocation

Deactivation changes the authoritative record

When the company deactivates an employee, CardIQ’s current identity state can reflect that the employee is no longer active/authorized. The exact visible behavior depends on the relevant CardIQ surface and deployed configuration.

Old physical copies do not override current state

A printed card, saved QR image, screenshot, or NFC item does not by itself preserve active authorization after the underlying company-controlled employee state changes.

What CardIQ does not claim about QR and NFC

Not an uncopyable QR

CardIQ does not claim that a public QR image cannot be photographed, screenshotted, forwarded, printed, or reproduced.

Not proof of physical possession or personhood

Scanning a QR or tapping NFC does not prove that the person physically present is the employee. CardIQ does not perform biometric, liveness, or face/voice verification through these surfaces.

Not a current W3C VC or DID credential claim

CardIQ does not currently claim that its standard employee QR/NFC surfaces are W3C Verifiable Credentials, DID-based credentials, or offline cryptographically verifiable employee credentials.

Not a guarantee that every linked request is legitimate

A valid company identity does not make every payment request, invoice, bank instruction, file, message, or meeting genuine. Sensitive transactions should continue to use normal secondary controls.

Frequently asked questions

Can someone copy a CardIQ QR code?

Yes. A public QR can be copied. If the exact legitimate QR is copied, it still points to the same authoritative CardIQ identity destination; copying the image does not grant control of the employee record.

Does NFC prove that the person holding the card is the employee?

No. NFC is a convenient route to the identity destination. CardIQ does not treat physical possession of the NFC item as biometric or legal proof of the person’s identity.

What happens to an old copied QR after offboarding?

The copied legitimate QR continues to resolve to the same identity destination, where CardIQ can reflect the current company-controlled lifecycle state. The old copied image does not preserve active authorization by itself.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing