1. Athlete / Subscriber
Owns the permanent identity root and controls which relying parties may use specific data, for a specific purpose and period.
HUGS ID separates a permanent human identity from the phones, email addresses, passwords, passkeys and accounts used to authenticate that person.
External service deployed · controlled shadow mode
Owns the permanent identity root and controls which relying parties may use specific data, for a specific purpose and period.
A guardian, agent or organization receives explicit, scoped, time-bound and revocable authority. Authority is not identity ownership.
A coach, reviewer or qualified party attests evidence. The verifier can validate a claim without taking control of the athlete’s identity.
Login.gov currently advises users who lose their only authentication method that they may need to delete the account and create another. SAM.gov can require a notarized Entity Administrator letter when administrator authority cannot be established electronically. Those controls address takeover risk, but they can break continuity and impose a slow recovery burden.
HUGS ID’s architectural response is a stable subscriber subject with multiple replaceable authenticators, controlled authority-based recovery, cooling periods, notifications, immutable receipts and relying-party links that preserve the person’s existing records.
| Security domain | HUGS ID target | How it applies |
|---|---|---|
| Digital identity | NIST SP 800-63-4 | Identity proofing, subscriber accounts, authenticators, authentication assurance and federation. |
| Application assurance | OWASP ASVS 5.0 Level 3 | High-assurance requirements for architecture, authentication, sessions, access control, APIs and secure development. |
| Phishing resistance | FIDO2 / WebAuthn passkeys | Public-key authenticators designed to resist phishing and credential replay. |
| Payment-security methodology | PCI DSS 4.0.1 controls | Relevant methodology for least privilege, strong authentication, logging, change control, testing and governance. |
| Operational assurance | SOC 2 and ISO/IEC 27001 roadmap | Independent evidence for security operations, risk management and control effectiveness. |
Phone, email, password, passkey, security key and recovery credentials are bindings to the subject—not the subject itself.
Passkeys and hardware-backed keys are the target primary authenticators, with step-up protection for recovery and high-risk actions.
Quorum approval, cooling periods, multi-channel notices and immutable evidence protect recovery without creating a new person.
Every grant records grantee, purpose, scope, start, expiration, status and revocation evidence.
Verification identifies who attested what evidence and when, while keeping the athlete as the identity owner.
Security events and verification evidence are append-only; permissions and authenticators can be revoked without erasing history.
This page is a public security position and implementation-status disclosure, not an audit report or certificate.