Corporate digital business cards
Publish company-controlled business cards with branded QR code sharing, secure vCard downloads, and email signature support.
Clear answers for HR, IT, Sales Operations, Compliance, and company admins evaluating CardIQ for employee identity management and corporate digital business cards.
Read CardIQ Enterprise Documentation · Developer & API documentation · Enterprise SSO documentation
Publish company-controlled business cards with branded QR code sharing, secure vCard downloads, and email signature support.
Admins manage profile details, company branding, premium templates on eligible plans, and approval workflows.
Profiles can capture leads and deliver them through secure webhooks to CRM tools and sales operations workflows.
Admins can disable or control profiles when employees leave, helping keep public contact identity current.
Paid plans can include Company Contacts, secure employee messaging, advanced analytics, branded QR codes, and easy integration workflows.
CardIQ supports Arabic and English public content and product flows for bilingual company teams.
Compare CardIQ pricing, review corporate identity management, learn about employee offboarding control, see branded QR code sharing, or request a demo.
Employees are managed identities and cards; Company Users are authenticated workspace accounts with roles.
Messages are private and internal; Highlights are official announcements that may reach eligible public audiences.
Notifications contain user-specific official updates; employee conversations remain in Messages.
The Directory contains active employees; Contacts contains external or business relationships.
The dashboard summarizes overall health; alerts are individual events requiring review.
Analytics Overview consolidates available high-level metrics; Card & Profile Analytics details engagement; Lead Analytics opens the detailed Lead Performance Analytics report; Leads CRM supports operational follow-up.
API Keys authenticate generic API access; CRM Webhooks configure outbound CRM synchronization.
It checks whether an email, mobile number, WhatsApp number, landline, or website is currently authorized by a selected company. The company must be selected first, and CardIQ returns only Verified or Not Verified without revealing employee identity. See the Communication Verification guide.
No. CardIQ does not provide reverse lookup or disclose an employee or company behind an arbitrary number. You must first select the organization you want to verify the number against.
No. Verified means the channel is currently registered by the selected organization in CardIQ as an authorized corporate communication channel. It does not prove who is physically using the device at that moment.
No. It means CardIQ could not confirm the channel as currently authorized by the selected organization. Verify sensitive requests through another trusted company channel.
No. CardIQ checks the number against organization-approved CardIQ records. It does not issue or claim Meta or WhatsApp verification and does not provide a WhatsApp badge.
Yes. CardIQ provides a deliberately limited company-scoped server API for approved integrations, selected public read helpers, and signed outbound lead webhooks where configured. See the Developer & API Documentation hub for its current scope and limits.
The company server API uses a secret in the X-API-Key header. Bearer tokens are separate and serve first-party employee/mobile app routes; the two credential types are not interchangeable.
Yes. The server derives the company from the authenticated API key, and the documented routes do not let callers select another tenant.
Yes. An eligible configured company can send the outbound lead_created event to one HTTPS receiver, and an administrator can send webhook_test. CardIQ does not expose a general inbound webhook API.
Yes. CardIQ signs the exact raw body with HMAC-SHA256 using the company secret and sends the digest in X-CardIQ-Signature.
No. CardIQ does not currently provide native SCIM provisioning; its documented API is a limited company-scoped integration surface.
Company-scoped API operations are blocked with HTTP 403 and can return COMPANY_SUSPENDED with a public-safe message that does not expose internal reasons or notes.
CardIQ requires a web-hosting environment with PHP and a MySQL or MariaDB database, plus appropriate web-server configuration, PHP extensions and file permissions. Confirm exact versions and deployment requirements with CardIQ before rollout.
The application does not currently include a managed automatic-backup service. The hosting or operations team is responsible for scheduling database and file backups and testing restoration according to the agreed deployment plan.
CardIQ can be deployed behind Nginx when it is correctly configured for PHP execution, route handling and protection of sensitive files. The repository does not provide a production-ready Nginx configuration, so the server configuration must be reviewed and tested for the deployment.
CardIQ currently provides a company-level configuration foundation for SAML metadata. It does not yet activate automatic SSO redirect or enforced login, and email/password login remains active.
CardIQ supports SAML metadata configuration, including provider type, Entity ID, SSO URL and certificate fingerprint/reference. This is a configuration foundation, not a completed or enforced SSO authentication flow.
CardIQ supports company-bound Entra OIDC sign-in for pre-mapped users and a read-only preview of explicitly selected groups where configured. The preview uses User.Read.All and GroupMember.Read.All application permissions and never creates, updates, links, or deactivates employees.
Okta can conceptually act as a SAML identity provider, but CardIQ does not currently claim a native Okta integration or tested compatibility.
Native SCIM provisioning and deprovisioning are not currently available. A custom API integration must not be described as SCIM support.
No. Automatic SSO redirect and enforced SSO login are not currently active. Enable and enforce controls store configuration readiness and future policy intent only.
No. SSO controls authentication and login; provisioning creates, updates or deactivates accounts. SAML SSO does not automatically mean SCIM provisioning.
The CardIQ Public Company Profile is a company-controlled digital identity hub that brings together official company links, contact channels, products and services, locations, representatives, employee identities, and corporate resources in one public destination.
CardIQ can provide a Linktree-style company destination, but it goes further. Linktree organizes links, while CardIQ is designed to organize and control company identity, official representatives, employee identities, and company information, with verification where enabled and supported.
Yes. A company can use its public CardIQ profile as an official URL that can be shared directly or through a QR code. The profile can centralize approved company information, links, contacts, representatives, and employee cards.
No. Verification depends on the verification features enabled for the company and the applicable setup. CardIQ should not be interpreted as universally verifying every company, employee, or user.
Because the profile is managed by the company, official links, representatives, employee identities, and company information can be updated centrally. This helps reduce reliance on outdated or unmanaged information.
It is company governance of outward-facing employee identity across profiles, digital business cards, signatures and meeting touchpoints, including authorization, updates and deactivation.
No. CardIQ verifies corporate authorization and company-controlled professional identity; it does not provide government-grade legal identity verification.
No. IAM systems control access inside an organization. CardIQ complements them by controlling how employees represent the organization externally.
A company publishes a CardIQ-provided DNS TXT record. CardIQ checks that record and, when it matches, presents the domain as verified.
The Identity Dashboard provides administrators with a real-time overview of their organization's identity health, including verification status, trusted domains, QR protection, security alerts, meeting readiness, and employee identity metrics.
The CardIQ Identity Health Score combines verified employee coverage, trusted domain configuration, meeting readiness, signature configuration, LinkedIn connection coverage, and penalties for reviews, frozen identities, and open security alerts. The dashboard shows the exact contribution of each signal.
CardIQ is a Corporate Digital Identity Control Platform that helps organizations manage company-controlled employee identities, digital business cards, public employee profiles, email signatures, meeting identity, and lifecycle control.
Employees can connect their LinkedIn profile. CardIQ may show “LinkedIn profile connected,” display name, and optional public LinkedIn URL. This adds professional context and supports admin review, but it is not official LinkedIn employee verification.
Company Highlights are professional announcements published by an authorized company administrator. They may include company news, product launches, partnerships, awards, certifications, or important updates, and appear on employee CardIQ profiles according to the selected target audience.
Following official updates lets a signed-in CardIQ user receive company-controlled public announcements from an official CardIQ company profile. It does not create an employment relationship or a social-network connection.
Verified Highlights are professional achievements such as completed projects, certifications, promotions, awards, or events submitted by employees and approved by an authorized company administrator before appearing on the public CardIQ profile.
CardIQ uses signature verification links, QR validation, company-controlled employee profiles, branded virtual meeting backgrounds with active employee QR, and admin review to help recipients confirm identity details and reduce risk.
Company Admins can publish a controlled email signature template that uses approved employee and company information. The same design is then generated automatically for eligible employees, while employee-specific details such as name, title, contact information, QR code, and profile link remain personalized.
Email signatures can include a CardIQ verification link or QR code so recipients can validate the employee profile through CardIQ.
Use Report suspicious identity on the public profile or signature verification page. CardIQ sends the report for admin review when available.
CardIQ asks you to compare the sender email from your email app with the CardIQ signature profile. This helps confirm that the email sender matches the company-controlled employee identity linked to the signature.
CardIQ signature verification checks whether the signature links to an active company-controlled profile and whether key trust signals, such as company domain verification, are available. If the company/domain is verified and the profile is active, the risk assessment can show low risk. If signals are missing, it recommends review.
Companies can use branded meeting backgrounds with active employee QR or validation links to add a company-controlled verification layer during online meetings.
Employee Identity Freeze lets authorized admins temporarily place an employee profile under review. During the freeze, CardIQ avoids presenting the profile, signature, or meeting QR as low risk and hides sensitive actions such as booking or vCard download.
Authorized admins can open the related QR abuse alert and use Resolve and clear QR review after completing their investigation. This clears the review state without deleting the QR or deactivating the employee.
Trusted Domain Policy lets a company define which email domains are approved for employee identities. After a company admin verifies their registration email, CardIQ can automatically add that email domain as a trusted domain. If an employee email does not match the trusted domain policy, CardIQ can show Review recommended instead of presenting the identity as low risk.
An inactive trusted domain is retained for audit history but is not used by CardIQ to trust employee email addresses or determine identity status.
Review recommended means one or more identity trust signals need admin attention, such as domain verification, trusted domain policy mismatch, inactive workspace, or frozen employee identity. Admins can review the reason in the workspace header or Company Configuration.
No. A trusted domain created from a verified admin email means the admin verified an email address on that domain. Full domain ownership verification requires a separate DNS verification step.
Meeting Identity Check is a short CardIQ guidance section on the employee QR/profile page. It explains safe signals such as active employee status, company-controlled profile, QR/profile validity, company domain verification when available, and whether admin review is recommended. It does not analyze video/audio or prove the meeting participant is real.
CardIQ helps reduce meeting impersonation risk with branded virtual meeting backgrounds, active employee QR validation, company-controlled employee profiles, inactive-profile warnings when an employee is deactivated, and admin review.
No. CardIQ does not analyze video/audio, does not detect deepfakes, and does not guarantee the meeting participant is real. It adds a company-controlled verification layer through branded meeting backgrounds, active employee QR validation, inactive-profile warnings, and admin review.
In the current setup, CardIQ can show employee or company booking links, or generate an email meeting request from the verified employee profile. Automatic Teams or Zoom meeting creation requires calendar/meeting API integration and admin consent, which is a future integration option.
The meeting QR proves that the QR links to a CardIQ employee profile and can show whether that profile is active and company-controlled. It does not prove the person in the video is physically the same person or guarantee they are real. If the employee is deactivated, the profile shows an inactive warning.
CardIQ uses company scoping, RBAC, audit logging, security alerts, admin MFA foundation, manual universal logout/session revocation, and safe metadata handling. Sensitive values like secrets, tokens, API keys, OAuth payloads, cookies, session IDs, and raw diagnostic data should never be exposed.
Role-based access control limits access based on role and company scope, such as Super Admin, Company Admin, staff, and employee access.
Yes, the mobile app supports business card OCR on Android to help capture lead/contact details from physical cards. Users can review and edit details manually before saving. Business card OCR is available on Android. You can still enter lead details manually.
Available capabilities, subject to plan, installed database migrations and workspace configuration, include the identity audit ledger, Enterprise security alerts and notifications, manual session revocation, administrator MFA, and review-recommended messaging. Confirm each control is enabled for the workspace before relying on it. Expanded risk checks remain roadmap work.
CardIQ offers Free, Pro, and Enterprise plans. Free supports up to 3 active employee profiles with essential digital card and identity-sharing features, Pro adds advanced CardIQ tools with annual pricing, and Enterprise adds full CardIQ and AttendanceIQ capabilities.
The Free plan supports up to 3 active employee profiles with essential digital card and identity-sharing features. Advanced branding, integrations, analytics, and enhanced identity governance require Pro or Enterprise.
Pro is currently offered internationally at $3.99 per user per month, billed annually at $47.88 per user. The standard displayed price is $9.99 per user per month. In Egypt, local Pro pricing is EGP 49.99 per user per month, billed annually at EGP 599.88 per user.
Free supports up to 3 users with essential digital identity and card sharing. Pro adds advanced branding, identity controls, analytics, leads, integrations, and company-managed employee profiles at the current annual Pro pricing. Enterprise is contact sales for enterprise controls, custom limits, and full AttendanceIQ.
CardIQ is built for HR, IT, Sales Operations, Compliance teams, and company admins that need a consistent way to manage employee-facing identity and contact details.
Yes. Company admins manage employee profiles, company branding, templates on eligible plans, and profile approval workflows so public information stays aligned with company policy.
Admins can disable or control employee profiles, QR profiles, and company-issued cards when an employee leaves or changes roles. If an employee is deactivated, the public profile and meeting QR flow will not be presented as active and will show a clear inactive-profile warning.
Yes. CardIQ employee profiles can include lead capture so visitors can send inquiries from a digital business card to the company workflow.
Yes. CardIQ supports secure webhook delivery for lead data so eligible company workspaces can route captured leads toward CRM tools and internal sales workflows.
CardIQ is a Corporate Digital Identity Control Platform. For enterprises it focuses on centrally managed employee identity, lifecycle control, public verification paths, governance, deployment flexibility, and integration with business systems where supported. See the Enterprise Documentation for details.
The company controls the professional identity it issues, including managed fields and public status. Employee access does not override authorized administrator governance.
Self-hosted and dedicated-cloud arrangements may be available through separate enterprise scoping and contract. Availability, responsibilities, updates and support must be confirmed with CardIQ; they are not automatic entitlements.
CardIQ has company-scoped API workflows and signed lead webhooks where configured. It does not currently provide native SCIM provisioning or a native Microsoft Entra ID provisioning connector. Any custom API integration requires confirmed scope.
Company lifecycle controls restrict normal workspace operations and active company-identity presentation according to the applied state. This workspace-level lifecycle is separate from deactivating one employee.
No. CardIQ supplies company-controlled professional-identity and active/inactive signals where enabled. It is not KYC, government or biometric verification, deepfake detection, or universal fraud prevention.