SFT
Sprint Family Tech Building safer digital lives that families actually control
Identity shouldn’t be owned by platforms.
It should belong to the person.

SiGear – A Working Prototype of Runtime Consent Enforcement

SiGear is no longer a concept. It is a functioning prototype that enforces consent decisions at runtime, based on identity, purpose, lifecycle state, and approved capabilities. Some interfaces are still being developed, but the core evaluation engine is working and available for controlled pilot use.

This page explains what exists today, what has been proven, and where we are inviting partners to help shape what comes next.


Architecture at a glance

SiGear combines NTI identity claims, a deterministic evaluation engine, and structured audit logging. Policy enforcement can run server-side or locally in the browser using a signed avatar.

           User / App → NTI Avatar → Policy Engine
→ Identity / Lifecycle / Capability checks
→ Allow or Deny
→ Audit log → Admin review → Approval → Updated Avatar

Full source code is available on GitHub: github.com/SugaComa75/SiGear

What the prototypes already prove

Prototype 1 – Living Consent Enforcement

  • Known allowed actions are permitted
  • Known disallowed purposes are blocked
  • Lifecycle states dynamically change system behaviour
  • Recovery requires explicit re-authentication
  • All sensitive decisions are logged with audit detail

Prototype 2 – Defence Against Silent Expansion

  • Unknown or newly introduced capabilities are denied by default
  • The system operates fail-closed, not fail-open
  • New capability axes are captured and surfaced for review
  • Administrators can see what was attempted and why it was denied

Together, these prototypes demonstrate that SiGear is enforcing real policy decisions at runtime, not simply recording consent.

Pilot SiGear

We are inviting a small number of partners to pilot the SiGear prototype in a controlled environment. A typical pilot:

  • Focuses on a high-value or high-risk data flow
  • Integrates via a single evaluation endpoint
  • Runs for 6–12 weeks
  • Produces auditable decision logs and governance insights
  • Helps shape final interfaces and approval workflows

If you would like to explore a pilot or integration, we would be happy to talk.

SiGear as a Standard

SiGear is more than a prototype or technical component. Its long-term purpose is to help establish a trusted standard for how digital services enforce consent and safeguarding rules. Instead of platforms deciding for themselves how data may be used, SiGear is designed to let users define their own digital boundaries and require services to prove they operate within them.

This creates a different kind of trust: not trust in promises, policies, or terms buried in small print, but trust in verifiable behaviour. When a service integrates SiGear, it can demonstrate that:

  • it does not silently expand access or purpose
  • it does not introduce new capabilities without review
  • it enforces user-defined rules consistently
  • it can evidence compliance through transparent audit logs

The long-term goal is for SiGear to contribute to a recognised public-interest framework for consent enforcement and digital safeguarding: a practical way for organisations to show that they respect the people they serve, not just in policy, but in system behaviour.