Two layers: the off-chain app runs business and admin operations; the chain is the source of truth for claims. The server holds no signing keys — every write is a Safe transaction signed by humans.
| Company | Team | Individual | |
|---|---|---|---|
| Anchor | Domain TXT + KYB | Domain TXT, no KYB | Public anchor (token post, snapshotted) |
| Gate | KYB off-chain | Domain + 2-of-3 review; every member private-KYC'd | Public anchor + private KYC gate (anti-sybil, never displayed) |
| Billing | Seats (persons) | No seats — per-member individual plans | Per-person plan |
| TYPE on card | COMPANY | TEAM — never readable as a KYB'd company | INDIVIDUAL |
| Claim | Full (wallet) / reduced (custodial) | Domain-anchored, explicitly no-KYB | Anchor-verified, alias-only — the anchor is the claim, KYC is the gate |
| Compromise | Attacker gets |
|---|---|
| Backend server | DoS + wrong cached data — detectable via explorer links. Cannot register, add, or revoke: no TT key exists on the server |
| One admin signer | Nothing — Admin Safe needs 2-of-3 |
| Admin Safe (2-of-3) | Can onboard fake clients. Cannot fabricate persons for wallet-plan clients; custodial clients isolated behind a separate signer set |
| Owner Safe | Full parameter control — mitigated by timelock |
| Client admin wallet | Adds within remaining seats (billing-limited) + revoke. Fail-closed: turns trust off, never fabricates unlimited trust |
| Team domain DNS / individual anchor | Passes TXT / token post for that namespace only — mitigated by similarity screening, cross-reference review, 2-of-3, private KYC |
TT never claims a representative is honest. TT proves: this communication account was authorized by this client, and that authorization is currently active.