Trust, evidence & privacy

The national trust infrastructure for the healthcare workforce.

This page is maintained by the Credential Nexus team to explain how credential information is classified, who can see it, and what our verification results do and do not mean. It describes controls that are live in the product today — it is not an independent audit or a certification.

Claims are not verifications
Self-reported claim

Information a professional entered themselves. It is labelled as a claim and carries no verification badge, no matter how complete it looks.

Source-verified evidence

A named authority was queried and returned a result. Every verified item shows the source, what it returned, and the exact retrieval timestamp.

Point-in-time, not perpetual

A verification describes what a source said at the moment it was retrieved. Status can change afterwards, which is why monitoring and re-checks exist.

A credential is only shown as verified when both an authoritative source record and a recorded verification decision exist for it. A legacy status field, a self-entered “verified” value, or an uploaded document is never sufficient on its own.

Three visibility tiers
Public

Credential title, jurisdiction, issuing authority, public status, expiration, and the source and timestamp behind it. Nothing else — no date of birth, contact details, documents, employment history, or compliance findings.

Employer-authorized

Fuller credential detail released only where the professional has granted active, scoped consent, or where an open verification case or lawful monitoring enrollment covers the requested scope. Consent can be revoked, and revocation takes effect immediately.

Restricted compliance

Sanction, exclusion and adverse-action material handled under source-specific access rules. It is never rendered on public pages, QR verification, search results, or exports, and is limited to authorized reviewers acting for a permitted purpose.

Professional consent, correction and appeal rights
  • Consent is scoped and revocable. Employers request access for stated scopes and a stated purpose. You choose whether to grant it, and you can revoke it at any time from your Professional Passport.
  • You can dispute anything on your record. Every credential entry carries a correction request. Submitted corrections go to a platform reviewer who accepts, rejects, or asks for more information.
  • History is appended, never erased. The disputed entry, the correction, and the reviewer’s decision all remain in your credential history, and you are notified when a decision is recorded.
  • You can see who looked. Consent decisions, verification cases and monitoring enrollments touching your record are visible to you.
Source attribution and data limitations
  • Every result names its source and time. Where a source could not be reached, the result is shown as unable to verify rather than being inferred or filled in.
  • NPDB is limited by law and by design. National Practitioner Data Bank material is only available to eligible querying entities under their own agreements and permitted purposes. Credential Nexus does not resell, republish, or expose NPDB content; where such a check applies, it is marked as requiring authorized access and is handled outside public surfaces.
  • Coverage varies by jurisdiction and source. Some boards and issuers publish machine-readable data, others require manual or authorized workflows. The registry of sources and their current integration state is shown inside the product.
  • We do not replace the primary sources. State licensing boards, Nursys, certification issuers and the NPDB remain the authorities of record.
Platform controls
Authentication

Email and Google sign-in with session-scoped access. Roles are stored separately from profiles so permissions cannot be self-escalated.

Data isolation

Every credential, document, and message row is access-scoped to its owner. Requests run as the signed-in user, never with elevated privileges.

Immutable evidence

Source records are written once. Ordinary users cannot edit or delete them, so a verification result cannot be quietly rewritten after the fact.

Controlled sharing

Shared credential links carry an expiry window and can be revoked at any time. Employer discovery is strictly opt-in.

Audit trail

Verification scans, consent decisions, document shares, dispositions and administrative actions write append-only audit records.

Ongoing review

The platform is scanned for access-policy and configuration issues, and findings are remediated as part of normal delivery.

Shared responsibility

Credential Nexus provides the platform controls described above. Account owners are responsible for who they invite, the roles they grant, the accuracy of the credentials they submit, and the links they choose to share. Employers remain responsible for their own hiring, credentialing and privileging obligations, including any primary-source verification their accreditor or regulator requires.

Reporting a concern

If you believe you have found a security issue, need a record corrected, or want your data deleted, contact the account owner through in-app messaging or submit a correction request from your passport. Abusive messages can be reported directly from any conversation and are reviewed by platform moderators.

What we do not claim. Credential Nexus does not assert SOC 2, ISO 27001, HIPAA or PCI certification, does not claim complete nationwide coverage of every credential or jurisdiction, does not guarantee that any individual verification will succeed, and does not eliminate compliance risk. Where the product is described as “audit-ready,” that refers to the append-only audit logging and export capabilities built into the platform, not to a completed third-party audit.