CardIQ FAQ

Frequently asked questions about CardIQ

Clear answers for HR, IT, Sales Operations, Compliance, and company admins evaluating CardIQ for employee identity management and corporate digital business cards.

Read CardIQ Enterprise Documentation · Developer & API documentation · Enterprise SSO documentation

What CardIQ helps companies manage

Corporate digital business cards

Publish company-controlled business cards with branded QR code sharing, secure vCard downloads, and email signature support.

Employee profile management

Admins manage profile details, company branding, premium templates on eligible plans, and approval workflows.

Lead and CRM workflow

Profiles can capture leads and deliver them through secure webhooks to CRM tools and sales operations workflows.

Offboarding protection

Admins can disable or control profiles when employees leave, helping keep public contact identity current.

Paid workspace tools

Paid plans can include Company Contacts, secure employee messaging, advanced analytics, branded QR codes, and easy integration workflows.

Arabic and English support

CardIQ supports Arabic and English public content and product flows for bilingual company teams.

Compare CardIQ pricing, review corporate identity management, learn about employee offboarding control, see branded QR code sharing, or request a demo.

Understanding CardIQ modules

Employees and Company Users

Employees are managed identities and cards; Company Users are authenticated workspace accounts with roles.

Messages and Company Highlights

Messages are private and internal; Highlights are official announcements that may reach eligible public audiences.

Notifications and Messages

Notifications contain user-specific official updates; employee conversations remain in Messages.

Directory and Contacts

The Directory contains active employees; Contacts contains external or business relationships.

Identity Dashboard and Security Alerts

The dashboard summarizes overall health; alerts are individual events requiring review.

Analytics Overview and detailed modules

Analytics Overview consolidates available high-level metrics; Card & Profile Analytics details engagement; Lead Analytics opens the detailed Lead Performance Analytics report; Leads CRM supports operational follow-up.

API Keys and CRM Webhooks

API Keys authenticate generic API access; CRM Webhooks configure outbound CRM synchronization.

CardIQ FAQ

What is CardIQ Communication Verification?

It checks whether an email, mobile number, WhatsApp number, landline, or website is currently authorized by a selected company. The company must be selected first, and CardIQ returns only Verified or Not Verified without revealing employee identity. See the Communication Verification guide.

Can CardIQ tell me who owns a phone number?

No. CardIQ does not provide reverse lookup or disclose an employee or company behind an arbitrary number. You must first select the organization you want to verify the number against.

Does Verified prove who is holding the phone?

No. Verified means the channel is currently registered by the selected organization in CardIQ as an authorized corporate communication channel. It does not prove who is physically using the device at that moment.

Does Not Verified mean the sender is definitely a fraudster?

No. It means CardIQ could not confirm the channel as currently authorized by the selected organization. Verify sensitive requests through another trusted company channel.

Does CardIQ verify WhatsApp through Meta?

No. CardIQ checks the number against organization-approved CardIQ records. It does not issue or claim Meta or WhatsApp verification and does not provide a WhatsApp badge.

Does CardIQ provide an API?

Yes. CardIQ provides a deliberately limited company-scoped server API for approved integrations, selected public read helpers, and signed outbound lead webhooks where configured. See the Developer & API Documentation hub for its current scope and limits.

How is CardIQ API access authenticated?

The company server API uses a secret in the X-API-Key header. Bearer tokens are separate and serve first-party employee/mobile app routes; the two credential types are not interchangeable.

Are CardIQ APIs company-scoped?

Yes. The server derives the company from the authenticated API key, and the documented routes do not let callers select another tenant.

Does CardIQ support webhooks?

Yes. An eligible configured company can send the outbound lead_created event to one HTTPS receiver, and an administrator can send webhook_test. CardIQ does not expose a general inbound webhook API.

Are CardIQ webhooks signed?

Yes. CardIQ signs the exact raw body with HMAC-SHA256 using the company secret and sends the digest in X-CardIQ-Signature.

Is the CardIQ API the same as SCIM?

No. CardIQ does not currently provide native SCIM provisioning; its documented API is a limited company-scoped integration surface.

What happens to API access when a company is suspended?

Company-scoped API operations are blocked with HTTP 403 and can return COMPANY_SUSPENDED with a public-safe message that does not expose internal reasons or notes.

What server does CardIQ require?

CardIQ requires a web-hosting environment with PHP and a MySQL or MariaDB database, plus appropriate web-server configuration, PHP extensions and file permissions. Confirm exact versions and deployment requirements with CardIQ before rollout.

Does CardIQ provide automatic backups?

The application does not currently include a managed automatic-backup service. The hosting or operations team is responsible for scheduling database and file backups and testing restoration according to the agreed deployment plan.

Does CardIQ support Nginx?

CardIQ can be deployed behind Nginx when it is correctly configured for PHP execution, route handling and protection of sensitive files. The repository does not provide a production-ready Nginx configuration, so the server configuration must be reviewed and tested for the deployment.

Does CardIQ support Enterprise SSO?

CardIQ currently provides a company-level configuration foundation for SAML metadata. It does not yet activate automatic SSO redirect or enforced login, and email/password login remains active.

Does CardIQ support SAML?

CardIQ supports SAML metadata configuration, including provider type, Entity ID, SSO URL and certificate fingerprint/reference. This is a configuration foundation, not a completed or enforced SSO authentication flow.

Does CardIQ support Microsoft Entra ID?

CardIQ supports company-bound Entra OIDC sign-in for pre-mapped users and a read-only preview of explicitly selected groups where configured. The preview uses User.Read.All and GroupMember.Read.All application permissions and never creates, updates, links, or deactivates employees.

Does CardIQ support Okta?

Okta can conceptually act as a SAML identity provider, but CardIQ does not currently claim a native Okta integration or tested compatibility.

Does CardIQ support SCIM?

Native SCIM provisioning and deprovisioning are not currently available. A custom API integration must not be described as SCIM support.

Is SSO currently enforced?

No. Automatic SSO redirect and enforced SSO login are not currently active. Enable and enforce controls store configuration readiness and future policy intent only.

Does SSO automatically provision employees?

No. SSO controls authentication and login; provisioning creates, updates or deactivates accounts. SAML SSO does not automatically mean SCIM provisioning.

What is the CardIQ Public Company Profile?

The CardIQ Public Company Profile is a company-controlled digital identity hub that brings together official company links, contact channels, products and services, locations, representatives, employee identities, and corporate resources in one public destination.

Is CardIQ like Linktree for companies?

CardIQ can provide a Linktree-style company destination, but it goes further. Linktree organizes links, while CardIQ is designed to organize and control company identity, official representatives, employee identities, and company information, with verification where enabled and supported.

Can a company share one official CardIQ link?

Yes. A company can use its public CardIQ profile as an official URL that can be shared directly or through a QR code. The profile can centralize approved company information, links, contacts, representatives, and employee cards.

Does CardIQ verify every company and employee?

No. Verification depends on the verification features enabled for the company and the applicable setup. CardIQ should not be interpreted as universally verifying every company, employee, or user.

How does the Public Company Profile help prevent outdated representation?

Because the profile is managed by the company, official links, representatives, employee identities, and company information can be updated centrally. This helps reduce reliance on outdated or unmanaged information.

What is Corporate Digital Identity Control?

It is company governance of outward-facing employee identity across profiles, digital business cards, signatures and meeting touchpoints, including authorization, updates and deactivation.

Does CardIQ verify government identity?

No. CardIQ verifies corporate authorization and company-controlled professional identity; it does not provide government-grade legal identity verification.

Can CardIQ replace Microsoft Entra ID or Okta?

No. IAM systems control access inside an organization. CardIQ complements them by controlling how employees represent the organization externally.

How does DNS company verification work?

A company publishes a CardIQ-provided DNS TXT record. CardIQ checks that record and, when it matches, presents the domain as verified.

What is the Identity Dashboard?

The Identity Dashboard provides administrators with a real-time overview of their organization's identity health, including verification status, trusted domains, QR protection, security alerts, meeting readiness, and employee identity metrics.

How is the Identity Health Score calculated?

The CardIQ Identity Health Score combines verified employee coverage, trusted domain configuration, meeting readiness, signature configuration, LinkedIn connection coverage, and penalties for reviews, frozen identities, and open security alerts. The dashboard shows the exact contribution of each signal.

What is CardIQ?

CardIQ is a Corporate Digital Identity Control Platform that helps organizations manage company-controlled employee identities, digital business cards, public employee profiles, email signatures, meeting identity, and lifecycle control.

What does LinkedIn connection mean in CardIQ?

Employees can connect their LinkedIn profile. CardIQ may show “LinkedIn profile connected,” display name, and optional public LinkedIn URL. This adds professional context and supports admin review, but it is not official LinkedIn employee verification.

What are Company Highlights?

Company Highlights are professional announcements published by an authorized company administrator. They may include company news, product launches, partnerships, awards, certifications, or important updates, and appear on employee CardIQ profiles according to the selected target audience.

What does Follow official updates mean?

Following official updates lets a signed-in CardIQ user receive company-controlled public announcements from an official CardIQ company profile. It does not create an employment relationship or a social-network connection.

What are Verified Highlights?

Verified Highlights are professional achievements such as completed projects, certifications, promotions, awards, or events submitted by employees and approved by an authorized company administrator before appearing on the public CardIQ profile.

How does CardIQ help reduce impersonation and social engineering risks?

CardIQ uses signature verification links, QR validation, company-controlled employee profiles, branded virtual meeting backgrounds with active employee QR, and admin review to help recipients confirm identity details and reduce risk.

How do company email signature templates work?

Company Admins can publish a controlled email signature template that uses approved employee and company information. The same design is then generated automatically for eligible employees, while employee-specific details such as name, title, contact information, QR code, and profile link remain personalized.

What is signature verification?

Email signatures can include a CardIQ verification link or QR code so recipients can validate the employee profile through CardIQ.

How do I report a suspicious identity?

Use Report suspicious identity on the public profile or signature verification page. CardIQ sends the report for admin review when available.

Why do I need to enter the sender email?

CardIQ asks you to compare the sender email from your email app with the CardIQ signature profile. This helps confirm that the email sender matches the company-controlled employee identity linked to the signature.

What does signature risk assessment mean?

CardIQ signature verification checks whether the signature links to an active company-controlled profile and whether key trust signals, such as company domain verification, are available. If the company/domain is verified and the profile is active, the risk assessment can show low risk. If signals are missing, it recommends review.

What is a branded virtual meeting background?

Companies can use branded meeting backgrounds with active employee QR or validation links to add a company-controlled verification layer during online meetings.

What is Employee Identity Freeze?

Employee Identity Freeze lets authorized admins temporarily place an employee profile under review. During the freeze, CardIQ avoids presenting the profile, signature, or meeting QR as low risk and hides sensitive actions such as booking or vCard download.

How do I clear QR Under Review?

Authorized admins can open the related QR abuse alert and use Resolve and clear QR review after completing their investigation. This clears the review state without deleting the QR or deactivating the employee.

What is Trusted Domain Policy?

Trusted Domain Policy lets a company define which email domains are approved for employee identities. After a company admin verifies their registration email, CardIQ can automatically add that email domain as a trusted domain. If an employee email does not match the trusted domain policy, CardIQ can show Review recommended instead of presenting the identity as low risk.

What is an inactive trusted domain?

An inactive trusted domain is retained for audit history but is not used by CardIQ to trust employee email addresses or determine identity status.

Why does my workspace show Review recommended?

Review recommended means one or more identity trust signals need admin attention, such as domain verification, trusted domain policy mismatch, inactive workspace, or frozen employee identity. Admins can review the reason in the workspace header or Company Configuration.

Does this prove domain ownership?

No. A trusted domain created from a verified admin email means the admin verified an email address on that domain. Full domain ownership verification requires a separate DNS verification step.

What is Meeting Identity Check?

Meeting Identity Check is a short CardIQ guidance section on the employee QR/profile page. It explains safe signals such as active employee status, company-controlled profile, QR/profile validity, company domain verification when available, and whether admin review is recommended. It does not analyze video/audio or prove the meeting participant is real.

How does CardIQ protect online meetings?

CardIQ helps reduce meeting impersonation risk with branded virtual meeting backgrounds, active employee QR validation, company-controlled employee profiles, inactive-profile warnings when an employee is deactivated, and admin review.

Can CardIQ detect deepfakes?

No. CardIQ does not analyze video/audio, does not detect deepfakes, and does not guarantee the meeting participant is real. It adds a company-controlled verification layer through branded meeting backgrounds, active employee QR validation, inactive-profile warnings, and admin review.

Can CardIQ generate Teams or Zoom links automatically?

In the current setup, CardIQ can show employee or company booking links, or generate an email meeting request from the verified employee profile. Automatic Teams or Zoom meeting creation requires calendar/meeting API integration and admin consent, which is a future integration option.

What does the meeting QR prove?

The meeting QR proves that the QR links to a CardIQ employee profile and can show whether that profile is active and company-controlled. It does not prove the person in the video is physically the same person or guarantee they are real. If the employee is deactivated, the profile shows an inactive warning.

