Public security position · September 2026

Identity security that survives a lost phone.

HUGS ID separates a permanent human identity from the phones, email addresses, passwords, passkeys and accounts used to authenticate that person.

The person survives the credential. Authenticators can change. Identity, history, authority and verified evidence do not.

External service deployed · controlled shadow mode

The athlete trust triangle

Identity, authority and verification remain separate.

1. Athlete / Subscriber

Owns the permanent identity root and controls which relying parties may use specific data, for a specific purpose and period.

2. Authorized Party

A guardian, agent or organization receives explicit, scoped, time-bound and revocable authority. Authority is not identity ownership.

3. Independent Verifier

A coach, reviewer or qualified party attests evidence. The verifier can validate a claim without taking control of the athlete’s identity.

Identity continuity

Recovery must not destroy the person’s digital history.

Login.gov currently advises users who lose their only authentication method that they may need to delete the account and create another. SAM.gov can require a notarized Entity Administrator letter when administrator authority cannot be established electronically. Those controls address takeover risk, but they can break continuity and impose a slow recovery burden.

HUGS ID’s architectural response is a stable subscriber subject with multiple replaceable authenticators, controlled authority-based recovery, cooling periods, notifications, immutable receipts and relying-party links that preserve the person’s existing records.

Standards framework

Recognized language. Verifiable claims.

Security domainHUGS ID targetHow it applies
Digital identityNIST SP 800-63-4Identity proofing, subscriber accounts, authenticators, authentication assurance and federation.
Application assuranceOWASP ASVS 5.0 Level 3High-assurance requirements for architecture, authentication, sessions, access control, APIs and secure development.
Phishing resistanceFIDO2 / WebAuthn passkeysPublic-key authenticators designed to resist phishing and credential replay.
Payment-security methodologyPCI DSS 4.0.1 controlsRelevant methodology for least privilege, strong authentication, logging, change control, testing and governance.
Operational assuranceSOC 2 and ISO/IEC 27001 roadmapIndependent evidence for security operations, risk management and control effectiveness.
Accuracy statement: HUGS ID does not claim PCI DSS, NIST, OWASP, SOC 2, ISO or FIDO certification merely by referencing these standards. Conformance and certification claims require documented scope, control evidence and independent assessment.
Security controls

What the architecture is designed to enforce.

Replaceable authenticators

Phone, email, password, passkey, security key and recovery credentials are bindings to the subject—not the subject itself.

Phishing-resistant access

Passkeys and hardware-backed keys are the target primary authenticators, with step-up protection for recovery and high-risk actions.

Recovery without reassignment

Quorum approval, cooling periods, multi-channel notices and immutable evidence protect recovery without creating a new person.

Least-privilege authorization

Every grant records grantee, purpose, scope, start, expiration, status and revocation evidence.

Independent verification

Verification identifies who attested what evidence and when, while keeping the athlete as the identity owner.

Audit and revocation

Security events and verification evidence are append-only; permissions and authenticators can be revoked without erasing history.

Deployment transparency

What is live—and what is still being tested.

This page is a public security position and implementation-status disclosure, not an audit report or certificate.