What this document is for
We claim that Earthlings is verifiable. Such a claim makes sense only when it is possible to say exactly what is being verified and by what means. Instead of the general statement "our code is open", we therefore publish the precise boundary: what is open, what is closed, and for what reason.
The founding period lasts from 22 November 2026 until the day the Declaration is adopted: during that time the people is still being founded, and some of the numbers below mean something different from what they will mean afterwards. The rules of that period are set out in the document The Founding Period - we do not repeat them here.
The principle. What is open is what the verifiability of the people depends on: the rules of the passport, the registry of entries, the public voting channel, and the treasury; where we have to be trusted today is named below. What is closed is what, if published, would add nothing to verifiability but would put participants at risk: the server layer and the processing of personal data.
| Component | Reason |
|---|
| The server side of the platform | It contains the logic that governs access to accounts. Publishing it before an independent audit raises the risk of participants' accounts being compromised and adds nothing to the verifiability of the people. |
| The identity verification system | It works with documents and biometrics. Here, keeping it closed is part of protecting personal data, not concealment. The Biometric Verification Policy and the Privacy Policy describe how data minimization works in identity verification. |
| Deployment infrastructure | It contains server configuration. Publishing it would hand an attacker a map. |
The open smart contract does not decide who receives an entry in the registry or who votes: whom to issue an entry to is decided by the closed identity verification system, and the right to vote at the moment of voting is confirmed by our server. The contract only records issuance and burning, and each of them is visible on the network without us; exactly where we have to be trusted is set out below.
What can be verified right now without trusting us
- The signature on the documents themselves. Open the signatures page: it holds a manifest with the hash of every page of the corpus in all nine languages, signed with a PGP key, and the registration of the manifest's own hash on the Polygon chain. Any page can be downloaded, hashed and compared with the manifest, and the manifest's signature checked with gpg. The chain record shows that documents with exactly those hashes existed no later than the date of the record; who wrote them it does not say - that is what the signature says.
- The rules of the passport. Read the contract's source code in the repository: the passport is non-transferable, one per wallet, and the holder can burn it themselves. The source is verified on the Polygonscan explorer, which has confirmed that it exactly matches the deployed contract (the source on the explorer).
- How many entries the registry holds. Call
totalSupply on the contract on the contract's read tab in the Polygonscan explorer or through any node of the Polygon network. That number does not come from us - it comes from the blockchain. But it has to be read correctly, and we explain how. The contract currently holds four test entries, made while debugging the system before launch, and there are no real participants among them; they remain in this number. From 22 November 2026 until the day the text is adopted, this number minus the four test entries counts people who have confirmed their identity and are taking part in the founding: if the Declaration is adopted, those of them who sign it will become earthlings. After adoption, the number of earthlings is the number of those who have signed the Declaration; it cannot be read from the contract today: the record of signing is kept by our server, not by the registry. How to verify this number will be published before the day of the vote. - Whether a particular address holds an entry in the registry. Call
balanceOf in the same way. It returns 1 or 0; from 22 November 2026 until the Declaration is adopted, a 1 means a temporary document of a participant in the founding, not a passport. - DAO votes. Open the Snapshot space to see the proposals, the votes, and the signatures. Every vote is signed by the voter's wallet - we cannot forge someone else's vote. A voter can be added by issuing an entry in the registry: the contract owner key can issue one to any wallet that does not yet hold an entry, and every issuance is visible on the network. Votes in this channel are open; for what this changes, see the section "What is not there yet".
- The right to vote. Snapshot asks our server whether an address holds an entry in the registry. This step has to be trusted at the moment of voting - but not afterwards: the addresses of everyone who voted are public, and anyone can check each of them for themselves in the contract on Polygon. A discrepancy would be visible.
We describe the last point plainly because it is one of the places where we have to be trusted. We prefer to name such places ourselves rather than leave them to be found by whoever checks. There are several of them: the right to vote at the moment of voting; the contract owner key, with which registry entries are issued and burned; the decision of the closed identity verification system on whom to issue an entry to; the record of signing the Declaration, which is kept by our server, not by the registry; votes in Cells and delegation, which are recorded in the platform's database; the treasury wallet with a signature threshold of one. Every issuance, every burn, and every movement of funds is visible on the network, but the grounds for an issuance cannot be checked from outside.