How does CardIQ protect employee data?

CardIQ uses company scoping, RBAC, audit logging, security alerts, admin MFA foundation, manual universal logout/session revocation, and safe metadata handling. Sensitive values like secrets, tokens, API keys, OAuth payloads, cookies, session IDs, and raw diagnostic data should never be exposed.

What is RBAC in CardIQ?

Role-based access control limits access based on role and company scope, such as Super Admin, Company Admin, staff, and employee access.

Does CardIQ support business card OCR?

Yes, the mobile app supports business card OCR on Android to help capture lead/contact details from physical cards. Users can review and edit details manually before saving. Business card OCR is available on Android. You can still enter lead details manually.

What security features are available now?

Available capabilities, subject to plan, installed database migrations and workspace configuration, include the identity audit ledger, Enterprise security alerts and notifications, manual session revocation, administrator MFA, and review-recommended messaging. Confirm each control is enabled for the workspace before relying on it. Expanded risk checks remain roadmap work.

What plans does CardIQ offer?

CardIQ offers Free, Pro, and Enterprise plans. Free supports up to 3 active employee profiles with essential digital card and identity-sharing features, Pro adds advanced CardIQ tools with annual pricing, and Enterprise adds full CardIQ and AttendanceIQ capabilities.

What is included in the Free plan?

The Free plan supports up to 3 active employee profiles with essential digital card and identity-sharing features. Advanced branding, integrations, analytics, and enhanced identity governance require Pro or Enterprise.

How much does Pro cost?

Pro is currently offered internationally at $3.99 per user per month, billed annually at $47.88 per user. The standard displayed price is $9.99 per user per month. In Egypt, local Pro pricing is EGP 49.99 per user per month, billed annually at EGP 599.88 per user.

Compare Free, Pro & Enterprise.

Free supports up to 3 users with essential digital identity and card sharing. Pro adds advanced branding, identity controls, analytics, leads, integrations, and company-managed employee profiles at the current annual Pro pricing. Enterprise is contact sales for enterprise controls, custom limits, and full AttendanceIQ.

Who is CardIQ built for?

CardIQ is built for HR, IT, Sales Operations, Compliance teams, and company admins that need a consistent way to manage employee-facing identity and contact details.

Can admins control employee profile updates?

Yes. Company admins manage employee profiles, company branding, templates on eligible plans, and profile approval workflows so public information stays aligned with company policy.

What happens when an employee leaves the company?

Admins can disable or control employee profiles, QR profiles, and company-issued cards when an employee leaves or changes roles. If an employee is deactivated, the public profile and meeting QR flow will not be presented as active and will show a clear inactive-profile warning.

Can CardIQ capture leads from digital business cards?

Yes. CardIQ employee profiles can include lead capture so visitors can send inquiries from a digital business card to the company workflow.

Does CardIQ support CRM integrations?

Yes. CardIQ supports secure webhook delivery for lead data so eligible company workspaces can route captured leads toward CRM tools and internal sales workflows.

What is CardIQ Enterprise?

CardIQ is a Corporate Digital Identity Control Platform. For enterprises it focuses on centrally managed employee identity, lifecycle control, public verification paths, governance, deployment flexibility, and integration with business systems where supported. See the Enterprise Documentation for details.

Who owns employee identity in CardIQ?

The company controls the professional identity it issues, including managed fields and public status. Employee access does not override authorized administrator governance.

Can CardIQ be self-hosted?

Self-hosted and dedicated-cloud arrangements may be available through separate enterprise scoping and contract. Availability, responsibilities, updates and support must be confirmed with CardIQ; they are not automatic entitlements.

Does CardIQ support APIs, webhooks, SCIM or Microsoft Entra ID?

CardIQ has company-scoped API workflows and signed lead webhooks where configured. It does not currently provide native SCIM provisioning or a native Microsoft Entra ID provisioning connector. Any custom API integration requires confirmed scope.

What happens when a company is suspended or frozen?

Company lifecycle controls restrict normal workspace operations and active company-identity presentation according to the applied state. This workspace-level lifecycle is separate from deactivating one employee.

Does CardIQ guarantee identity authenticity or prevent all fraud?

No. CardIQ supplies company-controlled professional-identity and active/inactive signals where enabled. It is not KYC, government or biometric verification, deepfake detection, or universal fraud prevention.