Developers
Building on PolicyBlockchain
Networks, node tiers, how to connect and send transactions, the contracts, and how to run a node.
- Status
- Live running now
- Building being built
- Planned not started
Overview
PolicyBlockchain is a permissioned network of two EVM chains, split by trust group. Money runs on the Settlement chain, validated by IEC. Insurance records run on the InsureBio chain, validated by five partners, which checkpoints Merkle roots into Settlement.
Only fingerprints and pointers go on a chain. Record bodies stay in the registries and the audit log. Applications never call a validator: writes go through a chain gateway, which holds the signing keys.
Networks
| Network | Chain ID | Validators | Status |
|---|---|---|---|
| Settlement mainnet | 1117710 | 4, run by IEC | Live |
| Settlement testnet | 11177102 | 4, run by IEC | Planned |
| InsureBio mainnet | 1140615 | 5: IEC, IBC (BindDesk), InsureCap, Paragon, Santee | Live |
| InsureBio testnet | 11406152 | 4, run by IEC | Live |
InsureBio mainnet went live on 3 October 2026. Tennessee and Lloyd's Lab each run a read-only full node on it.
Common to every network
| Setting | Value | Notes |
|---|---|---|
| Client | Hyperledger Besu 26.9.0 | Pinned |
| Consensus | QBFT | Final in one block, no confirmations needed. Tolerates f faulty validators out of 3f + 1 |
| Block time | 2 s | Set in the chain configuration |
| EVM | Shanghai | Active from block 0. Cancun is off, so no TSTORE, MCOPY or blobs |
| Gas | Zero | Minimum gas price is 0. Platform usage is metered off chain, not by the chain |
| Starting balances | None | No premine |
| Discovery | Off | Peers are explicit: static nodes and firewall allow-lists |
Node tiers
| Tier | Signs blocks | Full copy | Who | RPC |
|---|---|---|---|---|
| Validator | Yes | Yes | Settlement: IEC. InsureBio: the five partners | Local to the node only |
| Writer | No | Yes | Platform services and, later, agencies | Private network; ETH, NET, WEB3, TXPOOL |
| Full | No | Yes | Tennessee, Lloyd’s Lab, developers | Read-only (ETH, NET, WEB3), allow-listed |
| Light | No | Summaries | Viewers | Through the explorer and its API |
Hard rule: no application calls a validator's RPC. The QBFT API controls validator voting, so it stays local to the validator and is used only by operators.
Nothing is open to the public internet. Nodes talk to each other on port 30303 from allow-listed peers only. The public explorer API requires a free Bio-ID sign-in.
Connecting
Public testnet: coming Public RPC endpoints will be published with the public testnet. Until then, partners get access by request.
Platform services will receive the RPC URL as an injected environment variable and write through the chain gateway. Do not hardcode node addresses. Until the gateway ships, write access is operator-only.
viem · read (TypeScript)
import { createPublicClient, http, defineChain } from 'viem'
export const settlement = defineChain({
id: 1117710,
name: 'PolicyBlockchain Settlement',
nativeCurrency: { name: 'none', symbol: 'NONE', decimals: 18 },
rpcUrls: { default: { http: [process.env.PBC_SETTLEMENT_RPC_URL!] } },
})
const client = createPublicClient({ chain: settlement, transport: http() })
const block = await client.getBlockNumber()bash · health check
curl -s -X POST -H 'content-type: application/json' \
--data '{"jsonrpc":"2.0","id":1,"method":"eth_chainId","params":[]}' \
$PBC_SETTLEMENT_RPC_URL
# {"result":"0x110e0e"} = 1117710Sending transactions
- Gas price is zero. Send legacy transactions with
gasPrice: 0, or EIP-1559 withmaxFeePerGas: 0andmaxPriorityFeePerGas: 0. A tool that defaults the priority tip to 1 wei will be refused, so set it explicitly. - Compile for Shanghai. Use
evm_version = "shanghai"and Solidity 0.8.24 or newer. Cancun-only opcodes fail. - Finality is one block, about 2 seconds. Do not wait for confirmations.
- Services never hold chain keys. The chain gateway signs.
foundry · cast
cast send $CONTRACT 'fn(uint256)' 42 \
--rpc-url $PBC_SETTLEMENT_RPC_URL \
--legacy --gas-price 0Contracts
Not yet deployed Four contracts for the Settlement chain are built and tested (OpenZeppelin v5, Foundry, 92 tests). They are not deployed: they go live after review. They are not upgradeable in version 0.
| Contract | Purpose | Guarantees |
|---|---|---|
| Reserve | The Tawa Reserve: records deposits and daily bank attestations | Each settlement ID is used once. Minting pauses if the latest attestation is stale or failing |
| Tawa | Platform credit, issued against the Reserve | Issued only against a recorded, unused deposit. Peer-to-peer transfers are off by default |
| PromoTawa | Expiring promotional credit | Issued in lots that expire, within a funded budget. Not transferable |
| PolicyPoints | Insured rewards | Issued only while the Reserve covers what is outstanding. Not transferable |
Separation of duties
Roles are held by different parties: an admin multisig, a checker that records deposits and signs the daily attestation, a minter (the chain gateway), a meter role, and a pauser for emergencies. No role can both record a deposit and mint against it.
Environments
| Level | What | Use for |
|---|---|---|
| Local | Anvil (chain 31337), or the four-node Besu network from the network repository | Unit and integration tests on your machine |
| Testnet | 11177102 and 11406152 | Sandbox and partner integrations. Test money is free and the network is resettable |
| Fork rehearsal | anvil --fork-url $PBC_SETTLEMENT_RPC_URL | Rehearsing any mainnet change on real state. Required before every mainnet change |
| Mainnet | 1117710 and 1140615 | Production only |
Release path: local, then testnet, then fork rehearsal, then mainnet.
Running a node
Partners and developers can run a full node. Validators join by vote of the existing validator set.
- Get
genesis.jsonandstatic-nodes.jsonfor the network from IEC. Never generate your own genesis. - Run Besu 26.9.0 with discovery off, minimum gas price 0, and the RPC APIs for your tier.
- Generate the node key on the machine and back it up encrypted. It never leaves the node in plain text.
- Send IEC the node's enode and public IP address. IEC adds it to the peers' allow-lists and static nodes.
- Sync to the tip, then check that
eth_chainIdis correct and that you have peers. - Validators only: the existing validators vote you in. Taking over a seat means a new key on your machine plus a vote. There is no new genesis.
besu · full node (generic)
docker run -d --name besu --network host \
-v $PWD/config:/opt/besu/config:ro -v $PWD/data:/opt/besu/data \
hyperledger/besu:26.9.0 \
--genesis-file=/opt/besu/config/genesis.json \
--static-nodes-file=/opt/besu/config/static-nodes.json \
--data-path=/opt/besu/data --discovery-enabled=false \
--min-gas-price=0 --rpc-http-enabled \
--rpc-http-api=ETH,NET,WEB3 --rpc-http-host=127.0.0.1Links and access
| Resource | Status |
|---|---|
| Explorer ↗ | Live |
| Live network map ↗ | Live |
| Public testnet RPC | Coming |
| Chain gateway | Planned |
| Contract deployment | After review |
| Data standard (draft v0.1) | Request for comment |
Partner access, node onboarding and testnet access are by request.