Stop holding
everyone’s documents.

Issue a role against an identity someone else already verified. It opens what the role needs, and closes the day the role ends.

Free for the first ten people. No card, and no call unless you want one.

Businesses, communities, landlords and public bodies. One account type.

In production across Club TXP, Servicea, Fluxa, SeeYo Soon and Qlavia — and the brands inside each.

Nordkap AB
ORG-4417 · 34 PEOPLE
0documents held
WORK Sara LindqvistENGINEERING · SINCE MAR 2024 Active
WORK Tomas EkCONTRACTOR · UNTIL 30 NOV Active
WORK Alex JohanssonLEFT 4 SEPTEMBER Ended
SITE Byggpartner Nord ABSUPPLIER · 6 PEOPLE ADMITTED Active
34 active · 11 ended this yearNothing stored here

Who this is for

You run something with people attached to it.

A businessEmployees and contractors
A schoolStudents, staff and visitors
A landlordTenants and the trades who service the building
A communityMembers and volunteers
A public bodyCitizens, patients and case workers
A clinic or a clubAnyone who has to prove who they are

They need to get into buildings, systems and records. They need to prove who they are before you let them. And when they leave, all of it has to stop. Today that means you keep a copy of their passport and hope somebody remembers to close the door.

Identity documents on fileHR SHARED DRIVE
passport_alex_j.pdf Left the company · 2021 Held
ID_scans_contractors_2019 14 files · nobody knows who Held
onboarding_docs.zip Emailed twice · 2023 Held
Retention policy: noneYour liability
01 · The drawer

You are holding copies of other people’s lives.

Every person you ever onboarded left a passport scan behind. Employees, contractors, tenants, volunteers. Some left years ago. Nobody has looked at the folder since.

It is worth nothing to you and everything to whoever breaches it. And you checked each one by hand, for a document another organisation had already verified that week.

Alex JohanssonLEFT 4 SEPT
Building entry, floor 3 Badge never returned Open
Shared drive · Finance Account not disabled Open
Supplier portal Nobody knew it existed Open
Days since departure: 41Still inside
02 · The leaver

Access outlives the person.

Someone leaves on a Friday. IT disables what it knows about. The door badge, the supplier portal, the folder nobody documented — those stay open until somebody remembers.

A role that ends when the employment ends does not need remembering. It closes because the fact underneath it closed.

Every day an old account stays open is a day you cannot account for. Ten people costs nothing and takes an afternoon.

Open an account

One account. Two directions.

Your people, or your customers.

The same mechanic points two ways. Inward, it gives your team a verified identity tied to a role. Outward, it lets people arrive at your product already verified, without a form.

First day

Issue a Work ID. Every system opens.

The employee scans once. The role is issued against their own verified identity and every system the role needs is available before lunch.

Contractor

Admit a supplier's people. Without holding their passports.

A contractor is verified once, by SafeQloud, and admitted against a role with an end date. You never see a document.

Exit

The role ends. So does everything attached to it.

Nobody files a ticket. The employment ended, so the Work ID ended, so every door and system it opened is closed the same second.

Customer

They arrive already verified. No form.

A customer scans instead of filling in a registration. You receive what they approved, logged and revocable, and nothing you have to store.

Swipe, drag or use the arrows

Before you ask

The questions that decide it.

Four answers a technical buyer needs before the second meeting.

We would rather answer these now than have you find out in month three.

One of the answers is no

We already have an identity provider.

Then keep it. Entra, Okta and Google Workspace authenticate people you have already hired and already verified. They are good at that.

They cannot verify a stranger. They have no concept of a passport issued by a country. And they have no place for the people who are not on your payroll — contractors, tenants, students, members, visiting trades. SafeQloud does the verifying. Your provider keeps signing people in.

What does it connect to?

A REST API with a sandbox, and SDKs for Node, Python, PHP and Ruby. Verification is one call: POST /v1/identity/verify returns whether the person is verified and what they approved you to see.

Nothing has to be replaced. Most organisations start by adding it to one flow — onboarding, or a door — and leave the rest alone.

Where does the data sit?

In the EU. Identity documents are verified against the issuing authority and the result is held against the person’s own identity, not against your organisation.

You receive answers, never files. There is nothing of theirs on your systems to locate, secure or delete.

What do we sign?

A data processing agreement. SafeQloud is a processor under GDPR. The agreement names our sub-processors and the breach notification window. It says what happens to the record if you leave.

Ask and we will send it before you open an account, not after.

Where we are

What we have, and what we do not.

You are being asked to trust us with identity. The least we can do is say plainly where we have got to.

Running in production Yes Across Club TXP, Servicea, Fluxa, SeeYo Soon and Qlavia, and the brands inside each.
Institutions in production 5 Independent companies, separately held, sharing a founder. Each chose SafeQloud rather than building identity itself.
Data processing agreement Available Sent on request, before you commit to anything.
EU data residency Yes Verification and the consent record are held in the EU.
SOC 2 / ISO 27001 Not started If your procurement requires either, we are not ready for you today.
Independent penetration test Planned Not yet carried out. We will publish the result when it is.

If none of the noes are blockers for you, the first ten people cost nothing. Send this page to whoever signs it off

Open an account

Not sure which applies to you

Inward, outward, or both.

Most organisations start on one side and add the other later. One account covers both — you do not choose at sign-up.

What you getInwardOutward
Work ID for employees and contractorsYes
Physical access — doors, rooms, sitesYes
Document access with an audit trailYes
Access that ends when the role endsYes
Customer sign-up without a formYes
Identity-verified checkoutYes
Sign-in for your own platformYes
Consent collection, logged and revocableYesYes
API access and documentationYesYes
Dashboard and consent managementYesYes

Setup

Live in three steps. No integration fee.

Step 1Open the account

Two minutes, no card. It gives you the dashboard and the API, whichever side you start on.

Step 2Issue, or integrate

Inward: issue Work IDs and place codes at the doors and documents that need them. Outward: connect the API — the docs cover every endpoint.

Step 3Go live

Your people scan. Your customers arrive verified. Everything is logged, governed and revocable from the dashboard.

What it costs

Organisations pay. People never do.

The identity belongs to the person and always will. What is priced is what we do for you — verifying, issuing, carrying consent, and keeping the record.

SafeQloud
Free
up to 10 verified people

Work IDs, QR deployment, consent management, dashboard and full API with sandbox. No card required.

Enough to run a small team
SafeQloud
from €29
per month, 11–1,000 people

Everything above, plus advanced audit logs and role-based access. Scales with people and API volume.

Enterprise · custom SLA
Brands
Separate
priced by each brand

SQ Pay, SQ Check-In and the rest are independent companies built on SafeQloud. Activate from your account; they bill you directly.

Inward or outward, per brand

What it will never do

The limits protect you too.

You never hold the documents.

You receive a verified answer, not a passport scan. There is no folder to secure, no retention policy to write, and nothing to lose in a breach.

You see only what you asked for.

A request states its scope before the person answers it. Their other documents, their other roles and their other relationships are not visible to you.

The person can end it.

Consent runs from their side as well as yours. That is not a weakness in your access — it is what makes their data lawful for you to hold at all.

We do not sell what we see.

Not your people, not your customers, not your volumes. SafeQloud is paid by the organisations that use it and by nothing else.

Organisation account

Verified people. Nothing in your drawer.

Free for the first ten. Two minutes to open. No document you have to keep.

Free for the first ten people. No card, and no call unless you want one.