Overview

auténtiQo is a digital platform designed to provide certification and trust services as a Certification Service Provider (PSC). The product supports the issuance and management of digital certificates, identity verification, certificate renewal, revocation and suspension, as well as validation services such as OCSP, CRL, time stamping and NOM-151 conservation certificates.

The experience was designed around the complete certificate lifecycle: from identity and document verification to certificate issuance, management and subsequent validation. It also includes an operational back-office where certification agents can review applications, validate documentation and approve or reject certificate requests.

Software to use:

Role
  • Product designer
  • UX/UI Designer
  • UX Researcher
Company
  • Diverza
Product
  • B2B
  • Fintech
  • ID Certificate
  • International certification software
Platform

Web App

Year

2025

Problem

Complex certification process

Applicants must complete multiple technical steps to obtain a digital certificate, including request generation, identity verification and document validation.

Difficult certificate lifecycle management

After issuance, users need clear ways to manage renewal, suspension, revocation and certificate status without dealing directly with technical complexity.

Operational and trust requirements

Certification agents need to review and approve requests, while users also require reliable validation services such as OCSP, CRL and NOM-151 conservation certificates.

Mexico’s shift toward legally recognized digital processes increases the need for trusted certification services that can support secure and verifiable transactions.

Context

The shift toward legally recognized digital processes created the need for certification services that users could access and manage through a clear digital experience.

Research

Findings

Finding Context
Guided certification journeys Users need clear sequencing and progress visibility because certificate issuance involves request files, identity verification and document validation.
Lifecycle management matters The experience must support what happens after issuance, including renewal, suspension, revocation and status understanding.
Trust must be verifiable Users need simple mechanisms to confirm certificate and document validity through services such as OCSP, CRL and NOM-151 verification.
Back-office is part of the service Certification agents need to compare request data and supporting documents before approving or rejecting a certificate request.

Architecture and flows

Full flows only on interview

Product decisions

The issuance experience was divided into clear stages—request file, identity verification and document validation—to reduce the complexity of the certification process and make progress visible to the user.

Renewal, suspension and revocation were designed as independent flows, each with its own requirements, validations and outcomes instead of grouping them into a generic certificate-management action.

A “My certificates” area was created to let users search, review and manage certificates according to their status, including active, suspended, revoked or rejected requests.

OCSP was included as a dedicated validation flow so users could check certificate status in real time, complementing CRL-based validation.

The certification agent received a separate workflow to compare request data against uploaded documentation, approve or reject applications and trigger certificate generation.

Technical file generation tasks such as .req, .ren, .key and HASH creation were handled through the companion app, while the web platform focused on submission, verification, lifecycle management and consultation.

Design

Primary colors

#E41395

#232A30

#6645e6

Action colors

#0A7CEE

#FC4349

#24A790

#F3D600

Font colors

#000000

#AAAAAA

#FFFFFF

Grey colors

#555555

#717171

#8E8E8E

#AAAAAA

#AAAAAA

#E3E3E3

Typography

Futura Bold

Aa

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
a b c d e f g h i j k l m n o p q r s t u v w x y z

Futura

Aa

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
a b c d e f g h i j k l m n o p q r s t u v w x y z

Wireframe & Mockup

Prototype only on interview

Solution

A clear and traceable certificate lifecycle experience designed to simplify issuance, suspension, revocation, and consultation.

REQ Generator
Breaks the request generation into clear steps, helping users understand progress and required actions.
Creates a dedicated revocation key, independent from the password, to securely authorize future certificate revocation.
Issuance of a certificate
Shows the certificate issuance process in clear stages, helping users understand their progress and what remains before completion.
Adjusts the identity-check process according to the user’s country and identification document, preparing the correct verification path.
Certificate revocation
Revocation requires users to select a specific cause, creating a more controlled and traceable invalidation process.
Certificate suspension
Suspension reasons focus on temporary risk or operational scenarios, giving users a safer alternative to full revocation.
My certificates
Filters by certificate number, validity, use and status to help users quickly locate the certificate they need to manage.
Shows each certificate’s current lifecycle state at a glance, making active, suspended, revoked and rejected records easy to distinguish.
OCSP consultation
OCSP provides an immediate validity check, helping users confirm whether a certificate is still trusted at the moment of consultation.
Displays the certificate number, authority, validity and usage data to give users clear evidence behind the reported status.

Prototype only on interview

Validation

Identity verification · Certificate issuance · Certificate lifecycle · Revocation · Suspension · Renewal · OCSP · CRL · Digital trust · Compliance · Document validation · Certificate status · NOM-151 · Time stamping · Hash integrity · Certification authority

Requirement-to-flow validation

Each main journey was checked against its user story, acceptance criteria and Definition of Done to ensure that issuance, renewal, revocation, suspension and certificate consultation covered the required states and actions.

Iterative product refinement

The solution evolved through reviews with Product. For example, the issuance flow was revised after the Signicat integration and reduced to a simpler two-step process, showing how technical constraints and product decisions influenced the experience.

Operational and status validation

Critical scenarios were validated through system rules: certification agents could approve or reject requests, certificates were generated only after successful validation, and consultation flows exposed statuses such as valid, revoked, suspended or unknown.

Impact

Structured a complex certification journey

The product organized certificate issuance into a guided process that combines request generation, identity verification and document validation within a single experience.

Enabled complete certificate lifecycle management

Users could manage certificates beyond issuance through renewal, suspension and revocation, while checking their current status from a centralized certificate area.

Improved operational control for certification agents

The back-office provided a structured way to review requests, compare documentation and approve or reject certificate issuance.

Made digital trust verifiable

Services such as OCSP allowed users to verify certificate validity in real time and understand whether a certificate was valid, revoked, suspended or unknown.

Project learning

Design must translate regulation into understandable actions

Working on a PSC product showed that legal and technical requirements only become useful when users can understand what they need to do, why they need to do it, and what happens next.

Certificate issuance is only one part of the experience

The project reinforced the importance of designing the full certificate lifecycle, including renewal, suspension, revocation, status consultation and validation services.

Trust products require both user and operational experiences

The quality of the service depends not only on the applicant journey, but also on the certification agent’s ability to review documentation, validate information and make reliable decisions.

Technical complexity should stay behind the interface

Processes involving .req, .key, .ren, HASH, OCSP, CRL and NOM-151 can be highly technical, but the interface should expose only the information and actions users need at each step.

The main learning was that designing digital trust services is less about exposing technical complexity and more about making certification processes understandable, traceable and manageable.

  • Previous ProjectCancellations

  • Next ProjectREPSE Validation

Share