top of page

GSCA FAQ

Frequently Asked Questions
 

Understanding GSCA, ONE ID & the Global Trust Infrastructure
 

 

1. What is GSCA?
 

GSCA (Global Standard Certified Alliance) is an alliance-based global trust infrastructure designed to connect people, organizations, credentials, products, assets and transactions through a common trust framework.

GSCA provides the underlying framework through which different trust services and participating organizations can establish, issue, manage and verify trusted digital identities and records.
 

 

2. Why was GSCA created?

GSCA was created to address a fundamental challenge in the digital economy: how can people, organizations, products, certificates and assets be trusted across different systems, industries and countries?

GSCA aims to provide a common trust layer that can support different ecosystems rather than being limited to a single industry or application.
 

 

3. What does “Trust Infrastructure” mean?
Trust Infrastructure is the underlying framework that enables trusted identities, credentials, records, assets and transactions to be created, managed and verified.

Rather than focusing on one application, GSCA is designed as a foundation that can support multiple trust services and ecosystems.
 

 

4. Is GSCA a blockchain company?

No.

Blockchain and cryptographic technologies may form part of GSCA's technical infrastructure, but GSCA is not defined solely by blockchain technology.

GSCA combines identity, verification, certification, digital records, asset provenance, authorization and other technologies according to the requirements of each service.
 

 

5. Is GSCA centralized or decentralized?

GSCA is designed as an alliance-based and federated trust infrastructure.

Participating organizations may maintain their own operational environments and systems, while GSCA provides a common framework for establishing and verifying trust across the ecosystem.

GSCA does not require every participant to operate within one single centralized environment.
 

 

6. What is the GSCA Alliance?

The GSCA Alliance is the ecosystem of participating organizations, institutions, businesses and other qualified members that operate within the GSCA Trust Framework.

The Alliance allows independently operated organizations to participate in a common trust ecosystem while maintaining their own operational responsibilities.
 

 

7. Who can participate in GSCA?

Depending on the applicable membership and service requirements, organizations, institutions, businesses, professional bodies, educational organizations, technology providers and other qualified entities may participate in GSCA.

Specific eligibility requirements may vary according to the type of participation.
 

 

8. What is GSCA ONE ID?

GSCA ONE ID is the identity foundation of the GSCA ecosystem.

It is designed to provide a trusted digital identity layer that can be used across different GSCA services and applications.

ONE ID may support different identity use cases for individuals, organizations, employees, students, pets and other recognized entities, subject to the applicable service.
 

 

9. Is ONE ID only for individuals?

No.

ONE ID is designed to support different identity scenarios.

Depending on the service, it may be used for:

  1. Individuals

  2. Organizations

  3. Employees

  4. Students

  5. Members

  6. Pets

  7. Other recognized entities

The specific identity attributes and verification requirements depend on the applicable use case.
 

 

10. What is PET ID?

PET ID extends the GSCA identity concept into the pet ecosystem.

It is designed to provide a digital identity for pets and can potentially connect relevant information such as ownership, identification, certificates, records and other authorized information within the applicable GSCA environment.
 

 

11. Can ONE ID be used as an employee or student ID?

Yes.

ONE ID can support different organizational identity use cases.

For example, an organization may use ONE ID as part of an employee identity or student identity system, subject to its own authorization and management requirements.
 

 

12. What happens when an employee leaves an organization?

An organization may manage the employee's access and organizational authorization according to its internal procedures.

For example, organizational access, employee credentials or organization-issued services can be revoked or deactivated when employment ends.

The employee may still retain their own personal identity and independently authorized services where applicable.
 

 

13. What are GSCA Trust Assurance Levels?

GSCA may use different Trust Assurance Levels, including L1, L2 and L3, to support different levels of identity and verification requirements.

These levels are not intended to permanently define one specific technology or product configuration.

The applicable assurance level may be determined according to factors such as:

  1. Service requirements

  2. Risk level

  3. Organization requirements

  4. Member requirements

  5. Verification needs

  6. Regulatory or operational considerations
     

 

14. Does L3 always require the same verification method?

Not necessarily.

GSCA is designed to allow assurance requirements to evolve as technology, services and regulatory requirements change.

The actual verification mechanisms applicable to an assurance level may therefore be determined according to the relevant service and risk requirements.
 

 

15. What is eCert?

eCert is a digital certificate service within the GSCA ecosystem.

It is designed to enable organizations and authorized issuers to create, issue, manage and verify digital certificates and credentials.
 

 

16. What is eAsset?

eAsset extends the GSCA Trust Protocol into digital and physical asset-related use cases.

An asset may be associated with trusted digital information, identification, certification, verification or provenance information according to the applicable GSCA service.
 

 

17. What is eOrigin?

eOrigin is designed to establish and maintain trusted information relating to the origin, identity and transfer of an asset.

It may support different ownership and transfer scenarios, including applicable C2C transactions and secondary-market use cases.
 

 

18. Can eOrigin support second-hand transactions?

Yes.

The GSCA eOrigin framework is designed to support applicable asset transfer scenarios, including C2C (Consumer-to-Consumer) transfers.

Where supported, the transfer process can establish a digital record of the relevant transaction and transfer information.
 

 

19. Does GSCA verify every product automatically?

No.

GSCA provides a trust and verification infrastructure. The actual verification process depends on the issuer, organization, product, asset and service involved.

A GSCA verification result should therefore be understood within the applicable verification framework and information provided by the authorized issuer or participant.
 

