Announced on October 1, 2026, the ViitorCloud Carahsoft partnership makes EveryCRED, our digital trust platform, available to US public sector buyers. Under the agreement between ViitorCloud Technologies and Carahsoft Technology Corp., Carahsoft serves as ViitorCloud’s Master Government Aggregator®. Agencies can buy EveryCRED through Carahsoft’s reseller partners and through the NASA SEWP V, ITES-SW2, NASPO ValuePoint, and OMNIA Partners contracts named in the official announcement. 

What EveryCRED Is 

EveryCRED is a platform for issuing and verifying digital credentials. A credential is a record that an authority stands behind. Public sector teams call these by different names: a pass, a permit, a license, an ID, or a certificate. EveryCRED treats them all as credentials. 

Each credential answers a question someone needs settled before they act: 

  • An identity credential answers who or what this is. 
  • A permit answers whether the holder is allowed here, now, for this task. 
  • A license confirms a grant from an authority. 
  • A qualification confirms competence, such as completed safety training. 
  • An attestation confirms a fact, such as current employment. 

Credentials can describe people, such as employees, contractors, and citizens. They can also describe businesses such as approved vendors. 

Every credential involves three parties: 

  • Issuer: grants the credential and can withdraw it. A licensing office or a facility security team are examples. 
  • Holder: a person, or the owner of an asset or business, who carries the credential. 
  • Verifier: whoever checks the credential at the point of use, such as a guard, an access point, or a caseworker. 

Why Credential Status Matters at the Point of Check 

Each day, someone at a gate, counter, or work site must decide whether to trust a person or a business. 

Much of this still runs on printed cards, PDFs, phone calls, and spreadsheets. Cards can be copied. Calling the issuing office for every check does not scale. When an office withdraws permission, the card in the field still looks valid. 

This is where revocation matters. Revocation means the issuer withdraws or cancels a credential. A verifier needs to know, at the moment of the check, whether a credential has been revoked. 

EveryCRED returns a credential’s live status, including revocation, each time it is checked. Once an issuer revokes a credential, it fails verification wherever it is presented. 

Our joint announcement with Carahsoft describes this as moving away from perimeter-based security, where access depends largely on being inside a network or past a gate. The focus moves to validating identities and credentials. 

This approach is in line with the federal zero trust guidance in NIST SP 800-207, which says trust should not be granted based only on physical or network location. EveryCRED applies that idea to credentials. It does not replace an agency’s wider security controls. 

How a Credential Moves from Issuer to Verifier 

EveryCRED handles the life of a credential in five steps. 

1. Bind

Each credential is tied to a verified identity. Inside an organization, that identity comes from Microsoft Entra ID, Google Workspace, or another enterprise identity system. For people and businesses outside the organization, it comes from a KYC or KYB provider. These services verify individuals (KYC) or businesses (KYB). 

2. Assemble

A credential draws on data the organization already holds. Sources include HR systems, workforce scheduling tools such as Workday, CRM, project management, and visitor management systems. Issuers and approvers add validity dates and consent. Holders can also declare details, which one or more issuers then confirm. More than one issuer can sign a credential, and credentials can be linked when a workflow needs both. 

3. Deliver

Holders receive the credential in one of these places: 

  • an app the organization already provides, connected through APIs 
  • any standards-compliant digital wallet 
  • a white-label (custom-branded) wallet 

4. Verify

A verifier checks the credential through the EveryCRED verifier app, a registered gate or access point, or an API. Each check returns the credential’s live status. A forged or altered credential fails because it does not carry a valid signature from the issuer. 

5. Govern

Issuers can issue, revoke, reissue, and transfer credentials. When a holder is removed from the HR system, their credentials are revoked automatically. If an issuer is itself revoked, the credentials it issued can be revoked too. 

Every event is logged and can be exported through OpenTelemetry. OpenTelemetry is an open standard for sending logs to an organization’s existing monitoring and audit tools. Each verification record shows who checked, where, when, and the result. 

EveryCRED issues credentials as W3C Verifiable Credentials, an open standard, and supports SD-JWT. SD-JWT allows selective disclosure, which means the holder shares only the fields a verifier needs to see. Because the formats are open, any compliant wallet or verifier can work with the credentials. EveryCRED runs in a public or private cloud. 

Where EveryCRED Fits in Government Work 

Our joint announcement names six workflows for US public sector buyers: 

  • Contractor access validation: check that contractors and outside partners meet security requirements before they get access. 
  • License-based access control: grant access only after a real-time check that a person’s license is valid. 
  • Privileged role verification: confirm that staff in sensitive roles hold the qualifications that role requires. 
  • Grant and benefit eligibility: check that applicants are eligible, which helps reduce fraud. 
  • Inter-agency credential exchange: share and verify credentials securely across agencies. 
  • Supply chain and vendor integrity: verify suppliers and vendors throughout the procurement process. 

Three of these show how the five steps apply in daily operations. 

Contractor access validation

A facility manager needs to know that a contractor at the gate is approved for that site and period and has the required safety training. With EveryCRED, the contracting office issues a site permit, and the training provider issues a qualification. A guard or access point checks at entry. If the contract ends, the office revokes the permit, and the next check at the gate fails. 

