Preamble

The Problem This Standard Solves

The x402 whitepaper (Coinbase Developer Platform, May 2025) solved a real problem: legacy payment rails were designed for humans, not machines. API keys, subscriptions, manual billing — none of it works for autonomous agents that need to transact at machine speed. x402 implemented the long-reserved HTTP 402 status code, enabling any server to charge any caller in stablecoin with 200ms settlement and near-zero fees. That is a genuine contribution.

It also created a new attack surface. Simultaneously, three protocols are assembling a machine-native payment economy with no constitutional layer: x402 (HTTP 402, pay-per-call), MCP (Model Context Protocol — agents accessing tools and data), and AP2 + TAP (Google and Visa's agent identity and payment standards via Stripe and Coinbase). These protocols enable autonomous agents to initiate, authorize, and execute financial transactions faster than any human compliance review can operate — with no identity verification, no authorization chain, no asset classification, and no jurisdictional anchor.

This is not hypothetical. The Conduent breach of September 2025 exposed 25 million government and healthcare records through a single unguarded pipe. Not through the agency. Through the connection. 80% of 2025 ransomware attacks now leverage AI tools. The attack surface is widening every quarter and the controls have not changed.

Threat I
Legacy Proprietary Systems
State and municipal systems run on proprietary technology that cannot be patched at attack speed. No constitutional layer. No sovereign control. Vendor remediation on the vendor's timeline at the vendor's price.
Threat II
Open API Endpoints
Modernization requires open APIs. Every open endpoint is a potential entry point. Every third-party integration is a supply chain risk. The controls that govern legacy systems were never designed to defend open API surfaces.
Threat III
Autonomous Payment Agents
The most acute emerging risk has no precedent in existing control frameworks. Agents operating via x402 + MCP + AP2/TAP execute financial transactions at machine speed with no credential verification and no audit trail to an accountable human.
AgentCash turns agents into spenders.
AP2 + TAP gives agents an identity owned by the platform, not the person.
MCP gives agents access to tools and data with no credential verification.
M5x402 turns agents into licensed economic citizens of specific sovereigns — every agent credentialed, every payment TCID-signed, every action auditable back to the accountable human.
Why Certification Is the Gate — Not an API Key
M5x402 endpoints move titled sovereign assets with real legal, financial, and jurisdictional weight. An M4 gold bond, an M3 real estate title, an M2 renewable energy credit — these are not API credits. Certification ensures every developer understands the asset class they are handling, the account type their counterparties hold, and the legal framework governing every transaction before they write a single line of integration code.
THE CYRUS PROTOCOL — THE CONSTITUTIONAL GATE TO INTERNET 3.0
The existing global financial system is a closed market. SWIFT access is controlled by a small group of nations. Correspondent banking is gatekept by dominant financial centers. Sanctions regimes — however justified in intent — have locked out entire populations who had no say in their government's decisions. An Iranian family running a legitimate business, a Cuban researcher receiving payment for scientific work, a Venezuelan engineer building a company — all locked out not because of who they are, but because of where they were born. The current system punishes people for the decisions of governments they did not choose.

M5 is a fresh start for the world. The USC standard is designed with Nash Equilibrium mathematics — the incentive structure rewards participation and makes sovereignty valuable, rather than punishing deviation with exclusion. No nation is permanently locked out. Every sovereign has the same path. The gate is identical for everyone: five human rights commitments derived from the Cyrus Cylinder (539 BCE), the world's first known charter of human rights.

Nations currently under sanctions, in conflict zones where banking infrastructure has collapsed, in the Global South structurally excluded from developed-market financial access — all have the same path to Internet 3.0 as the largest economies on earth. The Cyrus Protocol asks less of any sovereign than the existing correspondent banking system demands, while asking more in terms of human dignity. That is the design. Internet 3.0 is not the world map. It is the world map of sovereigns that choose to commit to their own people. M5Canon enforces ratification at Layer 0 before any chain activates — not to exclude, but to ensure that every chain that activates is one that has made that commitment.
COMMITMENT I
Freedom of Religion & Belief
No enforcement of state religion or belief system on citizens
COMMITMENT II
Freedom from Slavery
No forced labor, indentured servitude, or trafficking
COMMITMENT III
Freedom of Movement
Citizens may leave and return without state persecution
COMMITMENT IV
Property Rights
No arbitrary seizure of property without due process
COMMITMENT V
Peaceful Coexistence
No aggression against neighboring peoples or sovereign jurisdictions
RATIFIED — WHAT OPENS
Chain activated on Internet 3.0 · Sovereign CBDC issuance authorized (intergovernmental settlement only) · Stablecoins recognized across all ratified chains · M5Bank accounts issued to citizens, businesses, institutions · M5Wallets credentialed under the sovereign USC code · Full access to M5 Global Index and exchange markets · CEDECO.eth certification for BOI institutions in that jurisdiction · Participation in the global adjudication pool under ICSN Global
THE NASH EQUILIBRIUM — WHY THIS WORKS
The value of Internet 3.0 participation compounds as more sovereigns join. Every new ratified chain expands the network that every existing member participates in. No single actor can improve their position by defecting — the incentive is always toward ratification. Countries that were previously excluded from the legacy financial system now have a path that rewards human rights commitments rather than geopolitical alignment with dominant financial powers. The math makes inclusion rational. The protocol makes it constitutional.
THE PATHWAY — FOR EVERY SOVEREIGN
Nations currently under sanctions, in conflict zones, historically excluded from developed-market financial access — all have the same path as the largest economies on earth. The Cyrus Protocol requires five human rights commitments. The existing correspondent banking system requires SWIFT membership, FATF compliance, IMF program alignment, and geopolitical favor. The Cyrus Protocol bar is lower institutionally and higher in human dignity. Nations reforming toward these commitments engage with ICSN Global working groups as part of the ratification pathway. The Internet 3.0 map grows. No sovereign is permanently excluded — only those whose governments choose not to commit to their own people.
THE FOUR-LAYER CONSTITUTIONAL ARCHITECTURE
LAYER 1 — THE OPEN STANDARD
USC Economic Standard
+ M5-AAIF (Linux Foundation)
The USC (Universal Sovereign Code) is the open economic standard. Every nation, state, tribe, and territory determines their own digital asset transaction standards using it — from CBDCs to stablecoins to real-world asset-backed tokens. The tokenomics are designed from the sovereign human (BOM) through legal entities (BOU, BOB, BOI, BOG) through the governance layer (ICSN Global) to the global adjudication pool. This is open-source. Any sovereign can implement it. No one owns the standard. M5 is donating the open-source protocol framework to the Linux Foundation as the M5-Agentic AI Foundation (M5-AAIF) — the neutral global standard for AI agent economics.
LAYER 2 — THE GOVERNANCE
ICSN Global Foundation
Wyoming DUNA
ICSN Global — converting to a Wyoming DUNA — governs the standard through human-led working groups and the global adjudication pool. Three credentialing gates ICSN controls:

CEDECO.eth — Certificate of Issuance for M4 Securities (financial instruments). Requires DTTC membership (U.S.) or equivalent clearing participant (Euroclear · JASDEC · CCASS · CREST globally).

CFTC Commodity Credentials — CPO (Commodity Pool Operator): operates pooled M2 commodity token investment vehicles trading futures and forex. CTA (Commodity Trading Advisor): advises on M2 commodity token positions within the MINERA, VIRDIS, TERRAVERTE, and other M5 index channels.

BRIDGE (Blockchain Registry Interbank Digital Asset Gateway Exchange) — 11,000+ SWIFT BIC codes and participant codes mapped to sovereign ENS BOI accounts. Legacy financial institutions bring their existing SWIFT identity; BRIDGE maps it to their M5 sovereign routing identifier and M4/M5 member account. No existing institution abandons its legacy infrastructure to participate.

Adjudication pools (NYCP©, state pools, unitednationschain.eth) are the constitutional enforcement mechanism. Pamela Norton retains founding authority as CEA. Governance is decentralized. No single entity controls the standard.
LAYER 3 — THE ENGINE
M5Canon Engine
Sovereign Banking Service Licence
M5Canon is not part of the open-source donation. It is the sovereign banking service engine licensed under the TitleChain Foundation — a Wyoming 1,000-Year Sovereign Purpose Trust. The trust terms are constitutionally fixed for 1,000 years. The licence fee flows permanently to TitleChain Foundation. M5Canon cannot be altered, forked, modified, or overridden by any licensee, any working group, any foundation, or any government entity — ever. Not by ICSN Global. Not by M5-AAIF. Not by any sovereign adopter of the USC standard. The engine is the engine. The licence is what any party pays for the right to operate sovereign banking infrastructure on M5Canon.
LAYER 4 — THE ENTERPRISE
M5Capital Holdings LLC
Enterprise Licensee
M5Capital Holdings LLC is the primary licensee of M5Canon — the enterprise and custom implementation layer. M5Capital builds sovereign banking infrastructure (M5Bank, SOPHIA credentials, M5 MCP server stack, TitleChain registry operations) on top of the licensed M5Canon engine. Other enterprises seeking to build sovereign banking infrastructure on M5Canon licence through M5Capital Holdings. M5Capital is the commercial gateway to the sovereign infrastructure that the USC standard describes but does not implement. The licence is proprietary. The implementation is proprietary. The standard above it is open.
Layer 1: USC Standard open (AAIF / Linux Foundation) · Layer 2: Governance decentralized (ICSN Global DUNA — CEDECO · BRIDGE · CFTC) · Layer 3: Operations proprietary (M5Capital Holdings — enterprise licensee) · Layer 4: Constitutional anchor immutable (TitleChain Foundation — Wyoming 1,000-Year Sovereign Purpose Trust — M5Canon licensor) — These four layers are constitutionally separate and cannot collapse into each other. No single entity controls all four. No single entity ever will.

Section 1

The M5 Asset Classification Standard (M1–M5)

M5CANON — CONSTITUTIONAL LAYER 0
M5Canon is not a blockchain. It is not a settlement rail. It is the constitutional enforcement engine that sits at Layer 0 — beneath every chain, beneath every rail, beneath every device and agent. It establishes the provenance and origination of trust from the moment an asset or identity is created, and enforces classification, routing, and compliance across every chain the asset subsequently touches. M5Canon does not move assets. It determines whether they can move, on which rail, under which credential, and creates the immutable tamper-evident event record that follows the asset regardless of which chain executes settlement.
PROVENANCE CHAIN — FROM PHYSICAL INFRASTRUCTURE TO HUMAN AUTHORITY
DARK FIBER
IRU capacity on ICSN-controlled dark fiber routes (Zayo, Lumen, Crown Castle, Uniti; Telxius/TE SubCom submarine internationally). Sovereign physical network — node-to-node traffic routed outside incumbent carriers.
SILICON
Chip, FPGA, TEE, QCaaS hardware. ZK proofs generated and keys minted at the hardware root of trust. BTQ QCIM → QPerfect silicon roadmap.
DEVICE
Handset, SV-GW registered device, eSIM sovereign device, M5Node validator. Device TCID issued and anchored to TitleChain.
AGENT
M5HUM-authorized agent operating under M5Mandate. Credentialed, bound, auditable. Cannot act beyond its signed mandate scope.
HUMAN
M5HUM credential holder. The sovereign person who is the constitutional authority. Every transaction traces back here. No agent supersedes the human.
M5CANON L0
Classifies, enforces, routes, records. Every event across every chain. Immutable. Tamper-evident. Chain-agnostic.
x402 starts at the HTTP request. M5Canon starts at the dark fiber. This is the complete provenance chain — physical infrastructure to constitutional enforcement — that no existing payment infrastructure tracks.
M5HUM DEVICE SOVEREIGNTY — EVERY DEVICE TITLED AND CONTROLLED BY THE HUMAN

Every device a M5HUM account holder owns — mobile phone, tablet, laptop, smart glasses, watch, eSIM, IoT sensors, and any agent connected to them — is registered, titled, and controlled as a sovereign M3 asset under the M5HUM credential. The human holds the title. The human holds the keys. No platform, no government entity, and no agent can access, revoke, or transfer device control without explicit human authorization via the M5Mandate — and no M5Gov entity can compel access without serving due process through the adjudication pool system, following the laws of the jurisdiction embedded in the device's USC code at the moment of registration.

