Skip to content

Privacy At SigID

SigID processes account identifiers, authentication and security signals, OAuth consent and application configuration, organization and tenant membership, agent identity and delegation records, billing references, operational telemetry, and audit events when those categories are needed to provide and protect the service. Authentication secrets and private key material are not exposed through public profile or discovery endpoints.

SigID acts as a controller for its own account security, billing, support, website, fraud-prevention, and service-operation purposes. When a customer uses SigID to process its users' data, that customer controls the application context and SigID acts under the applicable agreement and processing instructions. Applications receive only the claims and scopes authorized for their tenant and consent context.

People can use SigID Identity to review connected applications, active sessions, profile sharing, exports, processing restrictions, and account deletion controls. Retention may continue where necessary for immutable security logs, tax and billing records, dispute handling, legal preservation, backups, and fraud prevention. Depending on jurisdiction and processing context, people may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data.

The complete Privacy Policy describes data categories, sources, lawful bases, disclosures, international transfers, retention, user rights, cookies, automated security decisions, and subprocessors. Send privacy questions or rights requests to [email protected]; report security issues to [email protected].