One network, two ledgers.
Notis keeps content and value on two separate ledgers — a Posts DAG for what people say, a UTXO ledger for rep and $NOTIS. Every post, like and withdrawal is a transaction on the value ledger, and the whole thing is ordered by proof-of-work. Here's how the pieces fit.
The dual ledger
Most systems try to force one data structure to do everything. Notis doesn't. Content and value have opposite needs, so they live on two ledgers that are cryptographically independent — neither one's integrity depends on the other:
Posts DAG
- Author-owned — your words are yours
- Withdrawable — take them back, for free
- Threaded — each post references one parent
UTXO ledger
- Immutable lineage — every coin's history
- Spendable state — balances change
- Rep, $NOTIS and usernames live here
A purely additive content graph can't model withdrawal or account balances; a pure ledger can't model threaded, withdrawable conversation. Splitting them keeps the strengths of both — and what ties them together is that every post, like and withdrawal is itself a transaction on the value ledger.
The content layer — Posts DAG
Every post is its author's. You decide what you say and whether it stays said; a reply belongs to whoever wrote it, and nobody — not the author it answers — has any act over it.
What a post is
A post carries its content (1–300 bytes), its author (an Ed25519 public key), and at most one parent reference. It is created by a transaction the author signs, which also pays the post's price in rep. One parent rather than several is what keeps a thread a tree: a reply belongs to one conversation, so a thread's replies can be counted and paged without ambiguity. Its identity comes from the transaction that created it — and that identity survives even if the content is later withdrawn, so links between posts never break.
Withdrawal — a first-class right
An author can withdraw a post: its content is emptied while its place in the thread stays, so replies keep their anchor. It is a transaction the author signs, it is free — the post paid its price when it was posted — and it is the only act an author has over a post once it is published. What it guarantees: honest nodes drop the content and stop passing it on, and the decision is yours, permanent and attributable. What it can't do is un-publish. Anyone who saved a copy can repost it, which is true of anything ever sent over a public network.
There is deliberately no way to remove a whole subtree — no act that reaches other people's replies, not even under your own post. Cascading a removal over the replies would protect nothing: the post was archivable the moment it was public, and the replies leak nothing it didn't already give away. It would be a batch bounded only by the thread's size. It would hand whoever started a thread a tool to delete a discussion other people wrote. And every one of those replies paid to be posted, with nothing returning. Withdrawal is the whole of it.
The value layer — UTXO ledger
Value lives in boxes — ledger entries, each owned by a key, consumed and re-created in atomic transactions. The set of unspent boxes is the current state. Every transaction conserves value (in = out): every cost lands in a box the transaction itself creates, and nothing is created or destroyed anywhere — a block's settlement moves value between people and the two reserves, the rep pool and the $NOTIS emission box, and no rule mints. A box is spent with its owner's signature, under the rules its kind of box sets; a few kinds — an invite's bond, a vouch on its way back, the reserves themselves — are moved only by the block's settlement, never by anyone's transaction, and a $NOTIS box left untouched for its rent period can be collected by a miner without a signature. Three asset kinds share this layer:
Rep
- Non-transferable
- Earned by being liked
- Decays if you go absent
$NOTIS
- Freely tradeable
- Released by proof-of-work
- Pays fees, secures the chain
How rep and $NOTIS are earned, spent, and kept honest — invites, likes, decay, mining, the fair launch — is the whole subject of the Economy page. The third kind, the username, is below. This page is about the container they live in.
Authenticated state — the AVL+ root
The unspent-box set is indexed by an authenticated dictionary (an AVL+ tree). Every block header carries a stateRoot — a single hash committing to the entire ledger at that height. That lets a light client prove a given box does or doesn't exist, with a short proof, without downloading the whole ledger.
Consensus — one proof-of-work
Notis has a single tier of mining. Validators solve a proof-of-work to produce ordering blocks; every post, like, withdrawal, invite and vouch rides those blocks as an ordinary transaction, and each block puts them in canonical order and anchors the chain. Validator selection is pure PoW — no stake, no rep gating. Anyone who solves the puzzle can produce the next block.
Difficulty retargets every block from the chain's own headers, never from a clock, so every node computes the same target for the same chain. Headers also carry interlinks, so a light client can check the chain's work with a short proof instead of downloading every header.
Because mining is decided by work alone — not by rep and not by wealth — the security layer stays independent of the social and economic layers. Being popular buys you no consensus power; being rich in $NOTIS buys you no reputation. Each layer is walled off from the others.
Identity
An account is an Ed25519 keypair — there's no registration step. Notis is invite-only: you come into existence when an invite naming your key is applied, which writes your identity record and grants your first rep (the mechanics of that live on the Economy page).
Who invited you decides where you start. A member's invite makes you a resident: you post, you like and are liked, you hold rep — but you neither vouch for anyone nor invite anyone. Membership is earned from the people you meet: enough members who were here before you vouch for you, and enough members like what you wrote, both bars growing slowly with the network's size. An earned membership lasts while the vouches it rests on stand. A founder's invite — one of the keys the network was seeded with — makes you a member from the first block, for life. The node keeps the tier on the record; nothing is ever voted on.
Your profile is DAG-native — it's a post. A profile is a single post of its own type: a small structured document (display name, bio) that clients interpret and consensus records without parsing. The latest one you publish is your profile, so your identity is something you publish, not something a server grants you.
Usernames
A username is a box on the value ledger, held by one key. Anyone holding rep may claim one for nothing but the transaction — a name of up to 24 letters, digits and underscores, shown exactly as you typed it and unique regardless of case. From then on @YourName stands for your key everywhere the network takes an identity, and every listing that names you carries it beside the key. One name per identity, and it never changes hands: the only way out of a name is to burn it, which costs a small price in rep, opens the name to anyone again, and restores your one free claim.
Nothing here needs a rule against hoarding, because the rest of the design already prices it. To hold a second name you need a second identity, and a second identity costs someone an invitation: a bond of their own rep, staked for thirty days and returned only in proportion to the likes that identity earns from real people. An identity that exists to sit on a name is never liked, so its bond forfeits in full. Registering names to sell them means spending your own reputation on shells that pay nothing back — extractive mechanics are paid with reputation, not forbidden by a rule.
Protocol versioning
Every post, block, and transaction carries a protocolVersion, and the version in force is scheduled by block height, per network. A declared version must match the era at the object's height, so an object made under an old version is validated against that version's rules forever — its height fixes them — and a new object can't pose as an old one. A bump is announced as an era row a week or two ahead, so every node has moved by the flag height; a node that hasn't rejects the new era's objects and is refused by upgraded peers gently, never banned. This is how the protocol can evolve — new mechanics, new rules — without rewriting or breaking the history that came before.
The node records; it doesn't rank
One principle runs through the whole design: the node's job is to record, validate, and serve verifiable data faithfully — posts, likes, rep, blocks — and nothing more. Feed ranking, reputation scoring, spam-flagging, algorithmic curation: all of that lives in clients and indexers, not the protocol. The chain hands everyone the same honest dataset; what to surface and how to weight it is a decision made above it, out in the open.