auténtiQo is a digital platform designed to provide certification and trust services as a Certification Service Provider (PSC). The product supports the issuance and management of digital certificates, identity verification, certificate renewal, revocation and suspension, as well as validation services such as OCSP, CRL, time stamping and NOM-151 conservation certificates.
Overview
The experience was designed around the complete certificate lifecycle: from identity and document verification to certificate issuance, management and subsequent validation. It also includes an operational back-office where certification agents can review applications, validate documentation and approve or reject certificate requests.
Software to use:
![]()
![]()
![]()
Role
- Product designer
- UX/UI Designer
- UX Researcher
Company
- Diverza
Product
- B2B
- Fintech
- ID Certificate
- International certification software
Platform
Web App
Year
2025
Problem
Complex certification process
Applicants must complete multiple technical steps to obtain a digital certificate, including request generation, identity verification and document validation.
Difficult certificate lifecycle management
After issuance, users need clear ways to manage renewal, suspension, revocation and certificate status without dealing directly with technical complexity.
Operational and trust requirements
Certification agents need to review and approve requests, while users also require reliable validation services such as OCSP, CRL and NOM-151 conservation certificates.
Mexico’s shift toward legally recognized digital processes increases the need for trusted certification services that can support secure and verifiable transactions.
Context
Research
Understanding the PSC ecosystem
The research focused on how a Certification Service Provider operates beyond certificate issuance: identity verification, certificate lifecycle management, revocation controls and validation mechanisms such as OCSP and CRL.
Mapping certificate lifecycle and user requirements
We analyzed the information, documents and security steps required for issuance, renewal, suspension and revocation, identifying the different paths that users may follow depending on certificate status and type.
Exploring digital trust services
The research also covered NOM-151 conservation certificates, time stamping and HASH generation to understand how users could preserve and verify the integrity of digital information through auténtiQo.
Findings
| Finding | Context |
|---|---|
| Guided certification journeys | Users need clear sequencing and progress visibility because certificate issuance involves request files, identity verification and document validation. |
| Lifecycle management matters | The experience must support what happens after issuance, including renewal, suspension, revocation and status understanding. |
| Trust must be verifiable | Users need simple mechanisms to confirm certificate and document validity through services such as OCSP, CRL and NOM-151 verification. |
| Back-office is part of the service | Certification agents need to compare request data and supporting documents before approving or rejecting a certificate request. |
Architecture and flows
Full flows only on interview
Product decisions
Guided multi-step certificate issuance
The issuance experience was divided into clear stages—request file, identity verification and document validation—to reduce the complexity of the certification process and make progress visible to the user.
Separate certificate lifecycle actions
Renewal, suspension and revocation were designed as independent flows, each with its own requirements, validations and outcomes instead of grouping them into a generic certificate-management action.
Centralized certificate management
A “My certificates” area was created to let users search, review and manage certificates according to their status, including active, suspended, revoked or rejected requests.
Real-time trust verification
OCSP was included as a dedicated validation flow so users could check certificate status in real time, complementing CRL-based validation.
Dedicated operational back-office
The certification agent received a separate workflow to compare request data against uploaded documentation, approve or reject applications and trigger certificate generation.
Separate local and web responsibilities
Technical file generation tasks such as .req, .ren, .key and HASH creation were handled through the companion app, while the web platform focused on submission, verification, lifecycle management and consultation.
Design
Primary colors
#E41395
#232A30
#6645e6
Action colors
#0A7CEE
#FC4349
#24A790
#F3D600
Font colors
#000000
#AAAAAA
#FFFFFF
Grey colors
#555555
#717171
#8E8E8E
#AAAAAA
#AAAAAA
#E3E3E3
Typography
Futura Bold
Aa
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
a b c d e f g h i j k l m n o p q r s t u v w x y z
Futura
Aa
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
a b c d e f g h i j k l m n o p q r s t u v w x y z
Wireframe & Mockup
Prototype only on interview
Solution
A clear and traceable certificate lifecycle experience designed to simplify issuance, suspension, revocation, and consultation.
REQ Generator

Issuance of a certificate

Certificate revocation

Certificate suspension

My certificates

OCSP consultation

Prototype only on interview
Validation
Identity verification · Certificate issuance · Certificate lifecycle · Revocation · Suspension · Renewal · OCSP · CRL · Digital trust · Compliance · Document validation · Certificate status · NOM-151 · Time stamping · Hash integrity · Certification authority
Requirement-to-flow validation
Each main journey was checked against its user story, acceptance criteria and Definition of Done to ensure that issuance, renewal, revocation, suspension and certificate consultation covered the required states and actions.
Iterative product refinement
The solution evolved through reviews with Product. For example, the issuance flow was revised after the Signicat integration and reduced to a simpler two-step process, showing how technical constraints and product decisions influenced the experience.
Operational and status validation
Critical scenarios were validated through system rules: certification agents could approve or reject requests, certificates were generated only after successful validation, and consultation flows exposed statuses such as valid, revoked, suspended or unknown.
Impact
Structured a complex certification journey
The product organized certificate issuance into a guided process that combines request generation, identity verification and document validation within a single experience.
Enabled complete certificate lifecycle management
Users could manage certificates beyond issuance through renewal, suspension and revocation, while checking their current status from a centralized certificate area.
Improved operational control for certification agents
The back-office provided a structured way to review requests, compare documentation and approve or reject certificate issuance.
Made digital trust verifiable
Services such as OCSP allowed users to verify certificate validity in real time and understand whether a certificate was valid, revoked, suspended or unknown.
Project learning
Design must translate regulation into understandable actions
Working on a PSC product showed that legal and technical requirements only become useful when users can understand what they need to do, why they need to do it, and what happens next.
Certificate issuance is only one part of the experience
The project reinforced the importance of designing the full certificate lifecycle, including renewal, suspension, revocation, status consultation and validation services.
Trust products require both user and operational experiences
The quality of the service depends not only on the applicant journey, but also on the certification agent’s ability to review documentation, validate information and make reliable decisions.
Technical complexity should stay behind the interface
Processes involving .req, .key, .ren, HASH, OCSP, CRL and NOM-151 can be highly technical, but the interface should expose only the information and actions users need at each step.
The main learning was that designing digital trust services is less about exposing technical complexity and more about making certification processes understandable, traceable and manageable.