📱
Mobile / Phone
4-stage sovereignty pipeline: FIND→ATTEST→CONTROL→TOKENIZE via Telnyx + NPAC + STIR/SHAKEN + UCC Art.12 CER mint
💻
Laptop / Tablet
Device TCID issued. TEE-bound key storage. SV-GW encrypted channel. All agent tunnels route through sovereign gateway.
Watch / Glasses
Wearable device registration as M3 sovereign asset. Biometric data stays in M5POD vault — never on platform servers.
📡
eSIM / IoT
eSIM ownership token on sovereign chain. IoT sensors registered as SV-GW devices feeding oracle-verified M2 data.
🤖
Connected Agents
Every AI agent authorized by the M5HUM via signed M5Mandate. Agents are credentialed extensions of the human — not autonomous actors.
🌐
Social / Email
Social accounts and email addresses registered as sovereign identity records under the M5HUM credential. Member controls their digital identity graph.
UCC ARTICLE 12 CER — 33 STATES
UCC Article 12 — Controllable Electronic Records (2022 UCC Amendments, promulgated by the Uniform Law Commission and American Law Institute) — is now enacted in 33 U.S. jurisdictions including Alabama, California, Colorado, Delaware, Florida, Georgia, Hawaii, Indiana, Iowa, Kentucky, Louisiana, Maine, Minnesota, Nebraska, Nevada, New Hampshire, New Mexico, New York, North Dakota, Oklahoma, Pennsylvania, Rhode Island, South Dakota, Tennessee, Virginia, Washington, and the District of Columbia, with more legislatures expected to follow. New York's enactment (Assembly Bill 3307/Senate Bill 1840, signed December 5, 2025) is effective June 3, 2026 — the most commercially significant enactment given New York's role as the governing law in the majority of U.S. commercial financings. It establishes that a controllable electronic record (CER) — including a tokenized phone number, a device title, a genomic SNP token, or any M3 digital asset — can be owned, transferred, and legally controlled in the same manner as tangible personal property. M5 device tokens are issued as UCC Article 12 CERs under the sovereign chain of the member's jurisdiction. The USC code embedded at registration is the jurisdictional anchor that determines which state's CER law governs. A Wyoming-registered device is governed by Wyoming CER law. A California device by California CER law. The token is the legal instrument. The member is the controller of record.
DUE PROCESS PROTECTION — NO UNAUTHORIZED ACCESS
No M5Gov entity — no government agency, no regulatory body, no law enforcement authority — can access, seize, transfer, or revoke a M5HUM member's devices, data, or keys without serving due process through the M5 adjudication system. The jurisdiction is not abstract — it is embedded in the device's USC code at the moment of registration and carried in every transaction record thereafter. Interstate jurisdiction is governed by the state laws of the registered jurisdiction. Federal jurisdiction requires federal process through the NYCP© federal pool. International process routes through unitednationschain.eth. The member is the controller of record under UCC Article 12 CER. Control cannot be transferred without the member's consent or a valid adjudication order served through the correct jurisdictional pool.
ADJUDICATION POOLS — THE ENFORCEMENT LAYER
The adjudication pool system is where due process actually runs. Three pools govern three jurisdictional layers:

State Pools — 50 U.S. state adjudication pools handle disputes, reclamation notices, and access orders within their jurisdiction. Staffed by credentialed M5 Agentic Law Judges and human adjudicators. All orders are on-chain, verifiable, and carried in the USC event trail.

NYCP© Federal Pool — the New York Constitutional Protocol federal adjudication pool handles interstate and federal process. Federal agencies that wish to compel access to a M5HUM device must file through NYCP© — the order is verified, the USC jurisdiction confirmed, and the due process record is immutable.

unitednationschain.eth — the international adjudication pool for cross-border and treaty-governed process. Governed by ICSN Global working groups with human-led adjudication panels. BPS BP14 funds the arbitration pool infrastructure from every Complete-scope transaction.
Every device registration, every data access request, every agent authorization, and every adjudication order is recorded on TitleChain — immutable, timestamped, jurisdictionally anchored, and publicly verifiable at M5Scan.io. The jurisdiction travels with the asset from silicon to settlement.

M5Canon determines asset classification from the asset definition — you do not choose it. Attempting to misclassify an asset to access lower-friction rails is detectable at Layer 0 and constitutes a compliance failure logged to the tamper-evident event chain. The rails listed below are representative examples of the verified settlement infrastructure available to each class — not an exhaustive market listing. Rail access requires a verified M5Bank account. The M5Wallet is the credential gate to all markets.

ClassNameWhat It IsExamplesCred MinRail Examples (not exhaustive)
M1 Utility Cash-equivalent platform credits and payment tokens. Broadest rail set — any verified M5Bank account, any compatible chain TCUSD credits, compute tokens, API access, gig labor, time-denominated services, private stablecoins, MTL-licensed transfers L1 Cosmos/IBC · Base L2 · Bitcoin/Lightning · EVM chains · Solana · XRP · OpenFX · BorderLess · Circle/USDC · MTL rails · Formance Numscript · Dfns multi-chain
M2 Commodity Sensor-verified measurable production output. Lives on M5Bank member books. M5 Global Index private pools as primary liquidity venue RECs, gold-backed certificate tokens, carbon offsets, minerals, agricultural, biodiversity credits L2 M5 Index pools · BTC Ordinals/Taproot · Cosmos IBC · EVM chains · Solana · Cardano · Ondo Finance · Chainlink oracles · Storj/Arweave
M3 Titled Asset Cryptographic proof-of-title. TitleChain is the legal chain-of-custody registry for every M3 asset regardless of which chain holds it. The chain provides issuance, transfer, and settlement infrastructure. TitleChain provides the immutable chain of title. M5Wallet is the access gate to all M3 markets. Sovereign identity tokens, real estate, classic cars, luxury goods, tickets, mileage, IP rights, device titles, genomic SNP tokens L3 M5 Index pools · Solana · Polygon · Aptos · Avalanche (AVAX) · Cardano (ADA) · Sui · Hedera · Stellar · Base/EVM · Cosmos IBC · BTC Ordinals · Arweave/Storj · Chainlink
M4 Security Investment-grade instruments backed by M2/M3 assets. CEDECO.eth Certificate of Issuance required before any market access. Traded on regulated institutional venues — not public DEXes. BOI account + SwiftBRIDGE mapping required. PCM Gold Bond, Kisosen REC offering, equity tokens, notes, certificates, SAFEs L4 + BOI Canton/DAML · EVM chains · Bullish · Liquid Mercury · Hiive · Zoniqx · Rialto Markets · tZERO · INX · Kraken SPDI · XRP · USDC/USDT
M5 Sovereign/Gov Intergovernmental settlement layer for Cyrus Protocol-ratified sovereigns only. CBDCs move between sovereign chains — nation-to-nation, state-to-state, intergovernmental. Never retail. Never M5x402-accessible. Never issued to individuals or businesses. CBDC firewall blocks all access at Layer 0. CYRUS Protocol ratification records · TCID system · M5Gov BOG accounts · intergovernmental treaty instruments · sovereign CBDC issuance · Cyrus Cylinder (539 BCE) — constitutional basis BOG only Intergovernmental only · Canton CBDC-grade · Federal Reserve
M1 OPEN NETWORK — VERIFIED M5BANK ACCOUNTS ONLY
Money Transmitter Licensed
Any verified M5Bank account holder with an active MTL in their jurisdiction (USC-anchored) can move M1 value via traditional banking rails alongside blockchain rails. The MTL maps to the member's USC jurisdiction code and is verified on M5Scan.io. Examples: state-licensed money transmitters, MSBs registered with FinCEN, international payment institutions.
Borderless FX Settlement
OpenFX — open foreign exchange settlement for cross-jurisdiction M1 flows. BorderLess — borderless payment infrastructure for international M5Bank members. Ripple/XRP — cross-border M1 settlement especially for nation chains where legacy correspondent banking is slow or unavailable. Stablecoins can move across all these rails — jurisdiction determines which stablecoin list applies per USC code.
Cosmos / IBC — the Interchain Backbone
TitleChain and ICSN registry live on Cosmos for on-chain provenance. Cosmos EVM is where M5Canon's Layer 0 provenance chain anchors cross-chain state. IBC (Inter-Blockchain Communication) enables any Cosmos-connected chain to participate in M1 settlement natively. This is the interoperability backbone that connects sovereign chains across 170+ nations.
The CBDC Firewall
M5-class instruments are intergovernmental settlement instruments only — they move between sovereign chains (nation to nation, state to state, tribal government to federal government) through BOG account holders on the M5Gov layer. They are never issued to retail participants. They are never accessible through M5x402 endpoints. A CBDC on the M5 network is the constitutional instrument of a Cyrus Protocol-ratified sovereign — it settles obligations between sovereigns, not between people or businesses. The CBDC firewall is enforced at Layer 0 by the CYRUS Protocol before any other gate executes. If your endpoint routes an M5-class instrument, the transaction is blocked, the event is logged, and a M5Watcher alert is issued. There is no override.

1.1 TCUSD — Platform Credits, Not a Retail Stablecoin

TCUSD is the credit unit that members hold in their M5Bank account to operate on the platform. It is M1 class. It is not a retail stablecoin, not listed on exchanges, and not a consumer payment instrument. It is the unit of account the M5Canon engine uses to record activity on the internal ledger — the way a bank's general ledger uses a base currency before external settlement occurs.

When an entity pays for registration, credentials, API access, or any platform service, the payment is made in an approved sovereign stablecoin or the entity's own private stablecoin — then recorded as TCUSD credits on the internal ledger. The TCUSD balance is what M5Canon reads when processing any platform action.

Every TCUSD credit carries a USC (Universal Sovereign Code) — the jurisdictional identifier that anchors the credit to the sovereign chain of the issuing entity. USC is not a token. It is a classification and routing code embedded in every TCID and transaction record:

USC — Universal Sovereign Code
The ENS domain is the sovereign identity in full human-readable form. The USC code is the same identity compressed into a short machine-readable format that drops directly into regulatory reporting fields, clinical data exchanges, energy grid schemas, and financial messaging standards without transformation. One identity. Two representations. USC is the field-level encoding. ENS is the namespace. Both are authoritative. M5 is targeting finance, energy, and health as the first three critical infrastructure pillars — the USC code is designed to be natively compatible with the dominant standards in all three sectors simultaneously.
◈ FINANCE STANDARDS
ISO 20022 — pacs.008 (InstrPty), camt.053 (AcctSvcrRef), pain.001 (InitgPty)
SWIFT BIC — routing tables via SwiftBRIDGE mapping
FASB ASC 718/740/810 — equity, tax, consolidation jurisdiction
IFRS 9/15/16 — international financial instrument standards
SEC / FinCEN — regulatory reporting schemas
UCC Article 12 CER — 2022 UCC Amendments · 33 U.S. jurisdictions enacted · NY effective June 3, 2026
GENIUS Act (S.1582) — signed July 18, 2025 · Senate 68–30 · House 308–122 · federal stablecoin framework
◈ ENERGY STANDARDS
FERC — Federal Energy Regulatory Commission reporting schemas
EIA-923 / EIA-860 — generation and fuel data reporting
NERC CIP — Critical Infrastructure Protection, grid security
IEEE 2030 — smart grid interoperability standard
REC Tracking — WREGIS, GATS, M-RETS, NC-RETS
ISO 50001 — energy management systems standard
GHG Protocol — Scope 1/2/3 greenhouse gas accounting
FASB ASC 818 — Collaborative Arrangements · governs joint ventures, cooperative energy partnerships, and multi-party REC/carbon production arrangements on M5 (Kisosen, tribal energy JVs, West Edge Energy, ONE.BALI and equivalent cooperative structures)
NAICS 22 — utilities sector codes · UN SDG 7
◈ HEALTH STANDARDS
HIPAA — Privacy Rule, Security Rule, Transaction Standards (45 CFR 160/164). USC carries covered entity jurisdiction identifier
HL7 FHIR R4/R5 — health data interoperability. USC maps to FHIR Organization.identifier
ICD-10 / ICD-11 — WHO diagnosis codes in M3 health asset records
CPT / HCPCS — AMA procedure billing codes for health service tokens
LOINC — lab and clinical observation identifiers for SNP/genomic tokens
SNOMED CT — clinical terminology for diagnosis and procedure M3 assets
NPI / NDC — CMS provider registry · FDA drug identification
CMS-1500 / UB-04 — claim form standards for health payment rails
SE4 — Self-Determination standard for sovereign consent gates
VCF / FASTQ / BAM — genomic file format standards for 23andmine vault records
23ANDMINE VAULT — M5HUM GENOMIC SOVEREIGNTY
What the vault holds
Full genomic sequence & code · SNP tokens (individual nucleotide polymorphisms mapped to TCID ownership) · Whole genome, exome, methylation, FASTQ/BAM files · Stem cell preservation records · All derivative research outputs. Every item is a titled M3 asset under the M5HUM credential. No third party holds a first position.
Three-layer consent gate
Layer 1 ZK proof of credentialed status (m5CredentialProof circuit)
Layer 2 Notarized Sovereign Consent (SE4 self-determination)
Layer 3 Digital Twinning Guard — prevents derivative reconstruction of original sequence. Member controls every gate. Revocable at any time.
Reclamation & cooperative
Sovereign Data Reclamation Notices served by member's state BOG authority to any corporation holding their data — requiring full extraction, destruction of all copies including de-identified data, and confirmed deletion (8-stage pipeline: DRAFTED → SERVED → ACKNOWLEDGED → EXTRACTING → EXTRACTED → DESTROYING → DESTROYED → COMPLETED).

23andmine.eth BOU cooperative — opt-in personalized medicine research on member's terms. Member earns SNP tokens for each contribution. Retains revocation rights.
FORMAT: USC-[ISO2]-[STATE/REGION]-[ENTITY-ID]-[SEQUENCE] · ISO2 = ISO 3166-1 alpha-2 nation code · STATE = SOS jurisdiction · ENTITY = M5Canon classifier · SEQUENCE = registry serial
ENS Domain (Internet 3.0 Identity)
USC Short Code (ISO 20022 / FASB / SWIFT)
Jurisdiction / Entity
Std Compatibility
wyomingchain.unitedstateschain.eth
USC-US-WY-0001
Wyoming — State sovereign chain
ISO 20022
FASB ASC 740
californiachain.unitedstateschain.eth
USC-US-CA-0001
California — State sovereign chain
ISO 20022
FASB ASC 740
m5capital.bob.wyomingchain.unitedstateschain.eth
USC-US-WY-M5CAP-0001
M5Capital LLC — Wyoming BOB entity
SWIFT pacs.008
FASB ASC 810
navajochain.unitedstateschain.eth
USC-US-TR-NAV-0001
Navajo Nation — Tribal sovereign chain
ISO 20022
BIA Tribal codes
hhs.bog.unitedstatesgovernment.eth
USC-US-GOV-HHS-0001
US HHS — Federal agency BOG
FedRAMP
SWIFT TREAS33
bhutanchain.eth
USC-BT-GOV-0001
Kingdom of Bhutan — Sovereign nation chain
ISO 20022
SWIFT BNBTBTBT
icsnglobal.eth
USC-XX-STD-0001
ICSN Global — Multi-jurisdiction standards body
ICSN STD
Multi-jurisdiction
USC codes are embedded in every TCID, every BPS fee event, every ISO 20022 message field (pacs.008 InstrPty, camt.053 AcctSvcrRef, pain.001 InitgPty), and every FASB journal entry as the jurisdiction classifier. Resolve any USC code to its full ENS identity at m5scan.io/usc/[code] — or resolve any ENS to its USC at m5scan.io/ens/[domain].
TCUSD Credit Flow — Transparent Wallet Split Architecture
Member Payment
(approved sovereign stablecoin
or private M1 stablecoin)
M5Capital Holdings
Platform operator
secures the network
→ wallet split →
TitleChain Foundation
Registry engine. Records every title, issuance, transfer. Bitcoin-anchored.
ICSN Global
Standards body and DAO governance. Working groups. Interoperability.
Adjudication Pools
NYCP© federal pool, state pools, unitednationschain.eth international pool.
Commons Pool
CPI eco relief (CHILDREN, UTIL, FOOD, INFRA). Local infrastructure. Community support.

Every split is on-chain and verifiable. Fees are local-first — majority stays in the sovereign jurisdiction where value was created. ICSN/federal-layer fees fund resilience infrastructure. This is the constitutional answer to extractive platform economics.

1.2 Private Stablecoins and Sovereign Approved Stablecoins

GOVERNING LAW REFERENCE — STABLECOINS & DIGITAL ASSET TITLE
GENIUS Act — S. 1582, 119th Congress
Guiding and Establishing National Innovation for U.S. Stablecoins Act. Signed into law by President Trump on July 18, 2025. Senate vote: 68–30. House vote: 308–122. Establishes the first federal regulatory framework for payment stablecoins. Restricts issuance to permitted stablecoin issuers — subsidiaries of insured depository institutions, OCC-supervised nonbanks, or state-chartered entities under substantially similar state regimes. Requires 1:1 reserves. Subjects issuers to Bank Secrecy Act. Payment stablecoins are expressly not securities or commodities under federal law. Effective: earlier of 18 months after enactment or 120 days after final federal regulations.
UCC Article 12 CER — 2022 UCC Amendments
Promulgated by the Uniform Law Commission and American Law Institute in July 2022. Establishes Controllable Electronic Records (CERs) as a distinct asset class — including cryptocurrencies, NFTs, tokenized rights, and M3 digital assets — with clear rules for ownership, transfer, perfection, and priority. A qualifying purchaser who obtains control of a CER for value, in good faith, and without notice of a competing claim takes free of that claim. Enacted in 33 U.S. jurisdictions as of December 2025: Alabama, California, Colorado, Delaware, Florida, Georgia, Hawaii, Illinois, Indiana, Iowa, Kentucky, Louisiana, Maine, Minnesota, Nebraska, Nevada, New Hampshire, New Mexico, New York, North Dakota, Oklahoma, Pennsylvania, Rhode Island, South Dakota, Tennessee, Virginia, Washington + D.C. and others. New York (Assembly Bill 3307-A / Senate Bill 1840-A, signed December 5, 2025): effective June 3, 2026.

NOT YET ENACTED (as of April 2026)
Alaska · Arkansas · Connecticut · Idaho · Kansas · Maryland · Michigan · Mississippi · Missouri · Montana · New Jersey · North Carolina · Ohio · Oregon · South Carolina · Texas · Utah · Vermont · Wisconsin · Wyoming
These states still treat digital assets as general intangibles under Article 9 — perfection by filing only, no control-based priority, no take-free rule for qualifying purchasers. Entities operating in these states should specify an enacted-state jurisdiction in their CER records where possible. Check ULC tracker at uniformlaws.org for current status as legislatures continue to act.

⚠ NOTE ON WYOMING — M5 HOME JURISDICTION
Wyoming has led the nation in digital asset legislation across many fronts — SPDI charter, DAO LLC law, digital asset property exemptions, and the Wyoming Utility Token Act. However, Wyoming has not yet enacted UCC Article 12 CER. This means Wyoming citizens and entities do not currently have the legal protections that 33 other jurisdictions now provide — including control-based perfection of digital assets, the take-free rule for qualifying purchasers, and the clear chain-of-title framework for CERs. Wyoming-registered M5 entities should specify an enacted-state jurisdiction (such as Delaware, California, or New York after June 3, 2026) in their TCID and CER records as the governing CER jurisdiction until Wyoming acts. M5 is part of the advocacy infrastructure pushing Wyoming to close this gap — the state that chartered the SPDI and the DAO LLC should be the first to complete UCC Article 12 enactment, not among the last.

Every M5Bank member can issue their own private M1 stablecoin on any chain, denominated in their jurisdiction's approved currency, representing the value of their products or services. Entities that prefer not to issue their own stablecoin default to the approved sovereign stablecoin list for their chain — Wyoming's approved list, California's, the Navajo Nation's — determined by the sovereign chain under the GENIUS Act (Guiding and Establishing National Innovation for U.S. Stablecoins Act, S. 1582, 119th Congress, signed into law July 18, 2025 by President Trump — Senate vote 68–30, House vote 308–122) and UCC Article 12 CER (enacted in 33 jurisdictions as of December 2025; New York effective June 3, 2026). The GENIUS Act establishes the first federal regulatory framework for payment stablecoins — restricting issuance to approved permitted stablecoin issuers, requiring 1:1 reserves backed by U.S. dollars or low-risk assets, and subjecting issuers to Bank Secrecy Act obligations. The USC code embedded in every M5 transaction record is the jurisdictional anchor that determines which state's approved stablecoin list applies. External stablecoins are the settlement medium. TCUSD is the internal ledger representation.

1.3 TC-MGT — Treasury Reserve Only

TC-MGT (Minera Gold-Backed Token) is the M5Bank treasury reserve instrument. It is M2 class, not M1. TC-MGT is backed by verified in-situ gold assets held by credentialed M5Bank member entities in the mining sector — spanning junior explorers and development-stage operations such as Portuguese Creek Mine through to major producers and institutionally recognized counterparties such as Newmont, Agnico Eagle, and Barrick Gold, with settlement and assay standards governed by the London Bullion Market Association (LBMA). The LBMA Good Delivery standard is the benchmark: every gold asset backing TC-MGT must be traceable through a credentialed M5Bank BOB or BOI account in the MINERA sovereign index, sensor-oracle verified, and auditable to chain of custody on TitleChain.

TC-MGT is never used for platform services, API fees, credential purchases, or any operational transaction. The M5Canon engine enforces this as a hardcoded dual-token policy — any attempt to route TC-MGT through platform service rails is blocked at classification and logged to the tamper-evident event chain. TC-MGT is a treasury reserve instrument. TCUSD is the platform credit unit. They are architecturally distinct and M5Canon enforces that distinction at Layer 0 with no override.

TC-MGT BACKING STANDARD — M2 IN-SITU GOLD ASSET CHAIN
CREDENTIALED ISSUER
M5Bank member with active BOB or BOI account in the MINERA sovereign index. Mining sector entity — from junior explorer to major producer. USC jurisdiction code anchored at registration.
ASSET VERIFICATION
In-situ gold reserves sensor-oracle verified · NI 43-101 or JORC-compliant resource estimate · Independent assay and chain of custody · TitleChain registry record for every reserve block
BENCHMARK STANDARD
LBMA Good Delivery standard · Recognized producers: Newmont, Agnico Eagle, Barrick Gold and equivalents · LBMA spot price oracle feed for daily mark-to-market · BTC Taproot notarization of every audit event
CANON ENFORCEMENT
Hardcoded dual-token policy in M5Canon · TC-MGT blocked from all M1 platform service rails · Audit trail on every reserve event · FHE audit via M5LightLocker · Arweave permanent storage

1.4 BPS Fee Schedule — BP1 Through BP15

CodeEventBPSScopeZKRail
BP1Tokenization50CustomerBase L2
BP2BTC Notarization5CustomerREQUIREDBitcoin Taproot
BP3Title Transfer15CustomerREQUIREDTitleChain
BP4Trade Execution25CustomeroptionalExchange tier
BP5Retirement10CustomerREQUIREDTitleChain
BP6Cold Custody2/moCustomerM5LightLocker
BP7Registry Node Update0.5CustomeroptionalBase L2
BP8Hot Wallet Transfer1CustomerBase L2
BP9Compliance Screening2FullREQUIREDCEDECO oracle
BP10Dispute Resolution3FullAdjudication pool
BP11Cross-Chain Bridge3FullREQUIREDICSN IBC
BP12Governance Vote0.5FullICSN Global
BP13TitleChain Registry1CompleteTitleChain
BP14NYCP Arbitration2CompleteNYCP©
BP15Index Update3CompleteGGP oracle

Customer scope BP1–BP8: 114 BPS | Full scope BP1–BP12: 122 BPS | Complete scope BP1–BP15: 128 BPS


Section 2

M5Bank Account Framework and ENS Identity

Every entity on the M5 platform has an account type that determines what asset classes they can handle, what actions they can initiate, and what their public registry ENS identity looks like. Account type is determined by the entity's legal form and registration — confirmed by their sovereign chain's Secretary of State or equivalent governing body.

