profiq
← Back

Verification Methodology

Last updated Version 1.0 · July 2026

This page states exactly what a Profiq verification means, mechanism by mechanism. It exists so that anyone relying on a Verified record, a recruiter, an investor, a board, can see the proof standard for themselves rather than take our word for it. If our mechanisms change, this document and its version number change with them.

The four states of a record

Every professional record on Profiq is in exactly one state. Claimed: the person said it; nothing checked. Pending: a matching record was found in a public registry, awaiting review. Corroborated: a real public record exists and the person affirmed it is theirs, but ownership of the source has not been proven. Verified: the person demonstrated control of the source itself. Only Verified records appear on shared verified records and public profiles. A name match plus a click can never reach Verified.

What Verified formally asserts

Verified means: at a recorded point in time, this person demonstrated control of the source that the record comes from, through one of the mechanisms below. It does not assert job titles, seniority, dates, degrees, or performance unless the mechanism specifically proves them, and each record on a shared page states what was proven and what was not. Every verification is timestamped, and shared records display the verification date so you can judge freshness yourself.

Employment: work-email control

We send a single-use link, valid 30 minutes, to an address at the employer's own domain. Free and disposable email providers are rejected. Only someone with an inbox inside the company can complete it. Proves: affiliation with the company's domain at verification time. Does not prove: title, dates, or seniority; those remain the person's claim and are labeled as such.

Education: institutional-email control

The same single-use link mechanism, restricted to academic domains (.edu and international academic suffixes). Proves: affiliation with the institution as a student, staff member, or alum. Does not prove: the degree, graduation year, or field of study.

Domain and website ownership

The person places a one-time code we issue in the domain's DNS records or a file at its web root, and we check for it directly. Proves: control of the domain's DNS or web root at verification time. When the domain belongs to a registered company on Profiq, this additionally marks their company affiliation as verified. Does not prove: any specific title at the company.

Identity providers and code accounts

Signing in through Google, Microsoft, Apple, or LinkedIn proves control of that account, and we record an identity verification only when the provider itself asserts the email is verified. A LinkedIn identity verification is an identity check only, never a claim about work history. GitHub sign-in additionally imports repositories exactly as GitHub reports them; it does not assert sole authorship. Microsoft or Google sign-in from a company-controlled work domain carries the same proof value as the work-email mechanism above.

Public registries

We search ORCID, Crossref, OpenAlex, USPTO, and SEC EDGAR for records matching the person's name. A match alone produces a Pending record. The person affirming “this is me” produces Corroborated, which never appears on shared verified records. Reaching Verified requires proof of control of the source account itself, for example placing a one-time code on their public ORCID record.

What we refuse to do

We do not compute invented scores. No blended “match probability,” no “success likelihood,” no percentile against a cohort that does not exist. Where we show a number, it is a literal count you can recount yourself, a cited public statistic with its source named, or arithmetic on inputs you provided. Where the evidence does not exist, the product says so instead of estimating. Self-reported preferences (target roles, salary targets) personalize what we surface but are never displayed as verified facts and never shown to third parties.

Auditability

Every shared verified record is delivered through a revocable, single-purpose link controlled by the record's owner. Opens and reliance affirmations are logged. Verification tokens are stored only as cryptographic hashes. Where a record originates from a public registry or filing, the record links the primary source so you can check it yourself.

Questions

If you are evaluating Profiq verifications for hiring, diligence, or compliance and need more detail than this page provides, contact us at ceo@theupcapital.com.