IVQA verification answers one question for the person holding a document: does the issuing organization currently recognize this document as valid?
The credential record#
When you save a document in your dashboard, IVQA creates a credential record for it. The record stores:
- the public ID printed on the document (
IVQA-DOC-…,IVQA-CER-…,IVQA-DIP-…,IVQA-BDG-…); - the type and title of the document;
- a snapshot of the holder's identity at issuance (name, student or employee UID, program or department, level);
- the issuing organization;
- the issue date and, when one applies, the validity period;
- the current status: valid, pending, expired or revoked;
- for uploaded files, a SHA-256 fingerprint of the file.
The snapshot matters: editing or even deleting the student later does not change what the credential says about who it was issued to.
The QR code#
The QR code placed on the document encodes only the verification URL of that credential, signed by IVQA. Nothing personal is stored in the code. See QR code verification.
The lookup#
- Verifier scans the QR code (or enters the code on check.ivqa.org)
- IVQA looks up the credential by its public ID
- IVQA checks the credential status and the validity dates
- IVQA checks the state of the underlying document (published, draft, revoked)
- The page shows one verdict and the credential details
The verdict is computed at the time of the scan:
- If no published credential matches the code, the page says Not found. Draft and unpublished documents fall in this case: a document that was never published has no public existence.
- If the credential is revoked, the page shows REVOKED with the reason, and nothing else about the holder.
- If the validity period has ended, the page shows EXPIRED; if it has not started yet, NOT YET VALID.
- Otherwise the page shows VALID with the document details.
What a verifier sees#
For a valid document the page shows the document type and title, the issuing institution or company, the holder's name and UID, the public ID, the issue date and, for students, the program and level. Two small marks can appear: Signed QR: OK when the scanned link carried a correct IVQA signature, and File integrity verified when a fingerprint of the uploaded file is on record.
For a revoked document the page shows only the revoked banner and the reason.
What a verifier does not see#
- Contact details, national ID numbers or other personal fields of the student or employee.
- The document file itself. The verification page does not serve the PDF.
- Anything about other documents of the same person, unless the verifier opens the person's own page from their UID.
Every scan is logged#
Each visit of a verification page is recorded with its result, so your organization can see verification activity in Analytics.