FilPass Document Verification FAQs
Common Questions
Q1: Can your system support public QR scanning with a camera in one click?
A: Yes. This has been a core FilPass feature for over 6 years—any standard smartphone camera or QR scanner opens the verification page directly.
Q2: Why can a fake still appear "Verified" when scanned by a generic QR scanner?
A: Any actor can generate a QR code that points to a lookalike page showing "verified." That's a limitation of QR codes generally, not FilPass. No technology can stop someone from printing a QR that redirects to their own fake site.
Q3: How does FilPass prevent that?
A: While we cannot control how a QR code is generated, we can control how it's validated. The recommended flow is:
- Verifiers are directed to scan only via the official Issuing Authority verification page
- Only credentials genuinely issued through the Issuing Authority's page will show as Verified.
- Anything else will show as Tampered.
- An upcoming feature will let Issuing Authorities restrict verification to the official page as the sole permitted method — closing the loophole entirely.
Q4: Besides QR scanning, are there other ways to verify a document?
A: Yes. Every PDF issued by FilPass can be verified by dragging and dropping the file onto the verification page. Any edit — even a single character — breaks the cryptographic signature, and the verifier will see the document flagged as Tampered.
Q5: Since FilPass has other clients with their own verification pages, can those pages verify any FilPass-issued document?
A: No — and that's by design. Each document is cryptographically bound to the Issuing Authority that issued it. A specific Issuing Authority document verified through, say, a university's FilPass verification page (or any other issuer's page) will show as Tampered. This ensures no cross-contamination of trust between different issuing authorities.