2.1 The Five Account Types

TypeFull NameWhoAsset AccessKey Distinction
BOM Bank of Me Individual sovereign person. The complete financial life of a human being in one sovereign private cloud — their own M5POD container. M1 (base access) · M2/M3 assets they hold as investor · M4 as qualifying purchaser via BOI counterparty A person can hold BOG-level credentials within their BOM account. The account remains BOM. The credential is the authority. The account type is the legal entity form. See BOM Architecture below.
BANK OF ME (BOM) — THE SOVEREIGN HUMAN OPERATING SYSTEM
M5SCORE — YOU ARE YOUR SCORE. NOT A THIRD PARTY'S ASSESSMENT OF YOU.
The M5Score is not a credit score. It is not FICO. It is not a risk model built from data you never consented to share with people who never asked your permission. It is the sovereign reputation of a sovereign human — built from what you actually do, what you contribute, what you create, what you learn, what you build — over time, under your verified identity, anchored to your TCID. The longer your wallet has been active and uncompromised, the more transactions you have fulfilled, the more you have contributed to your community and creative economy, the higher your score. Not because of how much money moved — because of the quality and consistency of your sovereign economic life.
LONGEVITY
Time your wallet has been active, verified, and uncompromised under your control. Time is trust.
INTEGRITY
Pattern of economic activity — consistency, reciprocity, fulfillment. 500 small contracts completed matters more than large amounts moved.
CONTRIBUTION
Verified contributions to cooperative pools, environmental stewardship, governance participation, community infrastructure. These are titled M2/M3 assets — scored and owned.
SOPHIA SCORE
Every credential earned, course completed, skill certified, IP registered. The more you learn and create, the higher your SOPHIA component. Your knowledge compounds over time and cannot be taken.
AGENT QUALITY
The agents you have trained, credentialed, and deployed. When they perform well under your mandate, your score reflects their quality — they are extensions of your sovereign OS.
HOW REWARDS FLOW — NOT ADVERTISING, ENGAGEMENT
Companies that want to access the talent, knowledge, creative output, and community influence of high-M5Score holders do not buy advertising to reach them. They cannot. There is no advertising layer in the sovereign OS. Instead, they request access through the sovereign OS — presenting opportunities, compensation offers, and collaboration invitations that the human can accept, reject, or negotiate through their Vaulta. The human's agents evaluate offers against their mandate without the human needing to review every one. The company is not buying attention. They are requesting access to a sovereign human's capabilities on that human's terms. Rewards flow from engagement value, not eyeball value. From knowledge, not surveillance. From contribution, not consumption.
WHEN YOU GET HIRED — YOUR AGENTS COME WITH YOU
When a high-SOPHIA-score M5HUM holder is hired by any company, their credentialed agents come with them as verified extensions of their sovereign OS. The employer can verify every agent's credential, training history, and capability on M5Scan.io. The agents work for the human — not the company. The human can take them to the next engagement. The more you train your agents, the more they learn under your credential, the more valuable they become as part of your sovereign economic identity. Your SOPHIA score, your agent portfolio, your contribution history — these travel with you across every job, every gig, every enterprise you build or join. They are yours. They compound. They cannot be deleted by a platform or revoked by an employer.
FIVE LAYERS INSIDE EVERY SOVEREIGN ACCOUNT
LAYER 1 — SOVEREIGN IDENTITY
TCID · M5HUM credential · Sovereign soul ENS address · W3C DID/VC · Biometric binding (ZK-committed, never stored in plaintext) · Phone sovereignty (Telnyx FIND→ATTEST→CONTROL→TOKENIZE) · Device registry (all owned devices as M3 titled assets) · Social accounts and email accounts as sovereign identity records · 23andmine genomic vault · MyDNA health records
LAYER 2 — PERSONAL BUSINESS LEDGER
The BOM holder's own private portfolio and business ledger — their complete financial picture in one place:
· Traditional finance: bank accounts, brokerage, 401k/IRA, credit cards (read-only secure bridge)
· Digital assets: M1 TCUSD credits, M2 commodity tokens, M3 titled assets, M4 securities held as investor
· Stocks and equities: traditional holdings bridged via SwiftBRIDGE-equivalent consumer connection
· Invoices issued and paid: gig work, contract work, sole proprietor income — every invoice a titled record
· Income streams: salary, gig payments, BOU cooperative distributions, SNP token licensing income, REC token distributions
· Tax records: automated FASB/IFRS journal entries on every transaction
LAYER 3 — BANK OF US MEMBERSHIPS
Every BOU account the BOM holder is a member of, visible inside their M5POD:
· Credit unions they belong to
· Trade unions and labor organizations
· Cooperative pools: 23andmine.eth, energy cooperatives, producer cooperatives, agricultural cooperatives
· DAOs and ICSN working groups they participate in
· Each BOU shows: share/stake, governance rights, voting history, distribution history, and the BOM holder's current standing
LAYER 4 — BUSINESS CREDENTIALS & WORK ACCESS
Credentials the person holds giving access to BOB/BOI/BOG systems:
· Employment: employer's BOB/BOI account connection, payroll integration, benefits records
· Gig work: verified contractor relationships across platforms, rated work history, payment records
· Professional certifications: SOPHIA developer credentials, industry licenses, academic degrees from BOI educational institutions
· Government credentials loaded into BOM: the BOG-level credential a governor or official carries inside their personal BOM account — the credential is the authority, not the account type
LAYER 5 — CUSTODIANS, DIGNITY AGENTS & GUARDIANS
Trusted agents the person selects at any point in their life:
· Custodians — hold keys on behalf of the BOM holder: estate planning, incapacitation, minor accounts managed by parent custodians. Time-locked. Consent-gated. Revocable at any time while the person has capacity.
· Dignity Agents — AI agents the person names to act with dignity in specific circumstances: health directives, end-of-life instructions, mental health support protocols, crisis intervention preferences. They surface the person's wishes to the right humans at the right moment — they do not act unilaterally.
· Guardians — trusted humans named by the person (family members, attorneys, medical proxies) who can act through the M5 adjudication pool system if the person is unable to. No guardian can take unilateral control — guardian activation requires adjudication pool approval under the laws of the person's registered jurisdiction.
THE PRIVATE CLOUD — M5POD ENCRYPTION STACK
· M5POD — SOLID Protocol sovereign data container. The person's own cloud. No platform sees inside.
· AES-256-GCM — all data encrypted at rest
· Signal Protocol — E2EE for all pod communications
· FHE via M5LightLocker — computation on sensitive data without decryption
· ZK proofs — prove qualification without revealing underlying data
· Five protecting agents — SOPHIA, LENORE, MILNER, ROWBOAT, 23andMine each guard specific domains
· No agent supersedes the human — M5HUM is the constitutional authority
VAULTA — PERSONAL SOVEREIGN DATA ROOM
Every BOM account includes a Vaulta — a private sovereign data room within the M5POD: identity attestations (TCID, phone/SIM, biometric binding, CER records) · personal documents (IDs, passports, certificates, deeds, titles) · assets ledger: tangible (real estate, vehicles, art) and intangible (IP, credentials, tokens) · Ricardian contract repository (identity attestation, CER control forms, jurisdiction-specific templates from M5Canon) · full provenance chain — every document and asset carries a TCID and provenance hash chain anchored on TitleChain.
ODEA — WORKFLOW INTELLIGENCE AGENT
Odea is the workflow intelligence agent embedded in every M5POD. It knows which forms, attestations, Ricardian contract templates, and regulatory filings apply to each entity type and jurisdiction, and surfaces the right workflow at the right moment — eliminating formation and migration complexity. Serves five roles: SELF/Guardian (personal documents, CER control, health) · Co-op/BOU (governance docs, cooperative voting) · FSP/BOI (regulatory filings, compliance, custody) · Commissioner/BOG (oversight, audit access) · Investor (NDA-gated Private Data Room). Odea is also the workflow engine for Track A (legacy entity migration) and Track B (native sovereign formation).
PRIVATE DATA ROOM — BOB / BOI ENTITY LEVEL
For entities requiring investment review, every BOB and BOI account can activate a Private Data Room — NDA-gated, credential-enforced via SOPHIA + M5Canon: cap table (equity ledger, shareholder registry, SAFEs/T-SAFEs) · debt instruments (loans, credit facilities, convertible notes) · securities (stocks, bonds, future token allocations) · subscriber ledger · financial statements (P&L, balance sheet, cash flow) · legal documents (operating agreements, bylaws, board resolutions). M5Capital's own Private Data Room is the reference implementation.
BOUBank of UsCooperative, Trust, Wyoming DUNA, DAOM1 + M2Wyoming DUNA (Decentralized Unincorporated Nonprofit Association) structures, 1,000-year trusts, cooperative entities. ICSN Global converts to a Wyoming DUNA upon the first 100 M5Bank members joining the working group cooperative. TitleChain Foundation is a Wyoming Sovereign Purpose Trust. Both are BOU. Governed by cooperative rules — member-voted, on-chain governance.
BOBBank of BusinessLLC, Corp, holding company, tribal enterpriseM1 + M2 + M3Standard business entity. Tribal enterprises (the business arm of a tribe, distinct from the tribal government itself) are BOB. Cannot initiate M4 issuance.
BOIBank of InstitutionLicensed institution — Special Purpose Depository Institution (SPDI), bank, university, research body, regulated entityM1 through M4 Institutions operating under regulatory authority. Two pathways to BOI standing:

Pathway A — Legacy Institution: Holds an active SWIFT BIC code (global correspondent banking participant). SwiftBRIDGE maps the SWIFT BIC to their sovereign ENS address, establishing identity, jurisdiction, and standing. The SWIFT code is their proof of institutional recognition.

Pathway B — New Financial Services Entity: No SWIFT history. Applies for M5Bank BOI licence through the SOPHIA certification pathway — demonstrating regulatory and capitalization requirements for BOI standing. Receives a sovereign BRIDGE code as their routing identifier (the M5 equivalent of a SWIFT BIC).

To initiate M4 issuance: BOI account + SwiftBRIDGE or BRIDGE code + DTTC membership (U.S.) or equivalent recognized clearing participant credential in their jurisdiction (Euroclear / JASDEC / CCASS / CREST / equivalent).
BOGBank of GovernmentGovernment agency legal entity onlyM5-class accessThe legal entity embodiment of a government agency: DoD, HHS, FDA, state health departments, tribal government bodies. Only agencies hold BOG entity status — a person holding government credentials remains a BOM account holder with BOG credentials loaded.

2.2 The ENS Naming Convention — Account Type Encoded in Public Address

Account type is encoded directly in the public registry ENS address, making every entity's legal form and jurisdiction publicly verifiable on M5Scan.io without any off-chain lookup.

ENS NAMING FORMULA
[entity].[accounttype].[statechain].[nationchain].eth
acmegold.bob.californiachain.unitedstateschain.eth — California LLC / holding co
acmegold.bou.californiachain.unitedstateschain.eth — California DUNA cooperative
spdi.boi.wyomingchain.unitedstateschain.eth — Wyoming Special Purpose Depository Institution (SPDI) — BOI tier
hhs.bog.unitedstatesgovernment.eth — Federal agency (under unitedstatesgovernment.eth)
sugf.bob.southernutechain.unitedstateschain.eth — Southern Ute Growth Fund (enterprise, not tribal gov)
dod.bog.unitedstatesgovernment.eth — US Dept of Defense (federal agency)

2.3 ENSv2 Native Registry — m5wallet.eth + m5standard.eth

M5 launches on ENSv2 as a native hierarchical registration system. ENSv2 is explicitly designed for hierarchical registries where each name defines its own registry and resolver behavior — exactly the architecture M5 requires for policy-controlled identity issuance across jurisdictions. The M5 registry roots are:

m5wallet.eth — OPERATIONAL IDENTITY ROOT
The root registry for all sovereign identity issuance. Five fixed class subtrees — each with its own registry contract, issuance rules, and policy enforcement. Operated by M5 Network under ICSN Global namespace authority.
me.m5wallet.eth
us.m5wallet.eth
business.m5wallet.eth
institution.m5wallet.eth
government.m5wallet.eth
m5standard.eth — STANDARDS & AUDIT ROOT (AAIF GOVERNED)
Governed by M5-AAIF under the Linux Foundation. The canonical source for open standards, agent definitions, credential schemas, audit frameworks, hardware trust specifications, and policy templates. Not operated by M5Capital — neutral, open governance.
agent.m5standard.eth
credential.m5standard.eth
audit.m5standard.eth
hardware.m5standard.eth
schema.m5standard.eth
ENSv2 CANONICAL IDENTITY FORMAT — FIVE FIXED CLASSES
<name>.<jurisdiction>.<class>.m5wallet.eth
pamela.wy.me.m5wallet.eth
Personal sovereign identity — Wyoming resident
roots.santamonica.us.m5wallet.eth
Co-op / community / collective — Santa Monica
m5capital.wy.business.m5wallet.eth
Commercial entity — Wyoming LLC
drjones.health.ca.institution.m5wallet.eth
Licensed physician — institution.health subtree, California
dor.wy.government.m5wallet.eth
Wyoming Dept of Revenue — government class
board.elections.wy.government.m5wallet.eth
Government subtree expansion below class layer
One rule: The five classes (me, us, business, institution, government) are fixed at the class layer. All specialization — health, legal, education, faith, finance — goes below the class as a sector subtree under institution. Government agencies may also use sector subtrees (elections, treasury, health) below the government class. The class layer never grows beyond five. The ecosystem grows below it.
BRANDED EXPERIENCE LAYER — RESOLVES TO CANONICAL ENSv2
The bankof.* product surfaces are the experience layer — not the canonical identity root. The app may display pamela@bankof.me while the canonical routed identity under the hood is pamela.wy.me.m5wallet.eth. Both point to the same TCID, vault, and policy engine.
bankof.me → *.me.m5wallet.eth     bankof.us → *.us.m5wallet.eth
bankof.business → *.business.m5wallet.eth     bankof.finance → *.institution.m5wallet.eth
bankof.government → *.government.m5wallet.eth

2.4 Federal, State, and Tribal Jurisdiction Rules

Constitutional Distinction — Enforced at Infrastructure Layer
unitedstateschain.eth is the federated sovereign chain of the American people — citizens, businesses, state governments, tribal nations, territories, universities, and M5Bank account holders. Bottom-up. The union of sovereign states.

unitedstatesfederalgovernment.eth (aliases: unitedstatesfederalgov.eth · unitedstatesgovernment.eth) is the federal government's sovereign identity chain — federal agencies, departments, military branches, regulatory bodies (SEC, CFTC, FinCEN, DoD, GSA). This separation is not a naming convention. It is a constitutional enforcement rooted in the CYRUS Protocol, which establishes that government authority and civilian life are constitutionally separate spheres. M5 enforces this at the infrastructure layer.

Federal agencies sit under unitedstatesgovernment.eth — not under any state chain. DoD, DoE, HHS, FDA, USAF are all [dept].bog.unitedstatesgovernment.eth.

State agencies sit under their state chain: [dept].bog.[statechain].unitedstateschain.eth. The Wyoming Board of Medicine is wybom.bog.wyomingchain.unitedstateschain.eth.

Tribal sovereign chains are themselves BOG — sovereign governments. Tribal government body entities under them are [entity].bog.[tribename]chain.eth. The tribal enterprises (business arms) are [entity].bob.[tribename]chain.eth.

Michigan exception: Michigan is registered as michiganstatechain.eth (not michiganchain.eth) to avoid namespace conflict. All agencies and entities in Michigan follow the pattern: agency.michiganstatechain.unitedstateschain.eth. This is the only state exception in the 50-state + 6-territory registry.

Public registry addresses are fixed and assigned by the sovereign chain based on the entity's legal registration. Entities can create additional custom ENS addresses for commerce, branding, or products — but the public registry identity is canonical, state-determined, and verifiable at M5Scan.io.


Section 3

ICANN to ICSN: Migrating Existing Identity to Internet 3.0

Every entity arrives at Internet 3.0 by one of two paths:

TRACK A — LEGACY ENTITY MIGRATION
An existing entity — LLC, Corp, trust, DAO, co-op — with an active EIN, SOS filing, bank accounts, cap table, and legacy records. Odea guides a nine-step migration that ports legal identity, documents, assets, and accounts onto the M5 sovereign ledger while preserving full legal continuity. The entity's existing ICANN domain is their Web2 Certificate of Authority — the starting point for the ICANN→ICSN bridge. 33M+ U.S. businesses eligible.
TRACK B — NATIVE SOVEREIGN FORMATION
A new entity forming from genesis — blockchain-native, AI-augmented, sovereign from day one. No legacy records to migrate. Clean genesis on the M5 stack. Odea guides EIN pathway, SOS-equivalent on-chain formation, native M5Bank account, Vaulta genesis, and USC Order Book access. 5M+ new U.S. business formations per year plus 140M+ global micro-enterprises. Net-new M4 issuance under UCC Article 12 CER from birth.

Every entity that has built brand equity on a legacy domain (.com, .gov, .org, .edu, .net) migrates that identity to its sovereign ENS equivalent. This is not abandonment — it is migration forward. Brand equity, SEO, customer relationships, all carry through. Domain ownership verification is Step 1 of developer onboarding — it establishes jurisdiction before any account type, credential, or API access is granted.

Phase 1 — Activation
Cyrus Protocol Ratification + Sovereign Chain Activation
Before any chain can be activated, the sovereign authority formally ratifies the five Cyrus Protocol commitments. This is the constitutional prerequisite — M5Canon enforces it at Layer 0. No ratification, no chain. Once ratified, the governor, tribal council, or national authority signs the chain activation declaration. For U.S. governors this is a Tenth Amendment assertion of state sovereignty. For tribal nations, a tribal council resolution. For international sovereigns, the equivalent national authority act. This is a constitutional act, not a technology procurement. Not every nation will qualify. Not every nation will apply. The Internet 3.0 map is the world map of sovereigns that have made and maintained the Cyrus Protocol commitments.
Cyrus Protocol ratification → chain activation declaration → wyomingchain.unitedstateschain.eth
Phase 2 — Registration
TitleChain Issues ENS Domain and Certificate of Origination
TitleChain registers the ENS domain, issues a Certificate of Origination anchored to the sovereign chain, and notarizes the genesis record on Bitcoin via the m5BtcNotaryProof Keelung circuit. The chain is now canonical and publicly verifiable on M5Scan.io.
Certificate of Origination → Bitcoin Taproot ZK notarization → M5Scan.io
Phase 3 — Bridge
ICSN Maps Chain Domain to ICANN Domain
ICSN Global issues a Certificate of Authority mapping the legacy ICANN domain to the sovereign ENS address. The gateway routes both during transition. Websites, storefronts, APIs, and institutional identities progressively migrate all operations to the sovereign chain structure.
jpmorgan.com → jpmorgan.boi.unitedstateschain.eth
ICSN GLOBAL — NOT JUST THE GOVERNANCE BODY. THE PHYSICAL INFRASTRUCTURE OPERATOR.
ICSN stands for Internet Corporation for Sovereign Networks. That name was always precise. ICSN is not merely the standards body for Internet 3.0 — it is the physical infrastructure operator of a parallel internet for sovereign economic traffic. The three-layer physical network beneath the digital sovereignty stack: Master MVNO agreement → dark fiber IRU capacity → sovereign eSIM device layer. The most durable financial infrastructure businesses in history — NYSE, SWIFT, Fedwire — own their physical layer. ICSN owns its physical layer at the network level.
LAYER 1 — MASTER MVNO
ICSN Global holds the Master MVNO agreement. M5Nodes activate as sub-MVNOs underneath it. A single licensing relationship that the entire ecosystem rides — the marginal cost of adding the 500th M5Node sub-MVNO is essentially zero once the master agreement is in place. Not a phone company. A sovereign telecommunications infrastructure layer that happens to carry voice and data. Every device on the network is a titled M3 eSIM asset generating USC transaction data under its sovereign chain jurisdiction.
LAYER 2 — DARK FIBER IRUs
ICSN acquires Indefeasible Rights of Use (IRUs) on existing dark fiber routes at wholesale rates from Zayo, Lumen, Crown Castle, and Uniti across U.S. corridors — and Telxius and TE SubCom for international submarine routes. IRU agreements are operating expenses, not capital expenditures — ICSN acquires usage rights, not ownership, with no maintenance obligation. The capacity is then sublet to M5Node operators at preferential rates. A Texas M5Node and a California M5Node transacting USC-settled payments route that traffic over ICSN-controlled fiber — not over public internet transit. TCID-signed transactions travel over sovereign dark fiber. That is a parallel internet for sovereign economic traffic.
LAYER 3 — eSIM SOVEREIGNTY
Every device on the M5 network is registered as a sovereign M3 eSIM asset through the M5HUM credential pipeline (FIND→ATTEST→CONTROL→TOKENIZE via Telnyx + NPAC + STIR/SHAKEN + UCC Article 12 CER mint). The eSIM is the physical anchor of the sovereign identity chain — it carries the TCID, the USC jurisdiction code, and the M5Node routing assignment. When a device transacts, the provenance chain traces from the physical SIM through the sovereign network to M5Canon Layer 0. No existing telecom infrastructure tracks this chain.
M5NODE OPERATOR — SEVEN REVENUE STREAMS — MICRO-SOVEREIGN TELECOM + BANKING OPERATION
MVNO MARGIN
Connectivity margin on every device served on the sovereign network
DARK FIBER RATE
Preferential inter-node routing over ICSN-controlled IRU fiber capacity
VALIDATION REWARDS
M5Node USC validation rewards on every sovereign transaction routed
SOPHIA REVENUE
Credential revenue from every new M5HUM account the node originates
USC ORDER BOOK
First-look rights on MVNO capacity tokens + dark fiber IRU tokens at founding rates
M5BANK REVENUE
Account interest and fee revenue on every member account originated by the node
eSIM ASSET YIELD
USC transaction data yield from every titled M3 eSIM device on the node network
UNIT ECONOMICS
Near-zero marginal cost scaling — the 500th sub-MVNO costs essentially nothing to add once the master MVNO agreement is in place
A well-run M5Node in a mid-size market is not a hobbyist validator. It is a micro-sovereign telecom and banking operation with seven revenue streams — running on sovereign dark fiber, serving credentialed M5HUM holders, routing USC-settled transactions, and contributing to the physical infrastructure of Internet 3.0.

3.1 Domain Type Migration Reference

Legacy DomainEntity TypeTarget ENS PatternAccount Type
.gov state agencyState government agency[agency].bog.[statechain].unitedstateschain.ethBOG
.gov federal agencyFederal government agency[dept].bog.unitedstatesgovernment.ethBOG
.com businessLLC, Corp, holding company[entity].bob.[jurisdictionchain].ethBOB
.com bank/institutionLicensed financial institution[entity].boi.[jurisdictionchain].ethBOI
.org cooperative/DAONonprofit cooperative, DUNA[entity].bou.[jurisdictionchain].ethBOU
.eduUniversity, research institution[institution].boi.[statechain].ethBOI
International TLDAny international entity[entity].[accounttype].[countrychain].ethBy legal form
First-Mover Advantage
ICSN enforces namespace integrity — a legacy domain holder has priority claim on the corresponding ENS address. If acmegold.com is your domain, you have priority on acmegold.bob.californiachain.eth. Once registered on TitleChain, the mapping cannot be reassigned. Register before July 4, 2026 to secure your sovereign namespace.

Section 4

From Underlying Asset to Certified Offering: The M4 Issuance Pipeline

CEDECO.eth — Precisely What It Is and Is Not
CEDECO.eth IS: The on-chain Certificate of Issuance that certifies an M4 offering is properly structured, the issuer holds BOI standing, the underlying M2 or M3 asset has been verified, and the offering complies with Reg D 506(c) or Reg A+. The Certificate lives on TitleChain, Bitcoin-notarized via m5BtcNotaryProof.

CEDECO.eth IS NOT: An identity verification engine. Identity is handled at the account and credential layer — M5Scan.io, SFI L1–L5, W3C DID/VC. When developers see CEDECO in a transaction context, understand it as an issuance certification instrument, not an identity oracle.

DTTC Membership (U.S.): In the United States, CEDECO.eth issues Certificates of Issuance to DTTC member entities — recognized participants in the Depository Trust & Clearing Corporation system. DTTC membership is the U.S. institutional credential that qualifies a BOI entity to receive CEDECO.eth certification for M4 offerings.

Global Market Extension: Outside the U.S., CEDECO.eth extends the same certification structure to recognized clearing participants in each jurisdiction — Euroclear members (Europe) · JASDEC members (Japan) · CCASS members (Hong Kong) · CREST members (U.K.) · and equivalent recognized clearing bodies in other Cyrus Protocol-ratified sovereign markets. The membership credential in the local clearing system is the jurisdictional equivalent of DTTC membership. As new sovereign chains activate under Internet 3.0, their recognized clearing participant structures are mapped through ICSN Global and recognized by CEDECO.eth.

4.1 The Three-Layer Asset Journey

M4 Issuance — Asset Layers
LAYER 1 — UNDERLYING
Physical or Digital Asset
Gold in ground, REC from turbine, patent filing, real property deed
LAYER 2 — M2 TOKEN
On M5Bank Member Books
Gold-backed certificate token, REC token. BOB or BOI account holds this M2 asset.
LAYER 3 — M4 SECURITY
CEDECO.eth Certified Offering
PCM Gold Bond, Kisosen REC offering. BOI initiates. Reg D or Reg A+.

4.2 Nine-Step Issuance Pipeline — PCM Reference Implementation

00
Wyoming + Idaho M5Gov Accounts
BOG credentials for governors, banking commissioners, stablecoin commissioners activated on wyomingchain.eth and idahochain.eth.
01
Five-Tier Account Activation
BOM → BOB → BOI upgrade path. The Portuguese Creek Mine entity activates as BOB, upgrades to BOI with DTTC membership for M4 issuance authority.
02
TitleChain Certificate of Origination
portuguesecreekmine.boi.idahochain.unitedstateschain.eth registered on ICSN Internet 3.0. Certificate of Origination issued and Bitcoin-notarized via m5BtcNotaryProof.
03
OpenCorporates SOS Continuous Monitoring
24-hour Secretary of State good-standing verification gate. Entity must be in active standing before issuance proceeds.
04
Lead Investment Bank
Weild & Co. (coloradochain.eth, CODT-licensed) as lead investment bank for the $100M Reg D 506(c) offering.
05
CEDECO.eth Certificate of Issuance
Net-new M4 issuance born on-chain under UCC Article 12 CER (enacted 33 U.S. jurisdictions; NY effective June 3, 2026). Not a DTC migration — this is native sovereign M4 origination. CEDECO.eth certifies the offering is properly structured and compliant.
06
M5Canon Classification + SPDI Custody
M5Canon classifies the dual-token structure (PCM-B bond / PCM-GC gold certificate). SPDI custody: Kraken Bank Wyoming or N3XT Bank Wyoming.
07
Distribution Network
Rialto Markets (FINRA member, SEC-registered ATS for digital private securities), tZERO, INX, Ondo Finance, ADDX, or direct BOI-to-BOI. Rail selected by issuer and lead bank — not M5 default.
08
DTT Transfer
Digital Title Transfer: private ledger (Base L2) → M4 security token → offering network. M5 provides the Ricardian contract and DTT engine for any rail.
09
FHE Audit + Arweave + Bitcoin Merkle Notarization
Full homomorphic encryption audit via M5LightLocker. Permanent storage on Arweave. Bitcoin Merkle root notarization — immutable chain of custody, quantum-proof via m5BtcNotaryProof circuit.

TitleChain records every step of this pipeline immutably. ICSN Global is the DAO governance layer — human-led working groups, adjudication pools (NYCP© federal pool, unitednationschain.eth international pool), and standards ratification. TitleChain records facts. ICSN Global governs standards. Developers interact with TitleChain through the m5-ledger-server MCP and the TitleChain COO API.


Section 5

M5x402 Endpoint Security: Three Gates Before Execution

Every M5x402 transaction passes three constitutional gates before execution. These are not middleware suggestions — they are enforced by the M5Canon engine at Layer 0. A transaction that fails any gate is blocked, logged to the tamper-evident event chain, and a M5Watcher alert is issued. There is no retry without remediation.

01
TCID Credential Verification — Who Is the Agent?
Every M5x402 request must carry a TCID-signed W3C Verifiable Credential. The TCID format — TCID-CLASS-DOMAIN-HASH16 — is verified against the active sovereign chain before the endpoint responds. SFI credential level (L1–L5) determines which asset classes the caller can transact. Requests without a valid TCID receive a structured 403 response — not a 402. The payment is not the problem. The identity is.
02
M5Canon Asset Classification Check — What Is Being Moved?
Once identity is verified, M5Canon checks whether the requested transaction is consistent with the asset class of the instrument and the caller's credential level. An L2-credentialed agent cannot move an M4 instrument regardless of payment amount. The CBDC firewall blocks all M5-class access before this gate executes. The check also verifies that the settlement rail requested is appropriate for the asset class and account type combination.
03
M5Mandate Authorization — Is the Agent Permitted to Act?
Every agent operates under an M5Mandate — a constitutional authorization signed by the human TCID key and stored in the CEDECO registry. The mandate specifies: maximum daily/monthly spend limits, permitted asset classes, permitted payment rails, permitted merchant categories, and the threshold above which human approval is required before execution. An agent that receives a request exceeding its mandate does not execute and fail — it surfaces the request to the human and waits. Agents do not fail silently. Humans remain the constitutional authority.

5.1 ZK_REQUIRED Events — Seven That Cannot Be Skipped

If proof generation fails for any ZK_REQUIRED event, a RuntimeError is raised — the transaction is blocked, not skipped. This is enforced in the M5Canon engine and the five Keelung Haskell circuits (871 lines, 310 passing tests, Groth16/BN128).

m5BtcNotaryProof
Events: BP2, BP3, BP5 (REQUIRED) · BP1, BP4 (optional)
ZK REQUIRED
Quantum-proof Bitcoin notarization. Title issuance, transfer, and anchoring events wrapped in a ZK envelope. The verifier confirms notarization without touching underlying title data. Groth16/BN128.
cyrusAntiRehypProof
Events: BP7 (optional)
ZK OPTIONAL
Merkle proof that no asset has been used as collateral for more than one obligation simultaneously. Makes the anti-rehypothecation gate cryptographically auditable rather than merely contractual. Core to Patent #11,720,888.
m5CredentialProof
Events: BP9, REVOCATION (REQUIRED) · AGT_SKILL (optional)
ZK REQUIRED
Privacy-preserving three-factor credential verification. Proves credential validity without exposing the credential itself or the holder's identity beyond what is necessary. The verifier learns only: valid or invalid.
m5LicenseProof
Events: LICENSE_ISSUE (REQUIRED)
ZK REQUIRED
Enforces BPS fee schedule compliance at the circuit level. Canonical SSoT constants for CustomerScope (114 BPS), FullScope (122 BPS), CompleteScope (128 BPS). Fee enforcement cannot be bypassed by application-layer logic.
m5BridgeProof
Events: BP11 (REQUIRED)
ZK REQUIRED
Validates cross-chain bridge provenance and CYRUS Protocol compliance before any cross-chain settlement executes. Prevents double-spend and rehypothecation at the protocol level across all sovereign chain pairs.
Quantum Defense Stack
FHE — M5LightLocker: Data encrypted while processing. No plaintext leaves the vault under any computation.

ZK — Keelung Circuits: Events proven valid without content disclosure. Groth16/BN128, 310 passing tests.

QCaaS Silicon Roadmap: BTQ QCIM FPGA → ASIC → QPerfect QLU. Proof generation hardware migrates to quantum-native silicon as it matures. Classical-resistant today. Quantum-native by design.

5.2 Endpoint Configuration — Node.js, Python, Rust

// npm install @m5bank/x402-middleware @m5bank/sdk
import { m5PaymentRequired } from '@m5bank/x402-middleware';
import { M5Client, AssetClass } from '@m5bank/sdk';

const m5 = new M5Client({
  tcid:     process.env.M5_TCID,
  chain:    'californiachain.unitedstateschain.eth',
  sfiLevel: 2,              // L2 = M1+M2 access
});

app.get('/api/energy-data',
  m5PaymentRequired({
    amount:     '0.05',         // TCUSD credits
    assetClass: AssetClass.M2,  // REC data endpoint
    usc:        'USC-US-CA-0001',// California jurisdiction
    mandate:    { maxPerDay: 500, permittedRails: ['base_l2', 'ondo'] },
    zkRequired: false,           // M2 data query — ZK optional
  }),
  (req, res) => {
    // Only executes after all 3 gates pass
    // req.m5.tcid, req.m5.usc, req.m5.assetClass all available
    res.json({ recs: getRECData(req.m5.tcid) });
  }
);

// Error responses:
// 403 TCID_MISSING     — no credential on request
// 403 SFI_INSUFFICIENT — credential level too low
// 403 CBDC_FIREWALL    — M5-class asset blocked
// 403 MANDATE_EXCEEDED — surfaced to human, not failed silently
// 402 PAYMENT_REQUIRED — identity valid, payment needed
// 503 ZK_PROOF_FAILED  — ZK_REQUIRED event blocked
# pip install m5bank-sdk
from m5bank import M5Client, AssetClass, m5_payment_required
from fastapi import FastAPI, Depends
import os

app = FastAPI()

m5 = M5Client(
    tcid  = os.environ["M5_TCID"],
    chain = "californiachain.unitedstateschain.eth",
    sfi   = 2,
)

# Dependency: enforces all 3 gates before route body executes
gate = m5_payment_required(
    amount  = "0.05",            # TCUSD credits
    asset   = AssetClass.M2,
    usc     = "USC-US-CA-0001",
    mandate = {
        "max_per_day":      500,
        "permitted_rails":  ["base_l2", "ondo"],
        "human_threshold": 1000,  # surface to human above this
    },
)

@app.get("/api/energy-data")
async def energy_data(session = Depends(gate)):
    # session.tcid, session.usc, session.asset_class verified
    # ZK_REQUIRED events raise RuntimeError — blocked, not skipped
    return {"recs": get_rec_data(session.tcid)}

# M5Canon classification endpoint — classify before deploying:
# POST /api/m5-canon-validate
# {"asset_definition": {...}} → {"class": "M2", "rails": [...], "bps": 114}
// Cargo.toml: m5bank-sdk = "1.0"
use m5bank::{M5Client, AssetClass, M5Mandate, PaymentConfig, payment_gate};
use axum::{Router, middleware, routing};

let _m5 = M5Client::new()
    .tcid(std::env::var("M5_TCID")?)
    .chain("californiachain.unitedstateschain.eth")
    .sfi_level(2)
    .build()?;

let gate = payment_gate(PaymentConfig {
    amount:      "0.05".parse()?,
    asset_class: AssetClass::M2,
    usc:         "USC-US-CA-0001",
    mandate:     M5Mandate {
        max_per_day:      500,
        permitted_rails:  vec!["base_l2", "ondo"],
        human_threshold:  1000,  // surfaces above this — never fails silently
        ..Default::default()
    },
});

let app = Router::new()
    .route("/api/energy-data", routing::get(energy_handler))
    .layer(middleware::from_fn(gate));

// ZK failures    → Err(M5Error::ZkProofFailed)      — blocked, not skipped
// Mandate breach → Err(M5Error::MandateExceeded)     — surfaced to human
// CBDC firewall  → Err(M5Error::AssetClassForbidden) — logged + alerted
// All errors     → structured JSON with error code + remediation hint

5.3 M5Watcher — Continuous Compliance Monitoring

M5Watcher monitors every active endpoint in real time, reading every M5Canon event across all three network layers. It surfaces compliance anomalies to human principals before any enforcement action is taken. For developers: if your endpoint generates an event pattern that triggers a M5Watcher alert, you receive a structured notification through the m5-audit-server MCP with the specific event, the compliance rule triggered, and the recommended remediation — before any enforcement action is taken. You are never blocked without notice.

The Answer to Threat III — What You Are Actually Building
Return to the Preamble. Threat III was the most acute: autonomous payment agents operating via x402 + MCP + AP2/TAP executing financial transactions at machine speed with no identity verification, no authorization chain, no audit trail to an accountable human. The three gates you have just implemented are the direct technical answer to that threat. Gate 1 answers the identity problem — every agent is credentialed. Gate 2 answers the asset classification problem — every instrument is typed and routed correctly. Gate 3 answers the accountability problem — every agent operates under a human-signed mandate and cannot exceed it silently. M5Watcher answers the audit problem — every event is observable, surfaced to the human, and immutably logged. The endpoint you just secured is not an API integration. It is a piece of constitutional infrastructure for the sovereign financial internet.

Section 6

Receiving Payment and Representing Real Value

6.1 Interoperable Settlement Rails — M5Wallet as the Access Gate

The M5Wallet Principle
M5 is chain-agnostic by design. A member can settle on Base, EVM chains, Bitcoin, Solana, Cardano, XRP, Canton, or any interoperable chain — depending on the asset type, the counterparty, and their market preference. What is not optional is the M5Wallet. You must hold an M5Wallet to gain access to real-world asset markets on any of these chains. The wallet is the sovereign credential gate — it carries your TCID, your SFI credential level, and your USC jurisdiction code.

Critical requirement: Every M5Wallet is issued under a sovereign chain that has formally ratified the Cyrus Protocol. The wallet credential carries the USC code of a Cyrus-compliant jurisdiction. There is no M5Wallet that is not anchored to a ratified sovereign chain. A person living in a nation that has not ratified the Cyrus Protocol can still hold an M5Wallet — but it must be issued under the USC code of a jurisdiction they have legal standing in that has ratified. The wallet is the credential. The jurisdiction is the constitutional anchor. Both are required.
M1
Utility — Platform Credits, Private Stablecoins, Time and Labor
Base L2 (default, <200ms T+0) · Any EVM chain · Internal M5 ledger · Lightning Network for high-frequency micropayments. Settlement token: approved sovereign stablecoin or member private stablecoin. TCUSD is the internal accounting representation.
Fee payment: approved stablecoin → TCUSD credits · USC determines which stablecoin list applies
M2
Commodity — RECs, Gold, Carbon, Minerals, Agricultural
Chain is member's market preference. M5 is chain-agnostic for M2. Member selects based on counterparty, liquidity, and jurisdiction.
M5 GLOBAL INDEX POOLS
15 sovereign index private pools — MINERA, VIRDIS, NATURA, TERRAVERTE, QUANTA and others. Primary liquidity venue for M5Bank members. Highest trust, lowest friction.
BITCOIN CHAINS
BTC Taproot (notarization anchor, m5BtcNotaryProof) · Ordinals/Runes (commodity token issuance) · Lightning (high-frequency M2 micropayments)
EVM CHAINS
Base L2 · Ethereum mainnet · Polygon · Arbitrum · Any EVM-compatible chain the member prefers
ALT L1 CHAINS
Solana (high-throughput commodity trading) · Cardano (provenance-heavy certification) · Chainlink (oracle-verified commodity data feeds)
DATA PROVENANCE LAYER
Storj · Arweave — sensor data, audit trails, certifications, and legal documents attached to M2 assets. Permanent, tamper-evident, content-addressed.
YIELD + DEX
Ondo Finance (USDY/OUSG treasury yield on M2 holdings) · Direct DEX pools · Peer-to-peer between M5Bank members
M5Wallet required on all rails · USC-US-WY-0001 → wyomingchain.eth determines approved stablecoin list for fee payment
M3
Titled Asset — Identity, Real Estate, Vehicles, Collectibles, Consumable NFTs, IP, Devices
M3 is the broadest asset class by category. Every titled real-world asset with a legal owner of record is M3. The M5Wallet is the access gate to all M3 markets — without it you cannot prove title ownership on any chain.
M3 Asset Types: Tokenized sovereign identity (TCID soul token, M5POD) · Real estate and land titles · Classic cars and luxury goods · Consumable NFTs (event tickets, airline mileage, loyalty credits, subscriptions, access passes) · Patents, trademarks, copyrights, trade secrets · AI chip registrations · eSIM ownership tokens · Device titles (SV-GW registered devices) · Any titled asset with a legal owner of record
M5 GLOBAL INDEX POOLS
Sovereign index private pools for M3 asset classes — SOPHIA (IP), HUMANUS (identity), LUMINA (devices), RADIUS (real estate). Member-only liquidity.
CHAIN vs CHAIN OF TITLE — TWO SEPARATE FUNCTIONS
The settlement chain provides issuance, transfer, and smart contract execution. TitleChain provides the immutable legal chain of custody — these are complementary, not competing. A house title can be issued on Hedera, transferred on Polygon, and the legal chain of title lives on TitleChain regardless of which chain holds the token at any moment.
CHAIN OF TITLE CHAINS
Solana (consumable NFTs, high-frequency title transfers) · Polygon (real estate, IP, luxury goods) · Aptos (fast finality, Move-based asset security) · Avalanche / AVAX (subnet architecture for jurisdiction-specific RWA chains) · Cardano / ADA (formal verification, provenance-heavy real estate and identity) · Sui (object-centric model ideal for unique titled assets, high throughput) · Hedera (enterprise tokenized identity and real property, HBAR hashgraph) · Stellar (cross-border RWA, international title, built-in DEX) · Base/EVM (Ethereum-compatible) · Cosmos IBC (cross-chain title portability) · BTC Ordinals (provenance-anchored title inscription)
SERVICES SUPPORTING THESE CHAINS
Arweave/Storj — permanent storage for legal title docs, physical asset records, certifications (content-addressed, not a settlement chain). Chainlink — oracle-verified asset valuation and condition feeds updating M3 token metadata. These support the chains above.
M5Wallet required on ALL M3 chains — this is the access gate to real-world asset markets · TitleChain records every title regardless of the settlement chain · USC jurisdiction determines approved stablecoin list for fee payment
M4
Security — Notes, Bonds, Certificates, Equity Tokens, Structured Offerings
Regulated institutional venues only — not public DEXes. Settlement infrastructure: Canton Network / DAML (privacy-preserving DLT for notes, bonds, and certificates between BOI institutions — Canton is a Linux Foundation member, operating within the same neutral open governance framework as M5-AAIF) · EVM-compatible chains (for tokenized securities on compliant institutional rails). Regulated exchanges and ATSs: Bullish (institutional digital asset exchange) · Liquid Mercury (private securities marketplace) · Hiive (pre-IPO and private market platform) · Zoniqx (tokenized securities issuance and trading) · Rialto Markets (FINRA member, SEC-registered ATS) · tZERO (regulated digital securities ATS) · INX (SEC-registered digital securities exchange). SPDI custody: Kraken Bank Wyoming or N3XT Bank Wyoming. Cross-border settlement: XRP. Settlement denomination: USDC, USDT, or any approved stablecoin per USC jurisdiction. CEDECO.eth Certificate of Issuance required before any market access — rail and venue selected by issuer and lead bank, not M5 default.
BOI account + SwiftBRIDGE mapping required · USC jurisdiction determines regulatory framework and approved stablecoin list · Stablecoins can move M4 instruments or M4 can settle natively on approved chains