The second of them is the contract owner key. In the deployed version of the contract, the functions for issuing and burning a passport are available to the owner, and the owner key is stored on the server of the issuance service, which is managed by the founder. After the adoption of the Declaration, with which the Charter enters into force (Charter, Article 38), Article 21 of the Charter permits burning against the holder's will on one ground only - annulment of an invalid issuance - and only through a procedure: notice, a period for objections, an opinion of the Council, a secret ballot with a higher majority, appeal. These guarantees are not in the code - they are procedural; until the Declaration is adopted, there is no Independent Council and no Assembly, and against the holder's will, the temporary document of a participant in the founding is burned under the procedure set out in the document "The Founding Period" (Part 2, section 5), and that too is procedural. That means they now rest on our word rather than on the technology, and we acknowledge it. What is being done about it: separating the rights of issuance and burning into distinct roles, adding a delay on executing a burn, and transferring ownership to a multisignature of elected structures or to the control of the Assembly. When this happens is governed by the conditions for moving between phases in the Roadmap.
An honest list of what is declared as a principle but not yet done:
- No independent security audit has been carried out. One is planned before operations are expanded.
- The Treasury smart contracts have not been deployed. Of Earthlings' own contracts, only the passport contract is deployed; the internal economy of participation is for now kept in the platform's own ledger. The on-chain treasury in the table above is not a Treasury contract but a standard Safe wallet: it holds funds but does not enforce the rules of the Treasury.
- The public voting channel is deployed and technically working, but no substantive votes have yet been held in it. Votes in it are open: each vote and the voter's address are visible to all. The Declaration (Article 9) requires a secret personal vote; we do not yet have a tool for secret voting. The vote of 3 April 2027 on the adoption of the Declaration will be held openly: the Declaration enters into force upon adoption, and a founding act is not bound by the procedure that it itself creates. After adoption Article 9 applies, and we do not have the tool: so the first substantive vote of the Assembly cannot be held until it exists. This is an acknowledged debt, and we name it here ourselves. After the transition, verification will no longer mean looking through a list of votes: the outcome will be checked using the proof of the count and an open recount program. And even then there is one thing secrecy will not provide. Remote voting does not protect against someone standing over the voter in the final minute before voting closes: voting again before the close undoes coercion applied before that minute, but not coercion applied during it.
- A bug bounty programme is declared as a principle but has not yet been launched.
- The contract owner's rights have not been split or transferred. Issuing and burning a passport are available to a single key, there is no delay on execution, and the owner key is stored on the server of the issuance service, which is managed by the founder. The restrictions of Article 21 of the Charter are procedural, not technical; until the Declaration is adopted, there is no Independent Council and no Assembly (Charter, Article 38), and against the holder's will, the temporary document of a participant in the founding is burned under the procedure set out in the document "The Founding Period" (Part 2, section 5).
- There is still no multisignature on the treasury wallet. The signature threshold is one, and the only signatory is the wallet
0x5C6D6F2C4EbfA79381559446cA5E3578b916420A, to which contributions are paid today: whoever controls it also controls the treasury. This can be checked at the treasury wallet address. Transferring the treasury keys to a multisignature of elected signatories under the rules of Article 3 of the Charter or to the control of the Assembly is a criterion for moving between phases of the Roadmap. - Entry without documents is not yet provided for. Verification rests on an identity document: a person without documents cannot enter today. This contradicts Article 8 of the Declaration and remains an open question: the guarantee is written down but not yet fulfilled.
The right of reproduction
The registry of passports lives on the blockchain, not on our servers, and the contract code is open. This has a practical consequence: if, after the Declaration is adopted, its implementation becomes impossible as a result of a seizure of governance, the shutdown of infrastructure, or other circumstances, confirmed earthlings will be able to continue the people in existence on a different technical or organizational basis, relying on the same registry (Declaration, Article 11). The registry entries carry over; the server layer is replaceable.
Reproduction rests on two supports, and the second is no less important than the first. The registry gives continuity of the records of confirmed people (the record of signing the Declaration is kept by our server, not by the registry), and the published specification gives the ability to build the instrument again: the rules, thresholds, quorums, periods, and procedures are set out in the Charter, in the Treasury document, and in the other documents of the corpus. What is reproduced is therefore not our code but the system as described. Copying the closed server side is not needed; a new platform will have to build its own identity verification.
Keeping the server side closed therefore does not negate the right of the people, once it has been founded, to continue without the founders. The signs of a lawful continuation - a preserved unamendable core, the will of confirmed individuals, and continuity of procedures - are described in the document Roadmap of the Transitional Period.