Disclosures correct the assumptions a reader might otherwise overread. The corpus combines privacy, settlement, tokenomics, governance, external assets, and future architecture, so a reader may assume more implementation maturity, privacy, legal certainty, or project responsibility than it supports.
That correction belongs beside the claim, before a reader relies on it or repeats it as fact.
A useful disclosure is close to the claim it qualifies. It names the risk category, explains the boundary, and points back to evidence. It does not bury the issue behind a generic sentence that “risks exist.”
Disclosure Matrix
| Disclosure area | What readers must not infer | Required public posture |
|---|---|---|
| Maturity | Every whitepaper feature is already live. | Separate current behavior, target architecture, research lanes, and open questions. |
| Technical risk | Cryptography, wallets, bridges, DA, or proofs are risk-free. | State assumptions, implementation status, audit status, and evidence limits. |
| Privacy risk | Z00Z provides universal anonymity or universal recoverability. | Explain limited base-layer observability, wallet-implementation and operator data surfaces, ingress/egress edges, and scoped disclosure. |
| Token and economic risk | Tokenomics guarantee value, yield, liquidity, or stable outcomes. | Keep utility, treasury, fee, bond, and incentive language non-promotional. |
| Third-party integration | A compatible wallet or service is official or endorsed. | Identify z00z_wallets as the Z00Z open-source reference implementation; identify a custom wallet or other service by its actual developer, operator, affiliation, and support model. |
| Issuer separation | Z00Z guarantees reserves, redemption, legality, or solvency of third-party assets. | State that issuers and integrators own their own asset, reserve, and compliance duties. |
| Governance and treasury | Governance can casually rewrite invariants or founders can redirect value. | Distinguish protocol invariants, bounded policy parameters, challenge windows, caps, and control, affiliation, and operational-role evidence. |
| Security reviews | A review removes all defects or guarantees safety. | Describe review scope, date, residual risk, and unsupported areas. |
| Compliance classification | A protocol or wallet label proves that AML/CFT/CPF, sanctions, Travel Rule, licensing, monitoring, recordkeeping, or reporting duties do not apply. | Classification and controls follow actual functions, operators, users, data, affiliations, and jurisdictions; a profile does not reallocate those duties. |
| Offline and self-hosted flows | Delayed connectivity or a self-hosted address creates a universal exemption. | Disclose non-finality, conflict risk, local limits, later reconciliation, and any service-level duties that apply. |
| Responsibility allocation | Wallet software makes every use compliant or becomes responsible for a self-custodial user’s transactions. | The user controls keys, profile, local history, records, and disclosures and remains responsible for duties applicable to the user’s own conduct; project-linked and independent operators retain duties arising from what they actually distribute, operate, or control. |
| Retention and pruning | A 90-day target means every transaction, all personal data, or every independent copy is deleted. | Only expressly temporary challenge material may become deletion-eligible after the versioned block-height window and all retention conditions; settlement, replay, anchor, wallet-local, and independently retained records remain outside that claim. |
Maturity Disclosure
The documentation corpus contains several maturity states. Some pages describe current protocol direction. Some describe target architecture. Some describe future overlays such as corporate archives, richer disclosure tooling, mature external-asset lockers, governance hardening, agentic reward systems, or post-quantum migration. Those should not be collapsed into one present-tense product claim.
Maturity labels should be direct. Say “current,” “target,” “research,” “planned,” “not yet live,” or “open question” when those labels are true. Do not use ambitious roadmap language as a substitute for implementation evidence.
Privacy Risk Disclosure
Privacy is layered. The protocol may minimize public observability while ingress, egress, exact timing, service logs, wallet reuse, support exports, analytics, bridges, issuers, or corporate records still create visibility. Disclosures should reject absolute phrases such as untraceable, untouchable, regulation-proof, nobody can investigate, or trails disappear forever.
The safe posture is precise: Z00Z is designed for private settlement semantics, user-controlled possession, limited base-layer public observability, and scoped disclosure. It does not erase every outside data source and does not create a universal backdoor. The wallet role remains part of Z00Z architecture, but the reference crate or a custom implementation is not itself a legal actor. Its local data boundary places wallet history and configuration under user control, and the user retains duties that applicable law assigns to the user’s own conduct rather than transferring them to wallet software. Any project-linked or independent operator retains duties arising from its own functions.
