Export policy
Reference is broad. Copying is not.
Every public source may be cited. A source-derived pack leaves this site only after the licence, the commit, the dependencies, and a human review are real records. They are not.
This is an operating framework, not legal advice. It is not a finding by counsel. Non-commercial, demo, or test use does not remove copyright, licence, patent, contract, or export-control duties. A public repository is not permission to copy it.
Every public source may be referenced. Every source may be analysed within lawful access and platform terms. Only sources with a verified reuse basis may be exported, copied, packaged, redistributed, or used as source-derived code in a Build Pack.
Reference is broad. Analysis is broad. Export is conditional. Production is gated.
When in doubt, link — do not copy.
What this release will hand you
Research exports E0 to E5 are original Blockchain Lab text: metadata, a citation, a blueprint, a test outline, or a scaffold that does not copy a repository. E6 to E10 are refused. No component is marked “demo export available”. 27 repositories were licence-checked on 2026-10-01. None has a pinned commit.
- Unmet: Official source verified beyond the URL recorded on 1 October 2026.
- Unmet: Commit or release tag pinned.
- Unmet: Transitive dependency licences reviewed.
- Unmet: Licence text and notices packaged.
- Unmet: Secret scan.
- Unmet: Vulnerability review.
- Unmet: Human approval for a source-derived export.
- Unmet: SBOM generated from a lockfile.
Source access classes
| Class | Label | Behaviour | Export |
|---|---|---|---|
| S0 | Blocked | Do not ingest the content. Keep a minimal compliance note if a notice requires it. | No |
| S1 | Reference only | Metadata, URL, identity, and original analysis. No source body. | No source, code, or full-text export |
| S2 | Research analysis | Concepts, structure, and test plans within the access you actually have. | No raw source. No derived-code pack. |
| S3 | Reusable with conditions | A licence may allow a later governed pack. This release has not cleared one. | Only after provenance, scans, notices, and approval |
| S4 | Full reuse | Host or redistribute only with a verified right such as CC0 or an explicit redistribution grant. | Yes, with attribution and the licence |
| S5 | Owned or permissioned | Blockchain Lab wrote it, or written permission states the scope. | As the permission allows |
| U1 | User-owned private source | Private workspace only. The user confirms they may use it. No training by default. | User-directed. Not built on this site. |
How a class is assigned
- A public URL alone is S1, unless a licence or permission proves more.
- No licence, or an unclear licence, is S1.
- A public paper with uncertain rights is S1 or S2. Full text stays off the site.
- Official documentation is S1 or S2 unless its licence permits reuse.
- MIT, BSD, and Apache-2.0 source is usually an S3 candidate, and only after provenance and dependency checks.
- MPL and LGPL are S3 conditional. A legal review is required before any copy.
- GPL and AGPL are S3 restricted. Specialist approval is required before any copy. This release does not copy them.
- CC0 or public domain is S4 only after the status is verified. Nothing in this registry is marked that way.
- CC-BY is S4 subject to attribution. Nothing in this registry is marked CC-BY.
- Written permission is S5. Blockchain Lab text is S5.
- A user upload would be U1. This site does not accept uploads.
Decision tree
- Is the source legitimate and the provenance recorded? If no, stop at S0 or S1. No export of content.
- Is there a clear licence or written permission? If no, stay at S1 or S2. Analysis only.
- Does that licence permit the planned act? If no or uncertain, do not copy. Ask for a review.
- Are the dependencies and embedded assets compatible? If unknown, hold the pack. This release has not reviewed dependency trees.
- Has the source passed security, maintenance, and integrity gates? If no, research exports only.
- Is the output a demo or a production system? Production is a separate human review. This site does not issue it.
- Can notices, attribution, and licence text be packaged? If no, do not export the code.
Export types
| Type | What it is | Minimum class | This release |
|---|---|---|---|
| E0 | Metadata. Title, URL, licence note, tier | S1 | Issued, without copied source |
| E1 | Research report. Original architecture summary | S1 | Issued, without copied source |
| E2 | Citation bundle. Links and bibliographic fields already held | S1 | Issued, without copied source |
| E3 | Pattern blueprint. Decision record. No copied source. | S1 | Issued, without copied source |
| E4 | Test plan. What a human should test. Not an exploit. | S1 | Issued, without copied source |
| E5 | Original scaffold. New Blockchain Lab text marked original. Not a copy of the repo. | S1 | Issued, without copied source |
| E6 | Source-derived demo pack. Adapted upstream code | S3 after gates | Refused |
| E7 | Full source bundle. Upstream archive or full PDF | S4 or S5 | Refused |
| E8 | Dataset export. Cleared full text or code corpus | Cleared rights on every item | Refused |
| E9 | Model-training pack. Corpus cleared for training | S4 or S5, plus a training review | Refused |
| E10 | Production candidate pack. Deployment materials | Human legal, security, and architecture review | Refused |
Licence matrix
Practical operating rules. Not a substitute for the licence text or for counsel. The least permissive dependency decides the pack. A fork is a separate record. Generated text is not upstream code. Vendored code, if it ever appears, is tracked on its own row.
