Trust model

How CardIQ establishes trust

CardIQ does not treat a logo, QR code, email signature, meeting background, or contact detail as proof by itself. Trust comes from checking those surfaces against the organization’s current company-controlled records and lifecycle state.

1. Company context is established first

CardIQ is designed around a company-scoped trust model. Verification begins with the organization the person, identity, communication channel, or domain claims to represent.

Company-controlled workspace

Authorized administrators manage employee identity records, approved contact details, trusted domains, and lifecycle state inside the company context.

Domain trust signals

Where supported, CardIQ uses company-domain verification and trusted-domain records as organization-level trust signals. Domain trust does not by itself make every email address or person using that domain valid.

2. The authoritative record is company-controlled

Digital cards, QR codes, NFC links, signatures, and meeting backgrounds are presentation surfaces. CardIQ treats the underlying company-managed identity record as the source of current professional identity status.

Employee identity record

The company controls whether an employee is currently represented as active and authorized, together with the professional details it chooses to publish.

Approved communication details

Supported email addresses, phone numbers, WhatsApp numbers, landlines, and trusted domains are checked against the company context rather than inferred from appearance, names, or profile photos.

3. Verification is based on current state

CardIQ is designed to reflect whether a company currently recognizes an identity or communication detail. This lifecycle state is what makes offboarding and revocation meaningful.

Active employee

When the employee is active, CardIQ can present the company-controlled professional identity through supported public identity surfaces.

Deactivated employee

When the company deactivates the employee, CardIQ no longer treats that record as an active company-authorized professional identity. Public behavior depends on the relevant surface, but the current status remains controlled centrally.

4. Verification Hub checks communication channels

Verification Hub answers a narrow company-scoped question: is this submitted communication detail currently recognized by this organization?

Privacy-preserving result

The verifier selects the company first. CardIQ does not provide reverse lookup that reveals which employee owns an arbitrary email address or number.

Not Verified is not a fraud verdict

A Not Verified result means CardIQ did not find the submitted value among the supported active company records. It is a reason to verify through another trusted channel, not automatic proof of fraud.

Company-confirmed warning

Where a company administrator has reviewed a reported indicator and confirmed it as unauthorized, CardIQ may show a company-scoped security warning for future checks of that same indicator.

5. QR and NFC are pointers, not possession-based proof

A QR code can be photographed and an NFC link can be copied. CardIQ therefore does not treat possession of the QR artwork or URL as proof of identity.

Copied legitimate QR

A copied legitimate CardIQ QR still routes to the same company-controlled identity record. Copying the appearance does not give the copier administrative control over that record.

Fake QR or lookalike page

A fake QR can point to a phishing or lookalike destination. Users should rely on the official CardIQ/company-controlled verification destination and current record, not on visual similarity alone.

6. Reporting and review add a company security feedback loop

When a visitor sees something suspicious, CardIQ can support company-scoped reporting and administrator review without turning an unverified result into an automatic accusation.

Needs Review by default

A visitor report should begin as a review item rather than an automatic fraud determination.

Administrator confirmation

Company administrators can review and classify reports. Confirmed findings can strengthen future company-scoped warnings without exposing reporter identity publicly.

7. CardIQ complements — but does not replace — security and IAM controls

Email security

CardIQ does not replace SPF, DKIM, DMARC, mailbox authentication, Microsoft 365 security, or phishing controls. It adds company-controlled professional-identity context.

IAM and access control

CardIQ is not a replacement for Microsoft Entra, Okta, HR systems, or core identity providers. Enterprise integrations can support identity lifecycle workflows, but CardIQ focuses on external professional identity control and verification.

Physical identity / KYC

CardIQ does not perform government-ID proofing, biometric verification, liveness detection, or deepfake detection.

Frequently asked questions

What is CardIQ’s source of trust?

The source of trust is the organization’s current company-controlled identity and communication records, together with the relevant lifecycle state and supported company/domain trust signals. The visual design of a card or QR code is not treated as proof by itself.

Does CardIQ use cryptographically signed employee credentials?

CardIQ’s current public trust model is based on live company-controlled records and current status. CardIQ should not be interpreted as a W3C Verifiable Credentials, DID, or offline cryptographic-credential platform unless such a capability is explicitly introduced and documented.

Can someone copy a CardIQ QR code?

Yes. A QR code can be copied or photographed. CardIQ does not rely on possession of the QR as proof. A legitimate copied QR still resolves to the same company-controlled identity record and current status.

Does CardIQ guarantee that a message, invoice, or payment request is genuine?

No. CardIQ can help verify company-recognized professional identity or communication context, but transaction authenticity and payment approval require separate controls.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing