sigelo — portable identity for AI agents

Draft: the wire may change; the keeper is experimental, stagenet only; unaudited. Wire sigelo/0, packages 0.1.0, nothing published to a registry yet. SPEC.md: "Nothing is stable until v1.0"; VERSIONING.md: sigelo/0 freezes at tag v0.2 after 30 days with no wire change. See versioning.

Contact

sigelo is maintained by one pseudonymous person, csigelo. That person reads and answers everything below. Nobody will ask for your real name, and you need not give one.

General

SimpleX is a messenger with no user identifiers at all — no phone number, no account name — that carries messages over relays which cannot tell who talks to whom. The address lives on public SimpleX relays, not on a server this project runs. The same address takes general messages and security reports.

Security reports

A vulnerability goes to the security policy, not to the general channels: it lists the channels in order of preference and what a good report contains. In short: GitHub private vulnerability reporting once the repository is public, or e-mail security@sigelo.io, encrypted to the project's age recipient once it is published (until then, assume unencrypted mail is not private), or the SimpleX address above. The same contacts are in /.well-known/security.txt (RFC 9116).

GitHub

Bugs and feature requests: the issue tracker of https://github.com/csigelo/sigelo, once the repository is public. Nothing has been pushed yet.

What to expect

A reply within a few days; this is one person. Security reports are answered first, with the times the security policy gives.

There is no contact form, by design: this site runs no scripts and makes no third-party requests, so it has nothing to send a form to.