Verification boundaries

What CardIQ verifies — and what it does not

CardIQ verifies whether professional identity and communication details are recognized and authorized by the company that manages them. It is not a physical-identity, biometric, KYC, or deepfake-detection service.

What CardIQ verifies

CardIQ focuses on company-authorized external professional identity: whether the organization recognizes the person, contact point, or domain within the company context being checked.

Company-authorized employee identity

CardIQ can show whether an employee is currently presented by the organization as an active, authorized representative through company-managed identity records.

Recognized communication details

Within a selected company, CardIQ can verify supported communication details such as email addresses, phone numbers, WhatsApp numbers, landlines, and trusted domains against company-managed records.

Company and domain context

CardIQ can identify whether a company exists in CardIQ and, where supported, whether a domain is recognized as trusted by that organization.

Current authorization status

When a company deactivates an employee or changes approved information, CardIQ can reflect that change in the company-controlled external identity experience.

What CardIQ does not verify

A positive CardIQ result should not be interpreted as proof of a person’s physical identity or as a guarantee that every message, call, document, invoice, or meeting is genuine.

Physical identity or government-ID proofing

CardIQ is not a KYC service and does not verify passports, national IDs, or a person’s legal identity unless a separate, explicitly supported service is introduced.

Biometrics or face matching

CardIQ does not use face matching, liveness detection, fingerprints, or other biometric methods to prove who is physically behind a message or meeting.

Deepfake detection

CardIQ does not analyze audio or video to determine whether a voice, face, or recording is AI-generated or manipulated.

Transaction or document authenticity

CardIQ does not by itself validate invoices, bank instructions, contracts, payment requests, or the contents of a message. Verification confirms company-recognized identity or communication context, not the legitimacy of every transaction.

How to interpret a verification result

Verified / recognized

The submitted detail matches an active, company-managed record or trusted company context supported by CardIQ. Continue to use normal business judgment for the specific request or transaction.

Not recognized

CardIQ did not find the submitted detail in the supported active records for that company. This is a reason to verify through another trusted company channel, not automatic proof of fraud.

Confirmed unauthorized / security warning

Where the company has reviewed and confirmed a reported indicator as unauthorized, CardIQ may show a company-scoped security warning for future checks of that same indicator.

CardIQ is designed to strengthen corporate identity assurance and reduce ambiguity around who and what the company recognizes. It complements — but does not replace — fraud controls, payment verification, KYC, IAM, or cybersecurity monitoring.

A practical verification workflow

1. Select the company

Start with the organization you expect the person, email, phone number, WhatsApp number, or domain to belong to.

2. Check the communication detail

Use the company’s Verification Hub to check whether the submitted detail is recognized in that company context.

3. Validate the request separately

For payments, confidential data, password resets, executive requests, or unusual instructions, follow your organization’s normal secondary controls even when the identity detail is recognized.

4. Report suspicious impersonation

If something still appears suspicious, use the company-scoped impersonation reporting path where available so the organization can review it without exposing reporter identity publicly.

Frequently asked questions

Does CardIQ prove that the person on a call or video is really the employee?

No. CardIQ verifies company-authorized professional identity and supported communication details. It does not perform biometric face or voice matching, liveness checks, or deepfake detection.

If CardIQ says an email or phone number is not recognized, does that mean it is fraudulent?

Not automatically. It means the detail did not match the supported active records for the selected company. The safest next step is to verify through another trusted company channel.

Does CardIQ replace KYC or identity and access management?

No. CardIQ focuses on external corporate professional identity control and verification. KYC, IAM, payment controls, and cybersecurity monitoring remain separate controls.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing