Government & public procurement

    Supplier status that verifies itself.

    Issue a tamper-proof “verified supplier” credential from the data you already publish. Suppliers display it; every department verifies it in one click; revocation happens the day standing changes.

    How trust cascades Supplier registry issues credentials to Acme Consulting, Nordik Systèmes and Marie T., Acme; Department A and Department B verify them.

    The problem today

    Status confirmations are manual — emails, letters, PDFs, one request at a time.

    A logo on a supplier’s website proves nothing and can be copied.

    When standing changes — an award expires, a sanction lands — nothing on the web changes with it.

    How it works here

    1. Source

      Contract-award data and your ineligibility list, by CSV, API or the systems behind them.

    2. Rule

      Keep a supplier on the verified-suppliers list while it holds a federal award in the last 36 months and is not on the ineligibility list.

    3. Output

      A badge on the supplier’s site, a list every department follows, revocation within minutes.

    The rule, as you would write it
    “Keep Acme Consulting on gc-suppliers while it has an award in the last 36 months and is not ineligible; remove it otherwise.”

    What you issue

    • Organization

      Verified Supplier

      VALID

      Claims

      Legal name
      Status
      Latest award date
    • Person

      Authorized Representative

      VALID

      Claims

      Name
      Role at supplier
      Employment status
    • Claim on a credential

      Local-content Attestation

      VALID

      Claims

      Attestation date
      Evidence reference
      Attested by

    Who verifies

    • On a website

      A buyer clicks the badge on the supplier’s site and sees VALID, the legal name and the verified domain.

    • From a person

      A procurement advisor requests the representative’s pass before a kick-off; it arrives from the supplier’s own sign-in.

    • Inside your systems

      The department’s procurement system checks supplier status by API before award and subscribes to revocations.

    Works with your stack

    Organizations

    1. 1Your procurement or vendor system calls the API before a step completes
    2. 2QuartzPass confirms the supplier’s badge against the authority’s list
    3. 3The step closes with the verification recorded
    4. 4Your system subscribes to revocation events for that supplier

    People

    1. 1Your IAM/IGA onboards an external user and raises a verification request
    2. 2The person presents the credential their employer issued
    3. 3Verified attributes are written back (SCIM); the signed result arrives by webhook
    4. 4Access and role are granted — and withdrawn everywhere the moment the employer revokes

    Revocation reaches every connected system

    • QuartzID· native
    • Microsoft Entra ID
    • Okta
    • SailPoint
    • Saviynt
    • Ping
    • Procurement and vendor platforms via API

    Protocols: SCIM · SAML · OIDC · REST · webhooks

    QuartzPass issues and verifies. Your identity platform decides what it unlocks.

    Built for institutions

    • Conditionally qualified innovation, Innovative Solutions Canada Testing Stream 2026
    • SOC 2 Type II audited
    • ISO/IEC 27001
    • W3C Verifiable Credentials, OpenID4VC, SD-JWT

    Built on W3C Verifiable Credentials, OpenID for Verifiable Credentials (OID4VCI / OID4VP) and SD-JWT; ISO/IEC 18013 mdoc in development.

    Pricing

    What it costs

    The registry pays the Authority plan plus badge bands; accredited suppliers and every verifying department pay nothing.

    See pricing

    Usually on Authority

    A registry accrediting 20,000 organizations

    $5,156.25 / month in usage

    plus the $4,500/yr Authority fee

    90 days free from your first billable credential

    Questions

    Publish your first supplier list this quarter.

    A 12-month operational test or a department-wide rollout: we’ll scope it with you.

    Security and compliance

    • SOC 2 Type IIAudited by Sensiba LLP.
    • ISO/IEC 27001Certified by Sensiba LLP, an ANAB-accredited certification body.
    • GDPRCompliant with the EU General Data Protection Regulation.
    • PIPEDAReady for Canada's Personal Information Protection and Electronic Documents Act.

    Reports available upon request