Security

Built to hold as little of you as possible.

Most companies keep a file about you, your name, your birthday, your photo, and then try to guard that file. SigWave keeps no such file. Your mark is the picture that stands for you. It is made on your phone. When someone asks "is this really you?", only your own phone or computer can say yes. When you sign a paper with it, anyone can point a phone camera at the page on sigwave.id/scan and see who signed it and whether any line changed. This page says how it is built, and what is still in development.

Your mark is yoursYou make it in a browser at sigwave.id/me today, or in the iPhone app, which is in testing with a small group. Made in the app, its secret is made on your phone, inside the part built to keep secrets, and never leaves it. A mark made in a browser is weaker, and says so. Your mark itself is published so others can look it up. Nothing about you is sent anywhere until you answer someone.
You are there firstYour phone or computer checks that you are there: Face ID, Touch ID or your Mac's password before anything is signed.
What the directory holdsThe directory at sigwave.id holds, for you: your mark; the phones and computers you allow to say yes for it; the questions and answers you chose to send; receipts of what was asked and answered, without the answers' contents; signed records you chose to publish; and the addresses that let us reach a phone, which name a device, not a person. Two more things are kept but change nothing yet: reports about a mark that asked someone something, each one reason word, the two marks and which ask it was about, seen by nobody else and kept one year; and a standing for each mark, worked out from blocks and those reports. For now these are collected and studied without changing how any mark is treated. It also holds sealed packages passing between your own devices, and details you choose to seal for an approved processor. We cannot open either. It keeps the marks you blocked. The directory has no name for you unless you give one. It has no column for a birth date, an address or a document. If you choose to send one of those in an answer, it is kept with that answer.
Only your devices can answerOnly the devices on your list can answer for your mark or sign with it. A signed paper is checked on your own phone against the page itself, at sigwave.id/scan or in the app. No account is needed. The page is not uploaded; only its printed code is looked up.
Your devices, your listOne mark can live on your iPhone and your Mac, and every change to that list is signed. An Apple Watch app is in testing too; nothing is proven on a wrist yet. You add a new device by scanning from one you already hold. You hold the list. If a phone is lost or stolen, you take it off the list, and it can no longer answer for you. A recovery kit is made on the phone. It is two things you keep safe: a small saved file and seven words written on paper. Making the kit works today. In development: bringing your mark back from the kit alone, after you lose every device, arrives in a later version.
A copy of your mark can do nothingYour mark can be printed on a card or a letter, and anyone can see it. Seeing it gives anyone nothing. A photo, a scan, a perfect copy cannot answer a question, because the secret that answers is on your own device, not in the picture.
What you signed can be checked by anyoneA page you sign carries your mark and a document code. Anyone can point a phone camera at the page on sigwave.id/scan. It reads the mark, the code and every line, and says one of three things: Signed, when every line matches; Changed, when a word differs from what was signed; or Not signed. No account is needed. The iPhone app does the same check and is in testing with a small group. The Mac app is public at dl.sigwave.id. It can sign but cannot scan yet.
BlocksIn development. Blocking a mark already works on our service: its questions stop reaching you, and whoever holds it is never told. The button for it arrives in the next test build of the app.
We do not watch you read this pageNo cookies, no tracking. sigwave.id counts nothing about your visit and loads nothing from any other company. The site is carried by Cloudflare; if a page fails to load, your browser may tell Cloudflare that it failed, and nothing more. A mark you make in a browser is kept in that browser. This page came from us alone, and it tells your browser what it may not do: run code we did not mark for this one response, show this site inside another, pass on where you came from, or reach your microphone or your location. Only sigwave.id itself may use your camera, when you scan. It also tells your browser to speak to us only over a secured connection, for a year.

How we work

Every design gets a security read before it is built.

Before a new version goes out, it passes a gate: a check of the outside software we depend on for known weaknesses, a check of the code's types, a suite of attacks, twenty-odd test suites, and a fuzz of every route. Fuzzing means feeding the software junk on purpose, to find what breaks.

All of that runs against a local copy. Attacks are never run against the live service you use.

What is next

We are already building most of what follows, and we have confirmed that every piece is technically feasible under our patent-pending design.

In development. A public record of the directory's changes anyone can check without trusting sigwave.id: a device added, a device removed. It will be run by Synaping. The design and its security read are done. Nothing of it is built yet.

Built in Synap. Synap, Synaping's personal knowledge system, already remembers the device history it has seen for each SigWave mark it works with, and refuses one that goes backward or splits. It checks that history with a separate library held to SigWave's published test cases, the same way any outside business would. So far one mark, our founder's, takes part. That library is not offered to other businesses yet.

In development. Proof of who a company is. Today, when a company asks you something, the app says "Calls itself X", as it does for any person. A way for a company to show that its mark belongs to its own website and registry record is designed and approved. It is not built yet.

Report a problem

If you find a weakness in SigWave, write to security@sigwave.id. Tell us the mark involved, its sixteen characters; what you did, step by step; when, in your time zone; what you expected; and what happened instead. Never send a person's answers, their documents, or a screenshot of someone else's ask.

A person reads every report and writes back. If you are not sure what is fair to try, ask legal@sigwave.id first.