Grant and benefit eligibility

A benefits office often relies on facts that another authority has already confirmed. That authority can issue the fact as an attestation, which is a signed statement that the fact is true. A caseworker checks the signature and status from the credential itself. The applicant shares only the fields the office needs. 

Inter-agency credential exchange

When one agency relies on a license or role of authorization issued by another, the receiving agency needs to know it is genuine and current. Because the credential follows an open standard, the receiving agency can check it with any compliant verifier. The issuing agency keeps control of revocation. 

In each case, EveryCRED does not decide who should hold a credential. That decision stays with the issuing office, along with its policies and approval process. EveryCRED brings the office’s decision to the point of check and keeps it up to date. 

Map One Government Workflow to EveryCRED

Pick a contractor permit, license, or eligibility check. We show you how EveryCRED issues it, verifies it at the point of use, and revokes it when access ends.

What a Master Government Aggregator Does 

US public sector buyers usually purchase technology through established contracts and approved suppliers. A technology company that wants to sell to them needs a way into those contracts. 

Carahsoft is a government IT solutions provider. It acts as a master government aggregator for its technology vendors. It sells to US federal, state, and local government, education, and healthcare buyers through its reseller partners and contract vehicles. 

As our Master Government Aggregator®, Carahsoft is the channel through which EveryCRED reaches US public sector buyers. A US agency can buy EveryCRED under a contract vehicle it may already use. Carahsoft, or one of its reseller partners, handles the purchase. Our EveryCRED procurement page brings the current vehicles and contacts together in one place. 

How Each Contract Vehicle Works 

A contract vehicle is a contract that has already been competed and awarded. US agencies can order from it without running a new solicitation for each purchase.

Our joint announcement lists these vehicles: 

NASA SEWP V (NNG15SC03B and NNG15SC27B): SEWP is a government-wide acquisition contract (GWAC) run by NASA. It is open to all US federal agencies, including the Department of Defense, and their approved support service contractors. It covers commercial IT products and services, including software and cloud services. 

ITES-SW2 (W52P1J-20-D-0042): ITES-SW2 is an Army contract for commercial software. It is an IDIQ contract, short for indefinite delivery and indefinite quantity. An IDIQ sets the terms in advance, so US agencies can place orders as needs arise. Orders can come from the US Army, the Department of Defense, and other US federal agencies. 

NASPO ValuePoint (AR2472): NASPO ValuePoint is the cooperative purchasing program of the National Association of State Procurement Officials. A lead state runs the solicitation and awards a master agreement. A state then signs a participating addendum before its US state agencies, and in some cases its local governments, can buy under that agreement. Each buyer still follows its own procurement rules. 

OMNIA Partners (R240303): OMNIA Partners is a cooperative purchasing organization. A leading public agency runs a competitive solicitation for itself and other agencies. The resulting master agreement is available to public agencies, educational institutions, and nonprofits across the country. 

Contract periods and state-level entries change over time. Carahsoft keeps the current list on its ViitorCloud contracts page. Procurement teams should confirm that a vehicle is active for their agency or state before starting a purchase. 

What Contract Availability Does and Does Not Mean 

Contract availability means an agency has a way to buy EveryCRED. It does not mean that a government body has endorsed EveryCRED or deployed it. Each US agency still runs its own evaluation, security review, and approval before buying, and decides whether the product fits its needs. 

Where the Platform Stands Today 

EveryCRED’s core platform is live today. Issuers can create and sign credentials, and verifiers can check them instantly, with real-time revocation status. 

Available now: 

  • issuance and the verifier app and APIs 
  • identity binding and automatic revocation from systems of record 
  • delivery to the organization’s own app, standards-compliant wallets and white-label wallets 
  • audit export, and public or private cloud deployment 

In progress: 

  • The EveryCRED wallet app is in app-store review 
  • Credential suspension is planned; until then, an issuer can revoke a credential and reissue it

See EveryCRED Connect to Your Identity Systems

Bring your identity provider and one system of record. We walk you through credential issuance, automatic revocation, and audit export for your public sector setup.

How to Begin a Purchase Through Carahsoft 

US agencies can start a purchase under the ViitorCloud Carahsoft partnership with these steps: 

  1. Confirm the vehicle. Review the Carahsoft contracts page to find a vehicle your agency can use. 
  2. Contact the ViitorCloud team at Carahsoft. For quotes, contract details, and purchasing questions, use Carahsoft’s ViitorCloud page. Our EveryCRED procurement page also brings these details together. 
  3. Scope one use case with us. With a new client, we start with a scoping session on one credential and one point of verification, which leads to a pilot. 

Start Your EveryCRED Pilot Through Carahsoft

Choose one credential and one point of verification. We scope the pilot with your team, and Carahsoft handles the purchase on your contract vehicle.

Talk to Us About Credential Verification 

A credential verification pilot starts small. Pick one license, permit, or authorization your team still checks by hand or by phone and name the place where it is checked. From there, we scope how EveryCRED would issue it, verify it at the point of use, and revoke it when access ends. Carahsoft handles the purchase on a contract vehicle your agency already uses.  

Write to our team at ViitorCloud, or reach the ViitorCloud team at Carahsoft for contract and quote details. 

Rohit Purohit

Rohit Purohit

I am a tech business leader, CEO, and Co-Founder.