Skip to content

Export policy

Reference is broad. Copying is not.

Every public source may be cited. A source-derived pack leaves this site only after the licence, the commit, the dependencies, and a human review are real records. They are not.

This is an operating framework, not legal advice. It is not a finding by counsel. Non-commercial, demo, or test use does not remove copyright, licence, patent, contract, or export-control duties. A public repository is not permission to copy it.

Every public source may be referenced. Every source may be analysed within lawful access and platform terms. Only sources with a verified reuse basis may be exported, copied, packaged, redistributed, or used as source-derived code in a Build Pack.

Reference is broad. Analysis is broad. Export is conditional. Production is gated.

When in doubt, link — do not copy.

What this release will hand you

Research exports E0 to E5 are original Blockchain Lab text: metadata, a citation, a blueprint, a test outline, or a scaffold that does not copy a repository. E6 to E10 are refused. No component is marked “demo export available”. 27 repositories were licence-checked on 2026-10-01. None has a pinned commit.

  • Unmet: Official source verified beyond the URL recorded on 1 October 2026.
  • Unmet: Commit or release tag pinned.
  • Unmet: Transitive dependency licences reviewed.
  • Unmet: Licence text and notices packaged.
  • Unmet: Secret scan.
  • Unmet: Vulnerability review.
  • Unmet: Human approval for a source-derived export.
  • Unmet: SBOM generated from a lockfile.

Source access classes

ClassLabelBehaviourExport
S0BlockedDo not ingest the content. Keep a minimal compliance note if a notice requires it.No
S1Reference onlyMetadata, URL, identity, and original analysis. No source body.No source, code, or full-text export
S2Research analysisConcepts, structure, and test plans within the access you actually have.No raw source. No derived-code pack.
S3Reusable with conditionsA licence may allow a later governed pack. This release has not cleared one.Only after provenance, scans, notices, and approval
S4Full reuseHost or redistribute only with a verified right such as CC0 or an explicit redistribution grant.Yes, with attribution and the licence
S5Owned or permissionedBlockchain Lab wrote it, or written permission states the scope.As the permission allows
U1User-owned private sourcePrivate workspace only. The user confirms they may use it. No training by default.User-directed. Not built on this site.

How a class is assigned

  • A public URL alone is S1, unless a licence or permission proves more.
  • No licence, or an unclear licence, is S1.
  • A public paper with uncertain rights is S1 or S2. Full text stays off the site.
  • Official documentation is S1 or S2 unless its licence permits reuse.
  • MIT, BSD, and Apache-2.0 source is usually an S3 candidate, and only after provenance and dependency checks.
  • MPL and LGPL are S3 conditional. A legal review is required before any copy.
  • GPL and AGPL are S3 restricted. Specialist approval is required before any copy. This release does not copy them.
  • CC0 or public domain is S4 only after the status is verified. Nothing in this registry is marked that way.
  • CC-BY is S4 subject to attribution. Nothing in this registry is marked CC-BY.
  • Written permission is S5. Blockchain Lab text is S5.
  • A user upload would be U1. This site does not accept uploads.

Decision tree

  1. Is the source legitimate and the provenance recorded? If no, stop at S0 or S1. No export of content.
  2. Is there a clear licence or written permission? If no, stay at S1 or S2. Analysis only.
  3. Does that licence permit the planned act? If no or uncertain, do not copy. Ask for a review.
  4. Are the dependencies and embedded assets compatible? If unknown, hold the pack. This release has not reviewed dependency trees.
  5. Has the source passed security, maintenance, and integrity gates? If no, research exports only.
  6. Is the output a demo or a production system? Production is a separate human review. This site does not issue it.
  7. Can notices, attribution, and licence text be packaged? If no, do not export the code.

Export types

TypeWhat it isMinimum classThis release
E0Metadata. Title, URL, licence note, tierS1Issued, without copied source
E1Research report. Original architecture summaryS1Issued, without copied source
E2Citation bundle. Links and bibliographic fields already heldS1Issued, without copied source
E3Pattern blueprint. Decision record. No copied source.S1Issued, without copied source
E4Test plan. What a human should test. Not an exploit.S1Issued, without copied source
E5Original scaffold. New Blockchain Lab text marked original. Not a copy of the repo.S1Issued, without copied source
E6Source-derived demo pack. Adapted upstream codeS3 after gatesRefused
E7Full source bundle. Upstream archive or full PDFS4 or S5Refused
E8Dataset export. Cleared full text or code corpusCleared rights on every itemRefused
E9Model-training pack. Corpus cleared for trainingS4 or S5, plus a training reviewRefused
E10Production candidate pack. Deployment materialsHuman legal, security, and architecture reviewRefused

Licence matrix

Practical operating rules. Not a substitute for the licence text or for counsel. The least permissive dependency decides the pack. A fork is a separate record. Generated text is not upstream code. Vendored code, if it ever appears, is tracked on its own row.

