Credential security
Tamper-evident, single-use QR credentials with identity verification before issue.
MeetPass is built defence-in-depth: every layer — the credential, the gateway, the application and the data — is hardened, encrypted and auditable.
Tamper-evident, single-use QR credentials with identity verification before issue.
Every scan is verified at the gateway — online or offline for air-gapped sites.
Data encrypted at rest and in transit, with keys you control on your own servers.
Role-based access and least privilege, with privileged-member separation by default.
Records are encrypted at rest and in transit. In on-premise deployments, encryption keys never leave your environment — so no third party can read your data.

Every issue, scan and entry is logged immutably and retrievable for security reviews, investigations and compliance — with full search across sites.
Qatar's National Information Assurance Policy v2.0, owned by the National Cyber Security Agency, classifies every government information asset and scales its controls accordingly. MeetPass was designed to be deployable at each level rather than certified for one and hoped for at the rest.
Standard controls. Visitor records still written to the immutable log.
Role-based access, directory authentication, retention windows enforced.
Segregated records, dual authorisation on overrides, full session audit.
Air-gapped deployment, cleared operators only, no external connectivity of any kind.
Classification names follow the NIA v2.0 scheme published by the NCSA. Applicable controls and assurance level are determined by your own risk assessment, not by us. Read the policy.
The NIA policy expects government systems to authenticate against Qatar's national identity infrastructure. MeetPass reads and verifies the QID at registration and can authenticate staff against your directory rather than holding a second identity store.
Meeting and visitor records inherit a classification at creation. Restricted and Secret sessions are segregated, and access to them is gated on clearance rather than on role alone.
NIA compliance is audited annually by a certification body. The immutable log exports the entry, approval, override and retention evidence an assessor asks for, rather than requiring it to be assembled by hand.
For classified environments the whole platform runs on your infrastructure — private cloud, on-premise, or fully air-gapped with signed watchlist bundles imported on your own schedule.
Physical entry is not adjacent to information security — it is Annex A 7.2 of the standard itself. And it is the control your assessor observes first, because they walk through your lobby before they open a single document. A paper ledger is a finding waiting to happen.
| Control | What the standard asks for | What MeetPass gives the assessor |
|---|---|---|
| A.7.1 | Physical security perimeters | Sites, gates and zones modelled in the platform, with which pass types may cross which perimeter. |
| A.7.2 | Physical entry | Identity verified before arrival, entry authorised by a named host, every crossing scanned and logged. |
| A.7.3 | Securing offices, rooms and facilities | Room-level restrictions, privileged sessions and zone rules enforced from the same credential. |
| A.5.15 | Access control | Role-based access with least privilege, reviewed and reassignable without touching the record. |
| A.5.28 | Collection of evidence | A tamper-evident audit trail that an investigator or assessor can export without your team rebuilding it. |
| A.8.15 | Logging | Every request, approval, scan, override and export written with actor, action and timestamp. |
Security is not a module you switch on for the sensitive sites. Every pass type inherits the same verification, the same authorisation chain and the same immutable record — only the specifics differ.
Classification set at creation · privileged sessions segregated · signed MOM with signature audit · minutes distribution logged
QID/passport verification before issue · watchlist screening at request · signed QR validated offline · exit and overstay recorded
Plate bound to the credential · barrier validation logged · bay assignment and release on the same record
No documents held at the gate · tenant-authorised entry · per-unit approval rules · full retrieval by name, number or date
Capacity enforced at registration · zone restrictions per attendee type · turnstile validation · live occupancy for safety
One credential layer means one audit trail. There is no second system to reconcile, and no gap between them for something to fall through.
For most buyers this is the first question and the shortest conversation: the records generated by MeetPass live wherever your policy says they must, and nowhere else.
Hosted in-country on GCP Doha or Azure Qatar Central — or entirely on your own infrastructure. Records stay in the jurisdiction you nominate.
On-premise deployments hold their own encryption keys. No third party, including us, can read your data.
Configurable retention and deletion per record class, with the expiry events themselves written to the audit trail.
A fully disconnected installation with signed watchlist bundles imported on your own schedule.
MeetPass is architected to support regional data-residency mandates and recognised security practices.
We publish only what we hold. Where a standard is in progress it is labelled an alignment track — never presented as a certification. Certifications marked Certified are held by Source Code Tech Solutions, the company that builds and supports MeetPass; certification of your own management system remains yours to hold. Full architecture and compliance documentation is available under NDA during due diligence.
Yes. For the most sensitive sites, MeetPass deploys with no external network dependency — credential verification works offline at the gate.
Only the roles you authorise. Access is role-based with least privilege, and privileged actions are separated and logged.
Passes are single-use and tamper-evident, verified cryptographically at the gateway — a screenshot or copy will not clear the gate.
Yes — full security and architecture documentation is available for evaluation under NDA. Arrange it through a briefing.
On infrastructure you nominate — in-country on GCP Doha or Azure Qatar Central, in your own private cloud, or entirely on your own servers. On-premise deployments hold their own encryption keys, so no third party, including us, can read the data.
Every entry and exit for any date range by site, gate, host or individual; the approval chain behind each visit; every override with both approvers named; retention and deletion events; and access reviews for the period under audit.
Arrange a confidential briefing — including full documentation under NDA.