Legal & access
What we publish, summarise, and restrict
The default posture of the state is publication. Information is classified only where its disclosure would endanger the security, integrity, or privacy of the nation or a person. The rule that restricts information is itself published here.
Public
Public
Anyone may view. This is what builds trust.
- The chain explorer and public transaction history (PII-scrubbed).
- Block hashes, heights, and the public state root.
- Currency supply (live, runtime-fetched).
- The 1:1 reserve ratio.
- The technical description of XityChain, XityCoin, and XityConnect.
Partial
Partially public
Public in principle, abstracted in detail.
- The general design of the consensus and access-control model.
- The 24-hour recovery delay (a verified technical fact).
Restricted
Restricted
Never published. Disclosure would weaken the nation.
- Private keys and seed phrases.
- Reserve composition and custody detail.
- Identity evidence, documents, photos, beneficial-owner data.
- Internal network topology, failover logic, and admin endpoints.
- Vulnerability findings and incident-response playbooks.
- Validator hosts and public keys (where they would aid reconnaissance).
The single test. If revealing a detail makes Xity easier to attack, exploit, impersonate, or undermine, it is not public. This rule is applied consistently across every page of this site.
Vulnerability disclosure
Report responsibly
Reports go to the standard contact address. There is no PGP key published today and no separate CERT inbox. Do not publish findings before the operator has investigated.