LicenceClassResearchSource-derivedRequired action
Public domain / CC0S4 after verificationYesOnly after the status is verifiedNone of these components are marked public domain or CC0.
CC-BYS4 with attributionYesOnly with attribution, and not in this releaseNo registry row is marked CC-BY.
MITS3 candidateYesHeld. Gates unmet.Keep copyright and the licence notice. A public MIT file is not a finished export.
BSD-2-Clause / BSD-3-ClauseS3 candidateYesHeld. Gates unmet.Keep notices. Read any non-endorsement term.
Apache-2.0S3 candidateYesHeld. Gates unmet.Keep the licence and any NOTICE. Read the patent terms.
ISC / 0BSD / UnlicenseS3 candidateYesHeld until the file is the one you shipRecord provenance. Do not infer this from a missing file.
MPL-2.0S3 conditionalYesHeld for legal reviewTrack modified files. Not in this registry as a single grant.
LGPL-2.1 / LGPL-3.0S3 conditionalYesHeld for legal reviewLinking and distribution need a reading before any copy.
EPL-2.0 / CDDLS3 conditionalYesHeld for legal reviewFile-level duties. Not treated as MIT.
GPL-2.0 / GPL-3.0S1 in this releaseYesBlockedReference only. Do not copy the code in.
AGPL-3.0S1 in this releaseYesBlockedNetwork-use terms need specialist reading. Do not copy.
Business Source / BSLS1 or S2YesNo, unless the licence says soRead the change date and the use limits.
Source-available / customS1YesBlockedA custom community licence is not an OSI licence.
No licenceS1Metadata and original analysisBlockedTreat as all rights reserved.
Unknown or conflictingS1MetadataBlockedDo not ingest the source. Escalate.
Written permissionS5YesOnly inside the permissionAttach the scope to the manifest. None is attached here.
Blockchain Lab textS5YesYes, it is oursBlueprints and this policy are Blockchain Lab text. Third-party repos are not.

Reuse status is not the licence tier

Green would mean cleared

Compatible licence, official source, commit pinned, dependencies reviewed, notices known, no secrets, no blocking vulnerability, and a demo scope inside the licence. None of that is fully true here. Zero components show “demo export available”.

What the registry shows instead

A green or amber licence tier is “research available, reuse pending”. Red and grey are “reference only”. Pending is not a ticket. There is no review queue and no account.

Manifest

An E3 blueprint download carries this shape. Commit, hash, SBOM, and licence grant are null on purpose. The banner is mandatory.

RESEARCH / DEMO / TEST ONLY — NOT FOR PRODUCTION

This package contains original Blockchain Lab text and references to external sources.
It does not contain third-party source code.

It has not been independently security audited.
It has not been reviewed for legal, tax, securities, payments, custody, privacy, employment, data-protection or regulatory compliance.
Do not deploy to mainnet, use with real funds, connect private keys, process personal data, or rely on this package in production.

No commit is pinned. No secret scan, dependency review, or vulnerability review has been run.
Source-derived export (E6 and above) is refused.
{
  "export_id": "blc-exp-e3-20261001-openzeppelin-contracts",
  "export_class": "E3",
  "production_status": "NOT_FOR_PRODUCTION",
  "copied_source": false,
  "demo_export_available": false,
  "licence": null,
  "sbom_path": null,
  "sources": [
    {
      "name": "OpenZeppelin Contracts",
      "commit_sha": null,
      "license_spdx": "MIT",
      "source_class": "S3",
      "reuse_mode": "cited"
    }
  ]
}

Files an E6 pack would have to contain

Listed so a later pack cannot ship without them. This release does not generate the directory.

  • README.md
  • RESEARCH_ONLY.md
  • manifest.json
  • SBOM.spdx.json
  • AI-BOM.json
  • THIRD_PARTY_NOTICES.md
  • LICENSE_COMPATIBILITY_REPORT.md
  • PROVENANCE_MANIFEST.json
  • ROBUSTNESS_REPORT.md
  • THREAT_MODEL.md
  • TEST_PLAN.md
  • OPEN_HUMAN_REVIEW_QUESTIONS.md

Takedown and corrections

Email [email protected] with the page URL, the material, and why it should change. This API does not store a notice. A credible claim is applied by editing the registry: the row moves toward S1 or drops out of “mention”, and the page keeps a correction note. The quarterly re-read is due 2027-01-01. It re-checks the licence files. It is not a promise to pin commits.

Corrections/Operating handbook

Machine-readable records

JSON is metadata. source_code and full_text are null. These routes send noindex. Private workspace pages are noindex. This policy is public.

Sources for the identifiers