SigID Identity Terms
# SigID Identity Terms
SigID Identity is provided for managing a person's own SigID account, authenticators, sessions, connected applications, agents, delegation, credential access, wallets, privacy controls, and billing. Users must protect their credentials and recovery material, use only accounts and tenant resources they are authorized to access, and avoid automated or destructive activity against the hosted sign-in and account interfaces. Interactive forms are transaction-bound, CSRF-protected, and rate limited; they are not a substitute for the published API.
Application developers and automated clients must use the documented OAuth, OpenID Connect, SDK, CLI, and public API paths. They must validate tokens, respect scopes and tenant boundaries, avoid logging secrets, and follow rate-limit and retry instructions. Security research must avoid accessing another tenant's information or impairing production. Report vulnerabilities privately to `security@sigid.com` with safe reproduction steps.
Commercial terms, data-processing commitments, service levels, and deployment-specific obligations depend on the applicable agreement. Product questions go to `sales@sigid.org`; legal questions go to `legal@sigid.com`. The documentation and this summary do not create permissions beyond the account, tenant policy, consent, and agreement that govern a request.