Security notice
Never send a password, one-time passcode, MFA recovery code, authenticator secret, private key, Turnstile key, session cookie, or full identity document through ordinary email or telephone messaging.
General support
Target response: acknowledgement or substantive response within one business day
Telephone support may not resolve security-sensitive account changes. Identity and authority may need to be verified through an approved channel.
Support can assist with account access, invitations, workspace navigation, credential-issuance errors, document-upload issues, notifications, and public-verification problems.
Include the following where relevant:
- A concise description of what happened and what was expected
- The page or feature involved
- The approximate date and time, including time zone
- The exact error message
- A screenshot with private information hidden where possible
- The institution name and account email
Credential correction, revocation, or authenticity
The issuing institution controls the substance and status of its credentials. A recipient should contact that institution first about an incorrect name, course, award, date, status, or revocation request.
Contact Email address coming soon if a verification link or code fails, the public result conflicts with information from the issuer, the issuer cannot be identified or reached, or a credential appears to be displayed without proper authority.
Provide only the minimum public identifier needed to locate the record. Do not publish a credential identifier unnecessarily.
Account access and MFA
Use the normal sign-in and MFA recovery options first. If they do not work, email Email address coming soon from the address associated with the account. Additional verification may be required before access is changed. VerifyMe will never ask for a password, current one-time code, authenticator secret, or recovery code.
Privacy requests
Use this address for access, correction, deletion, restriction, objection, portability, consent-withdrawal, or other personal-data enquiries. State whether you are an account holder, credential recipient, institution, or public verifier and identify the relevant institution where appropriate.
VerifyMe aims to acknowledge a privacy request within two business days and provide a substantive response within 30 days, subject to identity verification, complexity, applicable law, and any necessary involvement of the issuing institution.
Security reports and responsible disclosure
A report should contain a clear description, the affected URL or feature, the likely impact, safe reproduction steps or a minimal proof of concept, and the reporter's preferred contact information.
Do not:
- Access another person's data
- Retain or distribute personal data
- Use social engineering
- Compromise accounts
- Disrupt the service
- Perform denial-of-service testing
- Demand payment
- Disclose an unresolved vulnerability publicly
Limited good-faith safe harbour
Where a researcher acts in good faith, limits testing to what is necessary, avoids privacy harm and service disruption, promptly reports the issue, preserves confidentiality, and complies with this policy, VerifyMe will treat the activity as authorised security research and will not initiate legal action solely for that compliant research, to the extent the decision is within VerifyMe's control.
This safe harbour does not authorise unlawful conduct, testing of third-party systems, extortion, privacy violations, intellectual-property infringement, or conduct causing harm. VerifyMe cannot bind a third party, regulator, or law-enforcement authority. A researcher who is uncertain should request written permission before testing.
For an active compromise or suspected personal-data breach, use "URGENT SECURITY" in the subject line.
Abuse and suspected fraudulent credentials
Report suspected impersonation, fraudulent credentials, unlawful content, or misuse to Email address coming soon. Include the verification URL or public identifier, issuing institution, reason for concern, and only non-sensitive supporting evidence.
A report does not guarantee immediate removal. VerifyMe may preserve evidence, contact the institution, restrict access, investigate, or refer a matter to an appropriate authority where justified.
Service availability
VerifyMe does not currently operate a public status page. If the service appears unavailable, retry after a short period and contact Email address coming soon with the approximate time, time zone, affected page, and error message.
A separate public status page may be introduced later. This section should then be updated with its verified URL.
Postal contact
Faisal Ahmed Habib trading as VerifyMe
Maitama, Abuja, FCT, Nigeria
Support limitation
VerifyMe support can resolve platform and account issues but cannot provide legal advice, award a qualification, or independently change an institution's academic, professional, or credential decision without proper authority.