The documented target challenge window is 1,555,200 finalized blocks,
nominally 90 days at a five-second finalized-block cadence, starting at
da_publication_ready. Expiry is not a day-91 erasure promise. It can make only
expressly temporary challenge material eligible for deletion after every
applicable versioned-profile condition; it does not
delete current settlement state, required replay or spent-state records,
anchors, finality evidence, wallet-local history, or independently retained
copies.
Token And Economic Risk Disclosure
Tokenomics and governance materials must avoid price, yield, appreciation, liquidity, or stable-value promises. The tokenomics corpus treats fees, bonds, treasury, incentives, useful-work programs, and bootstrap support as bounded design surfaces with risks. It also warns against treasury capture, market thinness, discretionary insider control, and AI or model systems that silently become value movers.
Public pages should say what the token or treasury mechanism is for, what remains provisional, what governance may tune, and what governance should not casually change. They should not imply that economic design removes market risk.
Third-Party And Issuer Disclosure
The wallet role is part of the Z00Z architecture, and z00z_wallets is the
project’s open-source reference/demo implementation. A custom compatible wallet
may be a project-linked or independent product depending on actual ownership,
control, distribution, support, and operations. The same facts determine
whether bridges, issuers, marketplaces, infrastructure providers, auditors,
analytics tools, and regulated services are independent. Compatibility is not
endorsement. A Z00Z-compatible wallet, service, or asset is not automatically
approved.
External assets require especially explicit wording. The protocol may validate internal rights or settlement transitions, but it does not automatically prove external reserve integrity, issuer solvency, legal status, redemption access, or support quality. Those obligations belong to the external actor that makes the promise.
Governance And Treasury Disclosure
Governance should be described by scope. Some parameters may be tunable. Deep cryptographic assumptions, serialization rules, replay boundaries, checkpoint semantics, vested rights, and settlement invariants should not be narrated as casual governance variables. Treasury programs should be rule-bound, capped, evidence-bound, challengeable, and separated from discretionary founder or steward control.
AI or agentic review systems should be disclosed as assistants, classifiers, routers, challengers, or recommenders unless a later design explicitly gives them a governed execution role. They must not be described as hidden owners of value movement.
User Responsibility Disclosure
Users remain responsible for keys, devices, any policy profiles they choose, local transaction history, receipts, backups, lawful use, taxes, accounting, reports, disclosures, and other obligations attached to their own conduct. They may select, modify, or create a country or regional wallet profile where a wallet supplies that capability, but must verify and maintain it and keep required rules and records current.
Where legally required, the user provides retained evidence to competent authorities in the user’s jurisdiction. Wallet software does not assume or certify that responsibility. Project-linked and independent operators retain duties arising from the functions, interfaces, data, claims, and services they actually distribute, operate, or control. See the Compliance Framework.
The Protocol is not everyone’s archive. A steward, if one exists, is not thereby everyone’s operator. A documentation site is not legal counsel.
Read Next
- Public Claim Boundaries for approved and prohibited wording.
- Compliance Framework for AML/CFT/CPF, sanctions, Travel Rule, configurable wallet profiles, records, and actual-function responsibility.
- Website Use And Risk Notice for the website notice boundary and the requirements for any actual service terms.
- Website Data-Boundary Notice for the source-backed site surface and missing deployment-specific facts.
Evidence and Further Reading
- Legal Architecture sections 16-18 define legal threat models, public claims, safe formulas, technical non-possession, and layered responsibility.
- Tokenomics and Incentives sections 8-10 define governance boundaries, token and market risks, treasury capture risks, and the limits of economic claims.
- DAO section 10 and appendix E support governance, treasury, model-control, and future-parameter disclosures.
- Privacy Threat Model And Metrics section 6 supports the privacy anti-pattern disclosures and the prohibition against absolutist privacy language.
- Legal Architecture appendix A provides the claims matrix used to distinguish safe formulas, caveated claims, and prohibited phrases.