6.2 Representing Non-Cash Value Through M5x402

Value TypeToken StandardClassIndex Anchor
Time, labor, and salaryTCUSD-denominated M1 tokens. USC-anchored to issuing entity's jurisdiction. Time-bound M5Mandate authorization for recurring salary streamsM1VALEO
Environmental stewardship / RECsM2 REC tokens, sensor-oracle verified. Double-counting eliminated at the protocol level — not policyM2VIRDIS
Knowledge work and IP licensingM3 IP licensing tokens issued at moment of conscious creation. Creator receives credits automatically via SOPHIA indexM3SOPHIA
Cooperative labor contributionVALEO index tokens. Cooperative governance activity as titled economic outputM1VALEO
Biodiversity / natural capitalM2 biodiversity stewardship credits. The community performing stewardship earns the credit — not an intermediaryM2NATURA

6.3 Protocol Integration Stack

MCP — Model Context Protocol Integration
Every M5x402 action via Model Context Protocol is automatically TCID-signed and M5Watcher-enforced. The 27 M5 MCP servers (208 tools) are the primary developer interface. Server access unlocks by SFI credential level: m5-api-gateway-server (L1), m5-ledger-server (L2), m5-contracts-server (L3), m5-lightlocker-server (L4), m5-fedramp-auth-server (L4+BOI). Your credential is verified on every tool invocation — not just at session start.
MPP vs M5x402 — When to Use Which
MPP (Machine Payments Protocol, Tempo/Stripe) handles multi-rail routing — stablecoins, cards, Lightning, and other payment rails in a single integration. M5x402 adds the constitutional layer: sovereign credential verification, asset classification enforcement, and jurisdictional anchoring. They are complementary, not competing. M5 rides both rails simultaneously: MPP handles the payment pipe, M5x402 adds the constitutional identity and classification layer on top. Use MPP when multi-rail routing is the primary requirement. Use M5x402 when sovereign credential enforcement is required. Use both when both matter.

Section 7

The Four Infrastructure Pillars

Identity, energy, finance, and health are the four sectors of critical infrastructure that underpin every other sector — and the four areas where ungoverned autonomous agents cause the most irreversible harm. Every SOPHIA developer credential maps to one or more pillars. These are not arbitrary categories. They are the four sectors where sovereign-credentialed edge infrastructure is most urgently needed, and where the M5 wallet creates the most immediate and measurable value for the humans it serves.

◈ Identity
Identity Management
SOPHIA-DEV-IDENTITY
TCID issuance interfaces, ICANN→ICSN migration tooling for clients, FedRAMP-aligned authentication (ID.me IAL2, PIV/CAC, Login.gov), phone sovereignty pipeline (Telnyx — FIND→ATTEST→CONTROL→TOKENIZE), device registry (SV-GW, eSIM/TEE, M5Node device tokenization). 70M+ Americans have verified identity through centralized custodians who monetize that data. This pillar builds the infrastructure that returns identity to its owner.
m5-identity-server · m5-device-server · m5-fedramp-auth-server
SOVEREIGN ADDRESS — JURISDICTION-VERIFIED COMMUNICATION ENDPOINT
Every M5 identity resolves to a legally recognized service endpoint — not an email address, not a username. This is a sovereign digital address: a jurisdiction-verified, TCID-bound, vault-routed communication endpoint that functions as the constitutional PO box of the sovereign human. It is recognized for legal service of notice, regulatory communication, and due process delivery — without exposing a physical address. Wyoming accepts PO box as a legal service address. This extends that principle to the digital sovereign layer.
WHO CAN SEND WITHOUT OPT-IN
Government senders (*.government.m5wallet.eth) for due process and notice · Licensed M4 professional wallets (doctor, lawyer, licensed institution) for regulated communications · Court-ordered delivery through adjudication pool
PAID MESSAGING — BRANDS PAY TO REACH YOU
Every non-authorized inbound message = payment + payload + policy check. Brands do not email for free — they pay to request delivery. User sets their price tier, auto-filter rules, and acceptance policy. Revenue split: User 60% · Network 20% · Validator 10% · Jurisdiction node 10%. This eliminates spam at the protocol level.
THE MASTER APP — SOVEREIGN CONTROL CENTER
The BOM account becomes the sovereign control center on the user's phone — replacing email, notification apps, and communication platforms. Government inbox · Licensed inbox · Paid market inbox · Peer-to-peer inbox. Core services embedded. Earnings dashboard. Policy engine. Immutable delivery log anchored to TitleChain.
Identity lives in the vault · Names live in ENS · Proof lives in TitleChain · Messaging is jurisdiction-aware, consent-based, and paid
◈ Energy
Energy Management
SOPHIA-DEV-ENERGY
M2 REC token issuance (sensor-oracle verified, double-counting eliminated at protocol not policy layer), VIRDIS index integration (Kisosen as reference — 75M RECs, $937.5M reference value), carbon credit cross-recognition across sovereign chains, CPI eco relief programs (36 node pools: CHILDREN, UTIL, FOOD, INFRA across 9 states). The renewable energy market is massive and structurally broken. Sovereign verification fixes it at the data layer — not with more auditors.
m5-eco-index-server · m5-eco-offer-server · m5-ondo-server
◈ Finance
Finance Management
SOPHIA-DEV-FINANCE
M4 issuance pipeline (full BOI→SwiftBRIDGE→CEDECO.eth flow), Ricardian contract deployment (triple-layer: human-readable + machine-readable + executable), settlement routing by asset class, M5Numscript ledger integration, 409A valuation via M5Valoris for developer entities, BPS fee schedule implementation. The finance pillar is where every other pillar's value becomes capitalized, tradeable, and accessible to the communities that produced it.
m5-ledger-server · m5-contracts-server · m5-wallet-server · m5-numscript-server · m5-pricing-server
◈ Health
Health Management
SOPHIA-DEV-HEALTH
The M5HUM (sovereign human) account is the constitutional home of every piece of health and genomic data a person generates across their lifetime. The 23andmine vault — a sovereign data vault issued under the M5HUM credential — gives every member exclusive title to their entire genomic sequence and code: SNP data, whole genome sequences, exome data, methylation profiles, stem cell records, and all derivative research outputs. No third party holds a first position on this data under any circumstances.

What the 23andmine vault covers: Full genomic sequence ownership and titling under UCC Article 12 CER (2022 UCC Amendments, enacted in 33 U.S. jurisdictions) and U.S. Patents 11,720,888 and 12,518,273. SNP tokens — individual single nucleotide polymorphisms mapped to TCID ownership, making each genomic marker a titled M3 asset. Stem cell preservation records (Muse Bio Labs integration). Exome, methylation, and whole genome file custody. Sovereign Data Reclamation Notices served by the member's state BOG authority to any corporation holding their genomic data — requiring full extraction, destruction of all copies including de-identified data, elimination of all traceable breadcrumbs, and confirmed deletion. The 23andMe (TTAM) precedent is the reference implementation.

Consent gate architecture: Three layers before any access is granted — ZK proof of credentialed status (M5-Keelung m5CredentialProof circuit), Notarized Sovereign Consent (SE4 self-determination standard), and a Digital Twinning Guard that prevents any derivative data from being used to reconstruct the original sequence. The member controls every gate. Access requests from health providers, research institutions (BOI accounts), and cooperative pools all flow through this three-layer system. The member licenses their data on their terms. They receive the economic benefit — not the platform.

23andmine.eth cooperative: A BOU cooperative pool allowing M5HUM members to opt-in to personalized medicine research on their own terms — contributing genomic data under consent-gated agreements, earning M2/M3 SNP tokens for each contribution, and retaining revocation rights at any time. LOINC codes for lab observations, ICD-10/11 diagnosis codes, and SNOMED CT clinical terminology all embedded in vault records for full HIPAA and HL7 FHIR R4/R5 compatibility.
m5-comm-server (Signal E2EE) · sovereign-health serverless · m5-identity-server · 23andmine.eth cooperative pool

Section 8

Certification: SOPHIA Developer Credentials

8.1 Developer Onboarding Flow

STEP 01 Domain ownership proof — verify your .com/.gov/.org/.edu via DNS TXT record. Establishes jurisdiction before anything else.
STEP 02 ICANN→ICSN migration — ICSN issues Certificate of Authority. ENS address registered and anchored to TitleChain.
STEP 03 M5Bank account activation — account type (BOM/BOU/BOB/BOI/BOG) determined by legal registration.
STEP 04 SOPHIA certification — complete the course module(s) for your target pillar(s) and credential level.
STEP 05 Credential issued — W3C VC loads to M5POD. LinkedIn publishes automatically. M5Scan.io verifiable immediately.
STEP 06 API access granted — M5x402 endpoints, MCP servers, and SDK unlock at your SFI credential level.

8.2 Three Developer Certification Tiers

SOPHIA-DEV-L1
Prerequisites:
Domain proof
BOM or BOB account
SFI Level 1–2
M1/M2 endpoint access. Basic agent deployment and mandate creation. Identity and energy pillar access. TCUSD credit system, USC code usage, private stablecoin configuration, ICANN→ICSN migration tooling for clients. M5x402 endpoint configuration in Node.js, Python, and Rust. M5Scan.io verification workflows. 27 MCP servers at L1 access level.

Curriculum maps to: Sections 1 (M1/M2), 2, 3, 5 (Gates 1–2), 6 (M1/M2 rails), 7 (Identity + Energy pillars).
SOPHIA-DEV-L2
Prerequisites:
L1 credential
BOB or BOI account
SFI Level 3
M3/M4 endpoint access. Titled asset integration, TitleChain registry API, Ricardian contract deployment (triple-layer: human + machine + executable). M5Numscript ledger scripting. Finance pillar access. ZK_REQUIRED event handling in all three languages. Full M4 issuance pipeline overview (execution requires L3).

Curriculum maps to: Full Sections 1–6, 7 (Finance pillar), all appendices.
SOPHIA-DEV-L3
Prerequisites:
L2 credential
BOI account
SwiftBRIDGE mapping
SFI Level 4–5
Full stack access. Cross-chain bridge (BP11, m5BridgeProof), BOI-tier M4 issuance pipeline execution (full CEDECO.eth flow), SwiftBRIDGE configuration and ISO 20022 message type integration, SPDI custody integration, health pillar advanced access (MyDNA vault, full genomic sovereignty, SNP token issuance, 23andmine.eth cooperative deployment, Sovereign Data Reclamation Notice filing via state BOG), sovereign chain deployment. BOG-tier credential bridge validation.