| Licence | Class | Research | Source-derived | Required action |
|---|---|---|---|---|
| Public domain / CC0 | S4 after verification | Yes | Only after the status is verified | None of these components are marked public domain or CC0. |
| CC-BY | S4 with attribution | Yes | Only with attribution, and not in this release | No registry row is marked CC-BY. |
| MIT | S3 candidate | Yes | Held. Gates unmet. | Keep copyright and the licence notice. A public MIT file is not a finished export. |
| BSD-2-Clause / BSD-3-Clause | S3 candidate | Yes | Held. Gates unmet. | Keep notices. Read any non-endorsement term. |
| Apache-2.0 | S3 candidate | Yes | Held. Gates unmet. | Keep the licence and any NOTICE. Read the patent terms. |
| ISC / 0BSD / Unlicense | S3 candidate | Yes | Held until the file is the one you ship | Record provenance. Do not infer this from a missing file. |
| MPL-2.0 | S3 conditional | Yes | Held for legal review | Track modified files. Not in this registry as a single grant. |
| LGPL-2.1 / LGPL-3.0 | S3 conditional | Yes | Held for legal review | Linking and distribution need a reading before any copy. |
| EPL-2.0 / CDDL | S3 conditional | Yes | Held for legal review | File-level duties. Not treated as MIT. |
| GPL-2.0 / GPL-3.0 | S1 in this release | Yes | Blocked | Reference only. Do not copy the code in. |
| AGPL-3.0 | S1 in this release | Yes | Blocked | Network-use terms need specialist reading. Do not copy. |
| Business Source / BSL | S1 or S2 | Yes | No, unless the licence says so | Read the change date and the use limits. |
| Source-available / custom | S1 | Yes | Blocked | A custom community licence is not an OSI licence. |
| No licence | S1 | Metadata and original analysis | Blocked | Treat as all rights reserved. |
| Unknown or conflicting | S1 | Metadata | Blocked | Do not ingest the source. Escalate. |
| Written permission | S5 | Yes | Only inside the permission | Attach the scope to the manifest. None is attached here. |
| Blockchain Lab text | S5 | Yes | Yes, it is ours | Blueprints and this policy are Blockchain Lab text. Third-party repos are not. |
Reuse status is not the licence tier
Green would mean cleared
Compatible licence, official source, commit pinned, dependencies reviewed, notices known, no secrets, no blocking vulnerability, and a demo scope inside the licence. None of that is fully true here. Zero components show “demo export available”.
What the registry shows instead
A green or amber licence tier is “research available, reuse pending”. Red and grey are “reference only”. Pending is not a ticket. There is no review queue and no account.
Manifest
An E3 blueprint download carries this shape. Commit, hash, SBOM, and licence grant are null on purpose. The banner is mandatory.
RESEARCH / DEMO / TEST ONLY — NOT FOR PRODUCTION This package contains original Blockchain Lab text and references to external sources. It does not contain third-party source code. It has not been independently security audited. It has not been reviewed for legal, tax, securities, payments, custody, privacy, employment, data-protection or regulatory compliance. Do not deploy to mainnet, use with real funds, connect private keys, process personal data, or rely on this package in production. No commit is pinned. No secret scan, dependency review, or vulnerability review has been run. Source-derived export (E6 and above) is refused.
{
"export_id": "blc-exp-e3-20261001-openzeppelin-contracts",
"export_class": "E3",
"production_status": "NOT_FOR_PRODUCTION",
"copied_source": false,
"demo_export_available": false,
"licence": null,
"sbom_path": null,
"sources": [
{
"name": "OpenZeppelin Contracts",
"commit_sha": null,
"license_spdx": "MIT",
"source_class": "S3",
"reuse_mode": "cited"
}
]
}Files an E6 pack would have to contain
Listed so a later pack cannot ship without them. This release does not generate the directory.
- README.md
- RESEARCH_ONLY.md
- manifest.json
- SBOM.spdx.json
- AI-BOM.json
- THIRD_PARTY_NOTICES.md
- LICENSE_COMPATIBILITY_REPORT.md
- PROVENANCE_MANIFEST.json
- ROBUSTNESS_REPORT.md
- THREAT_MODEL.md
- TEST_PLAN.md
- OPEN_HUMAN_REVIEW_QUESTIONS.md
Takedown and corrections
Email [email protected] with the page URL, the material, and why it should change. This API does not store a notice. A credible claim is applied by editing the registry: the row moves toward S1 or drops out of “mention”, and the page keeps a correction note. The quarterly re-read is due 2027-01-01. It re-checks the licence files. It is not a promise to pin commits.
Corrections/Operating handbook
Machine-readable records
JSON is metadata. source_code and full_text are null. These routes send noindex. Private workspace pages are noindex. This policy is public.
Sources for the identifiers
- SPDX license list — identifiers only. We do not invent one when the file is mixed or custom.
- Open Source Initiative licences — approval of a licence is not approval of a repository.
- GitHub licence API — a detection hint. NOASSERTION means the file was read, not skipped.
