Credential registry
Verify a credential.
Both fields are required, on purpose. If a credential number alone returned a name, anyone holding a leaked number could learn who it belongs to, and the number space could be walked to build a list of certified engineers. Requiring the name means we only confirm what you already know.
Numbers look like SA-APEX-2026-7QK4-M2XD. Case, spacing, accents and middle names do not matter.
How this is protected
Minimal by design, and not browsable.
| Shown once name and number both match | Never shown, to anyone |
|---|---|
| Credential, number, status and the time you checked. | Exam scores and any per-domain detail. |
| Issue and expiry dates. | Employer, or any internal authorization status. |
| Endorsements held. | Client work, engagement history or references. |
| The holder’s display name and country, where they consented to publish them. | Email address, application evidence or program notes. |
Two factors, not one
A number alone returns nothing. The registry confirms; it does not disclose.
Identical failure responses
A wrong name and a non-existent number produce the same answer, so the form cannot be used to test whether a number is real.
Rate limited on failure
Genuine checks are unaffected. Guessing gets expensive quickly.
A holder chooses whether their name is echoed back on a successful check. A credential that verifies without displaying a name is not suspicious — it means the holder did not consent to publication, which is their right, and the match itself already confirmed you had the right person.