 

20. Can GSCA be used for anti-counterfeiting?

GSCA is designed to help organizations establish verifiable digital identities and records associated with products, certificates and assets.

Depending on the implementation, technologies such as dynamic QR codes, NFC, cryptographic records and other verification mechanisms may be used to help detect unauthorized or inconsistent information.
 

 

21. What is the relationship between NFC and GSCA?

NFC can provide a convenient physical interface for accessing a digital identity or verification record.

For example, an NFC-enabled product, certificate, pet tag or other physical object may provide a connection to its corresponding digital record, subject to the applicable GSCA implementation.
 

 

22. Can GSCA support QR codes as well as NFC?

Yes.

GSCA services may use different identification and verification technologies, including QR codes, NFC and other mechanisms depending on the requirements of the particular application.
 

 

23. What types of industries can GSCA support?

GSCA is designed as a multi-industry trust infrastructure.

Potential applications include:

  1. Education

  2. Certification

  3. Professional organizations

  4. Events

  5. Sports

  6. Pet services

  7. Products and manufacturing

  8. Supply chains

  9. Membership

  10. Corporate identity

  11. Digital assets

  12. Other trusted-record applications

The ecosystem is not restricted to one industry.
 

 

24. Is GSCA only for large companies?

No.

GSCA is designed to support organizations of different sizes and requirements.

The applicable service, membership and assurance requirements may vary according to the organization's needs and intended use.
 

 

25. Can an organization maintain its own systems?

Yes.

GSCA's alliance-based approach is designed to allow participating organizations to maintain their own operational systems and environments while participating in a common GSCA Trust Framework.

Integration requirements depend on the applicable service.
 

 

26. Does GSCA own all the data created by its members?

Not necessarily.

Data ownership, responsibilities and access rights depend on the applicable service, agreement and legal requirements.

GSCA's framework is designed to distinguish between trust infrastructure functions and the operational data responsibilities of participating organizations.
 

 

27. Can GSCA work across different countries?

GSCA is designed with international and cross-border use cases in mind.

However, specific services and data processing arrangements remain subject to applicable laws, regulations, contractual requirements and the operating environment of the participating organizations.
 

 

28. What is GSCA Certified?

“GSCA Certified” refers to a certification or verification status issued or recognized under an applicable GSCA framework.

The meaning and scope of a particular certification depend on the relevant certification program, issuer and applicable requirements.
 

 

29. Can a GSCA record be verified by another person?

Where a service provides public or authorized verification, a recipient may be able to verify the relevant credential, certificate, asset or record using the designated GSCA verification mechanism.

The information available during verification depends on the permissions and configuration of the specific service.
 

 

30. Can GSCA records be changed after they are issued?

GSCA services are designed to provide integrity and traceability for relevant records.

Where a record requires an update, correction, revocation or status change, the applicable service may maintain an appropriate record or status rather than allowing unauthorized alteration of the original trusted information.
 

 

31. What happens if a certificate or credential is no longer valid?

Depending on the service, a credential may have a validity period or status such as active, expired, revoked or otherwise inactive.

Verification systems may display the applicable status when verification is performed.
 

 

32. What is GSCA's role in a trust transaction?

GSCA provides the framework and infrastructure that can support identity, verification, certification, authorization, provenance and trusted records.

The responsibility for the underlying information remains with the relevant authorized issuer, organization, owner or participant according to the applicable service and agreement.
 

 

33. Can GSCA support business-to-business transactions?

Yes.

GSCA is designed to support B2B, B2C and applicable C2C trust scenarios.

Different services may be offered according to the requirements of organizations, businesses and end users.
 

 

34. Does GSCA provide consumer services?

Yes.

Although GSCA is strongly focused on enterprise and institutional trust infrastructure, certain services may be made available directly to individuals and consumers.

Examples may include applicable identity, pet, certificate, asset or other trust services.
 

 

35. What is the difference between GSCA and a normal SaaS application?

A conventional SaaS application generally solves a particular business problem.

GSCA is designed as a trust infrastructure that can support multiple services, organizations, industries and use cases through common trust principles and identity frameworks.

The goal is to allow additional trust services to be connected to the ecosystem over time.
 

 

36. Will GSCA continue to add new trust services?

Yes.

GSCA is designed as an expandable infrastructure.

New services and applications may be introduced as technology, market requirements, member needs and regulatory environments evolve.

Future services may therefore not be limited to the services currently available.
 

 

37. How can my organization become a GSCA member?

Organizations interested in participating can contact GSCA to discuss their organization, intended use case, market and requirements.

Membership and onboarding may be subject to applicable eligibility, verification and due diligence requirements.
 

Please contact:
cs@ecert.app

 

38. How can I integrate my system with GSCA?

Organizations and technology partners interested in integration can contact GSCA to discuss their technical requirements and intended application.

Integration options depend on the relevant GSCA service and organizational requirements.

Please contact:
cs@ecert.app
 

 

39. I have a question that is not answered here. Who should I contact?

We are happy to help.

If your question is not covered by this FAQ, please contact our team and include as much relevant information as possible so that we can direct your enquiry to the appropriate person.

Email: cs@ecert.app
 

 

40. Where can I learn more about GSCA?

You can explore the GSCA ecosystem through our website, including our Trust Infrastructure, ONE ID, Trust Protocol, certification, membership and other available services.
 

For specific business, technical, membership or partnership enquiries:

cs@ecert.app
 

GSCA — Building the Trust Infrastructure for a Connected World.

bottom of page