Legal & access

What we publish, summarise, and restrict

The default posture of the state is publication. Information is classified only where its disclosure would endanger the security, integrity, or privacy of the nation or a person. The rule that restricts information is itself published here.

Public

Public

Anyone may view. This is what builds trust.

  • The chain explorer and public transaction history (PII-scrubbed).
  • Block hashes, heights, and the public state root.
  • Currency supply (live, runtime-fetched).
  • The 1:1 reserve ratio.
  • The technical description of XityChain, XityCoin, and XityConnect.
Partial

Partially public

Public in principle, abstracted in detail.

  • The general design of the consensus and access-control model.
  • The 24-hour recovery delay (a verified technical fact).
Restricted

Restricted

Never published. Disclosure would weaken the nation.

  • Private keys and seed phrases.
  • Reserve composition and custody detail.
  • Identity evidence, documents, photos, beneficial-owner data.
  • Internal network topology, failover logic, and admin endpoints.
  • Vulnerability findings and incident-response playbooks.
  • Validator hosts and public keys (where they would aid reconnaissance).
i
The single test. If revealing a detail makes Xity easier to attack, exploit, impersonate, or undermine, it is not public. This rule is applied consistently across every page of this site.
Vulnerability disclosure

Report responsibly

Reports go to the standard contact address. There is no PGP key published today and no separate CERT inbox. Do not publish findings before the operator has investigated.