Security documentation

CardIQ Enterprise Security & Governance

Controls for administering company identity while keeping claims within the platform’s implemented security and verification boundaries.

Enterprise authentication boundary

Review what the current SAML configuration foundation does—and does not—activate.

Available now

Controls remain subject to role, permission, plan and tenant context.

Administrative roles

Super Admin and Company Admin responsibilities are separated. Company access is scoped and permission checks protect management actions.

Support access boundaries

Support Operators use explicitly allowed, tenant-scoped support workflows. They are not Company Admins and the support model does not provide employee impersonation.

Authentication and sessions

Password/session controls, login activity, session revocation and administrator TOTP MFA foundations are implemented.

Audit and alerts

Identity audit records and security alerts support authorized review; availability can depend on plan and configuration.

Company trust

DNS TXT domain verification and Trusted Domains provide scoped ownership and email-domain signals. They do not prove government identity.

Lifecycle enforcement

Employee deactivation and company lifecycle states can stop an identity from being presented as active.

Company lifecycle is not employee lifecycle

A company state applies at workspace level; employee status applies to one professional identity.

Company states

Operational lifecycle controls include active, suspended, frozen and archived handling where applied. Suspended or frozen workspaces restrict normal company operations and active identity presentation.

Employee states

An employee can be activated, reviewed, frozen where supported, or deactivated independently within an operating company.

Security assurance boundary

Evaluate CardIQ controls alongside your own policies and hosting arrangement.

No certification claim

This documentation does not claim ISO, SOC 2, PCI, NCA or other CardIQ certification.

No universal authenticity guarantee

Verification signals help recipients assess a company-controlled identity; CardIQ does not guarantee authenticity in every case or prevent all fraud.

Control how employees represent your company externally

Explore the CardIQ platform or review the workflow from verification through identity deactivation.

See how CardIQ works View pricing