What IVQA does#
- Signed QR codes. The link inside every QR code carries an IVQA signature; the verification page shows Signed QR: OK when it is intact, so a verifier can tell an IVQA-issued code from a typed or forged link.
- Public pages show the minimum. No contact details, identifiers or files are exposed; revoked documents show only the revoked banner. Drafts have no public existence.
- Immutable credential snapshots. A document's public record is fixed at issuance; editing or deleting the person later does not rewrite it.
- Hashed secrets. API tokens are shown once and stored hashed. Passwords are never displayed.
- Throttling. Sign-in attempts are throttled per email and per IP; the API is rate-limited per token; public verification pages are rate-limited per visitor.
- Audit trail. Revocations, restorations, QR generation and token operations are logged with the acting user.
- Form protection. Dashboard forms are protected against cross-site request forgery. A 403 Forbidden on a form usually means the protection token expired: refresh the page and try again, with cookies enabled.
What we recommend#
Enable two-factor authentication
For every user with the Owner or Admin role at least. See Two-factor authentication.Apply least privilege
Give colleagues the smallest role that fits: Contributor for viewing and QR creation, Manager for day-to-day issuance, Admin only when user administration is needed. See Administrators and roles.Remove access promptly
Remove users who leave the organization from Users & Roles, and cancel invitations that were not accepted.Scope and expire API tokens
One token per integration, minimal scopes, an expiry date, and revocation when the integration is retired. See Authentication and API tokens.Use revocation, not deletion, for withdrawn documents
Revocation keeps an auditable trace and shows REVOKED to verifiers; deletion removes the record.Sign out on shared computers
Use Log out from the dashboard header.
Reporting a security concern#
If you believe an account or a document has been misused, contact support with the public IDs involved. Revoke affected credentials from Status & Revocations right away; you can restore them later if the concern is cleared.