01 Protocol governance, privacy, and safety
Capital cannot buy control — as an engineering requirement
cl 38.1cl 38.4cl 38.5
Where the company stewards any protocol token, digital asset system, or digital governance system, it must ensure transferable economic value is structurally separated from governance over the company's purposes, Protected Provisions, and constitutional governance — so that no person, holding, investor, partner, founder, director, member, subsidiary, or amount of capital can acquire control over them.
Clause 38.4 applies the same rule to insiders: the company must not create any founder, director, member, investor, employee, or partner right that confers private control over the purposes. The anti-capture rule binds the people who wrote it.
02 Protocol governance, privacy, and safety
No token obligation — and lawful token mechanics if there is one
cl 38.2cl 38.3
Clause 38.2 states that no provision of the constitution obliges the company to issue, sell, distribute, airdrop, allocate, custody, list, or operate any token or digital asset — mirrored as Protected Provision item 7. If the company does operate token systems, clause 38.3 requires the mechanics — identity, distribution, custody, liveness, uniqueness, sanctions, AML/CTF, financial services, consumer law, privacy, security — to be set by board-approved policies that comply with all applicable law.
03 Protocol governance, privacy, and safety
Privacy by design, in the constitution
cl 39.1cl 39.2
The company must apply privacy-by-design principles to identification, authentication, safety, anti-fraud, and accountability systems so far as reasonably possible and lawful — and must prefer architectures that minimise personal data collection, minimise centralised data custody, use encryption and selective disclosure where feasible, and allow independent audit where safe and lawful. This is the constitutional root of the VEID identity research program.
04 Protocol governance, privacy, and safety
Safety gates before production
cl 40.1cl 40.2
The company must not knowingly develop, deploy, license, or maintain technology for unlawful mass harm, unlawful surveillance, coercion, unlawful discrimination, or private capture. And before deploying production systems that materially affect identity, digital assets, health, safety, public infrastructure, or significant economic rights, the directors must establish safety, security, privacy, financial-services, AML/CTF, sanctions, consumer-law, and incident-response policies. Deployment is gated on governance, not the other way around.