This page is maintained by the Credential Nexus team to explain how credential information is classified, who can see it, and what our verification results do and do not mean. It describes controls that are live in the product today — it is not an independent audit or a certification.
Information a professional entered themselves. It is labelled as a claim and carries no verification badge, no matter how complete it looks.
A named authority was queried and returned a result. Every verified item shows the source, what it returned, and the exact retrieval timestamp.
A verification describes what a source said at the moment it was retrieved. Status can change afterwards, which is why monitoring and re-checks exist.
A credential is only shown as verified when both an authoritative source record and a recorded verification decision exist for it. A legacy status field, a self-entered “verified” value, or an uploaded document is never sufficient on its own.
Credential title, jurisdiction, issuing authority, public status, expiration, and the source and timestamp behind it. Nothing else — no date of birth, contact details, documents, employment history, or compliance findings.
Fuller credential detail released only where the professional has granted active, scoped consent, or where an open verification case or lawful monitoring enrollment covers the requested scope. Consent can be revoked, and revocation takes effect immediately.
Sanction, exclusion and adverse-action material handled under source-specific access rules. It is never rendered on public pages, QR verification, search results, or exports, and is limited to authorized reviewers acting for a permitted purpose.
Email and Google sign-in with session-scoped access. Roles are stored separately from profiles so permissions cannot be self-escalated.
Every credential, document, and message row is access-scoped to its owner. Requests run as the signed-in user, never with elevated privileges.
Source records are written once. Ordinary users cannot edit or delete them, so a verification result cannot be quietly rewritten after the fact.
Shared credential links carry an expiry window and can be revoked at any time. Employer discovery is strictly opt-in.
Verification scans, consent decisions, document shares, dispositions and administrative actions write append-only audit records.
The platform is scanned for access-policy and configuration issues, and findings are remediated as part of normal delivery.
Credential Nexus provides the platform controls described above. Account owners are responsible for who they invite, the roles they grant, the accuracy of the credentials they submit, and the links they choose to share. Employers remain responsible for their own hiring, credentialing and privileging obligations, including any primary-source verification their accreditor or regulator requires.
If you believe you have found a security issue, need a record corrected, or want your data deleted, contact the account owner through in-app messaging or submit a correction request from your passport. Abusive messages can be reported directly from any conversation and are reviewed by platform moderators.