Curriculum maps to: All sections plus extended M4 issuance practicum and sovereign chain deployment module.

8.3 LinkedIn Credential Publishing

Every SOPHIA developer credential publishes to the holder's LinkedIn profile automatically at issuance — not manually, not upon request. The credential is a W3C Verifiable Credential carrying: certification level, pillar(s) covered, issuing sovereign chain, TCID of the issuing authority, and a direct verification link on M5Scan.io. Any employer, counterparty, or institution can verify in seconds without contacting the issuer. The credential is owned by the developer, stored in their M5POD, portable across all platforms and jurisdictions, and valid until the ICSN working group ratifies a standard revision — at which point renewal is a single re-examination, not a full recertification.

WHAT CERTIFICATION MEANS — THE WEIGHT OF WHAT YOU ARE BUILDING
When you complete SOPHIA-DEV-L1, you are not receiving an API key. You are receiving a credential that says you understand the constitutional layer beneath the payment protocol — the asset classes, the sovereign identities, the mandate boundaries, the ZK proofs, the jurisdiction anchors. When you complete SOPHIA-DEV-L3, you are one of the first humans on earth qualified to deploy sovereign economic infrastructure on Internet 3.0.

The developers who built the x402 protocol built a fast, elegant payment pipe. The developers who build on M5x402 are building the constitutional layer that governs what moves through that pipe, who is accountable for it, and which sovereign jurisdiction holds it. That is a different kind of work. It requires a different kind of credential. It carries a different kind of weight.

The Preamble named the crisis: 525+ ransomware campaigns, $57B in projected annual damage, autonomous agents with a free pass across unguarded endpoints, no identity verification, no audit trail, no accountable human at the end of the chain. The standard you are now certified to build on is the constitutional answer to that crisis. Not a cybersecurity product. Not a compliance framework. A sovereign operating standard for the digital infrastructure of institutions, governments, and humans — built over eight years, patent-protected, and ready to deploy.

Build accordingly.

Apply at m5bank.app/developer


Section 9

Reference Implementation and Developer Tools

ToolWhat It DoesCredentialAccess
M5 Developer SDKW3C DID, W3C VC 2.0, SOLID Protocol. Open source. Node.js, Python, Rust. Zero platform lock-in.Opengithub.com/m5bank/sdk
27 MCP Servers / 208 ToolsFull backend access tiered by SFI level. m5-api-gateway (L1) through m5-lightlocker (L4). TCID verified on every tool call.L1 minm5bank.app/developer/mcp
M5Scan.ioVerify any TCID, credential, asset, CEDECO.eth certificate, ENS mapping, or USC code in real time. Publicly accessible.Publicm5scan.io
M5Canon ValidateClassify any asset before deploying it. Returns class, permitted rails, credential requirements, applicable BPS fees.L1POST /api/m5-canon-validate
M5Canon SandboxTest environment: pre-loaded wallets, mock M5x402 endpoints, ZK proof simulation, M5Mandate boundary testing. No real assets.L1m5bank.app/developer/sandbox
ENS ResolverQuery ICANN→ICSN mapping status, domain ownership verification, Certificate of Authority status, ENS registration lookup.PublicGET /api/ens-resolver
Odea Workflow AgentWorkflow intelligence embedded in every M5POD. Guides Track A (legacy migration) and Track B (native formation). Knows which forms, attestations, and Ricardian contract templates apply per entity type and jurisdiction.L1 + accountm5bank.app/odea
ICSN Global GitBookCanonical public record of sovereign identity for all 50 states, 6 territories, and 220+ nations. Every ENS subdomain, BRIDGE code, M5Bank Node ID, and USC Nation Code. Human-readable and machine-queryable.Publicgitbook.icsnglobal.org
M5-API ENSv2 Record Schema
Required identity records: m5.tcid · m5.class · m5.jurisdiction · m5.vault_uri · m5.notice_policy · m5.messaging_policy · m5.payment_policy · m5.issuer · m5.status · m5.provenance_hash

Signature authority (S0–S7): S0=none · S1=receipt · S2=consent · S3=personal execution · S4=delegated · S5=institutional · S6=fiduciary · S7=constitutional/title/sovereign authority

Agent records: m5.primary_agent · m5.guardian_agent · m5.dignity_agent · m5.ward_agent · m5.agent_activations · m5.agent_states [available|pending|approved|accepted|active|paused|revoked|suspended] · m5.agent_skills

Credential status (C0–C7): C0=unverified · C1=submitted · C2=under review · C3=verified · C4=provisional · C5=accredited · C6=privileged/regulated · C7=sovereign/constitutional authority

Sophia score: m5.sophia_credential_level · m5.sophia_score · m5.sophia_confidence · m5.sophia_domains {financial-literacy, digital-sovereignty, identity-stewardship, governance-participation}

Resolution flow: ENS name → TCID → Vault → Policy Engine → Agent Layer → Provenance → BTC Anchor
L1+docs.m5bank.app/api-schema
M5Node Operator KitMaster MVNO sub-activation, dark fiber IRU preferential routing enrollment, eSIM sovereignty pipeline integration, USC Order Book MVNO capacity token + dark fiber IRU token first-look registration. Full seven-revenue-stream node operation setup.L2 + BOB/BOIm5bank.app/node
M5-AAIF (Linux Foundation)M5-Agentic AI Foundation — M5's open-source AI agent economic framework donated to the Linux Foundation as the neutral global standard for how AI agents transact, credential, and operate across sovereign jurisdictions. Includes M5Canon Ricardian standards, USC token classification, and M5 MCP server architecture. Linus M5Agent is M5's sovereign orchestrator — named in honor of Linus Torvalds.Openlinux.foundation/m5-aaif
Live DashboardM5Bank sovereign banking dashboard — accounts, ledger, digital assets, payments, compliance, cap table, 409A valuation. Includes MyDNA Chart (genomic files, SNP tokens, stem cell records, consent gates, 23andmine.eth cooperative pool), Health Providers, and Reclamation Notice pipeline.L1 + accountquantum-proof-notary-app-wxnmj38y.devinapps.com

9.1 Error Reference

// M5x402 structured error responses — handle each explicitly

402 + "TCID_MISSING"       // No credential on request — return 402 with payment details
403 + "TCID_INVALID"       // TCID fails sovereign chain verification
403 + "SFI_INSUFFICIENT"   // Credential level too low for this asset class
403 + "CBDC_FIREWALL"      // M5-class asset — blocked, logged, M5Watcher alerted
403 + "MANDATE_EXCEEDED"   // Agent hit mandate boundary — surfaced to human, awaiting approval
403 + "ASSET_MISMATCH"     // Asset class inconsistent with credential or settlement rail
503 + "ZK_PROOF_FAILED"    // ZK_REQUIRED event — RuntimeError, blocked NOT skipped
503 + "SOS_PENDING"        // OpenCorporates SOS 24-hour gate not yet cleared
503 + "WATCHER_ALERT"      // M5Watcher compliance anomaly — human review required
503 + "SWIFT_BRIDGE_UNMAP" // BOI account missing SwiftBRIDGE mapping — required for M4

// All errors include: error_code, message, remediation_hint, m5scan_url

The Moment We Are In

Why This Standard Exists, Right Now

Three protocols — x402, MCP, and AP2/TAP — assembled a machine-native payment economy in 2025. They did it fast, elegantly, and without a constitutional layer. They gave autonomous agents the ability to initiate, authorize, and execute financial transactions at machine speed, across any endpoint, with no identity verification, no asset classification, no jurisdictional anchor, and no audit trail back to an accountable human. This was not malicious. It was incomplete. The payment pipe was built. The constitutional layer was not.

The consequence is already visible. $57 billion in projected annual ransomware damage. 80% of attacks now leverage AI tools. The Conduent breach. 25 million government and healthcare records exposed through a single unguarded connection. The attack surface is not theoretical — it is live, it is widening, and the controls designed for the previous era of human-initiated transactions do not apply to machine-speed agent commerce.

THE WINDOW — WHY NOW MATTERS
THE OPEN ATTACK SURFACE
Right now, today, any agent running on any x402-enabled endpoint can initiate financial transactions with no credential, no mandate boundary, no asset classification, and no human at the end of the accountability chain. This is not a future risk. It is the current state of machine-native payments. The standards are being written in this window — by whoever builds them first.
THE REGULATORY MOMENT
The GENIUS Act (July 2025) established the first federal stablecoin framework. UCC Article 12 CER is now enacted in 33 jurisdictions. New York goes live June 3, 2026. The legal infrastructure for digital asset title and sovereign payment is being codified right now. The sovereign banking standard that rides on top of this infrastructure needs to exist before the regulatory moment closes and the defaults are set by others.
THE INFRASTRUCTURE OPPORTUNITY
$471 trillion in illiquid real-world assets. $87 trillion in DTC-custodied securities eligible for sovereign digital migration. 140 million global micro-enterprises with no access to institutional financial infrastructure. 170+ nations that have never had a fair seat at the international financial table. All of it waiting for the constitutional layer that makes it accessible, secure, and sovereign.

The M5x402 standard is the constitutional answer to the open attack surface. It is also the economic answer to the infrastructure gap. And it is the human answer to a financial system that has spent decades using mathematical sophistication not to distribute opportunity but to concentrate it — not to secure identity but to monetize it — not to reward contribution but to extract it.

The Nash Equilibrium design of the USC standard means the incentive always points toward sovereign participation rather than extraction. The Cyrus Protocol gate means the infrastructure is built on human rights commitments, not geopolitical alignment. The M5Score means the sovereign human's reputation is built from what they actually do — not what a third party inferred from data they never consented to share. The M5Canon engine — licensed under the TitleChain Foundation Wyoming 1,000-Year Sovereign Purpose Trust — means the enforcement rules in any deployed version are constitutionally fixed. No licensee, no sovereign, and no working group can modify the engine unilaterally. New standards ratified by ICSN Global through member consensus are implemented in versioned engine releases, each licensed under the same sovereign purpose trust terms — making the path to change deliberate, governed, and transparent rather than unilateral or covert. What the engine enforces today it enforces permanently until a new version is deliberately and publicly released through the same constitutional process.

The developers who build on M5x402 are building the constitutional layer that governs how value moves across the sovereign internet — what is classified as what, who is accountable to whom, which jurisdiction holds which instrument, and which human stands at the end of every agent's action chain.

This is not infrastructure for the next startup cycle. It is infrastructure for the next era of human economic sovereignty. The window to build it correctly — before the defaults are set, before the attack surface is exploited at scale, before the regulatory moment closes — is open right now.

July 4, 2026. Federal Hall, New York City. The launch of Internet 3.0.
Certification opens now. The standard is ready. The infrastructure is built. The sovereigns are activating.

Appendix C

Account Type Decision Tree

Use this flowchart to determine the correct M5Bank account type for any entity. When in doubt, verify on M5Scan.io using the entity's SOS registration number or SWIFT BIC.

ENTITY TYPE? Is it an individual person? YES BOM Bank of Me Can hold BOG creds inside BOM account NO Cooperative / Trust / DUNA / DAO? YES BOU Bank of Us NO Government AGENCY legal entity? (DoD, HHS, FDA, state dept, tribal govt body) YES BOG Bank of Government Agencies only Person = BOM NO Licensed institution — SPDI, bank, university, research body, regulated entity? YES BOI Bank of Institution + DTTC + SwiftBRIDGE → can initiate M4 NO BOB Bank of Business LLC · Corp · holding co · tribal enterprise KEY RULES SPDI (Special Purpose Depository) = BOI Person + gov credentials = BOM Tribal GOVT CHAIN = BOG Tribal ENTERPRISE = BOB Fed agencies → unitedstatesgovernment.eth State agencies → [statechain].eth Public registry ENS = state-assigned Custom ENS = entity choice Verify: m5scan.io
Appendix J

Account Type Permissions Matrix

Capability BOM BOU BOB BOI BOG
M1 Utility transactions
TCUSD credit operations
Private stablecoin issuance (M1)
M2 Commodity tokens (hold)
M2 Token issuance
M3 Titled asset NFTs
M4 Security tokens (hold)gov only
M4 Issuance (initiate via CEDECO.eth)+ DTTC + SwiftBRIDGE
M5 Sovereign instruments
SwiftBRIDGE mapping
M5Mandate creation
Agent deployment
ICANN→ICSN migration
BOG credentials (hold within BOM)hold only✓ entity
Adjudication poolviewviewparticipate
Base L2 settlement (M1)
Ondo Finance settlement (M2)
Canton / XRP settlement (M3)
Rialto Markets / tZERO / INX (M4)gov only
Ricardian contract deploymentL2+
M5Node validator operationpartial