Skip to content

Developers

Building on PolicyBlockchain

Networks, node tiers, how to connect and send transactions, the contracts, and how to run a node.

Status
Live running now
Building being built
Planned not started

Overview

PolicyBlockchain is a permissioned network of two EVM chains, split by trust group. Money runs on the Settlement chain, validated by IEC. Insurance records run on the InsureBio chain, validated by five partners, which checkpoints Merkle roots into Settlement.

Only fingerprints and pointers go on a chain. Record bodies stay in the registries and the audit log. Applications never call a validator: writes go through a chain gateway, which holds the signing keys.

PolicyBlockchain architectureApplications write through a gateway to the Settlement chain and the InsureBio chain. InsureBio checkpoints Merkle roots into Settlement. Record bodies stay in the registries and audit log, off chain.Applicationsand partner systemsChain gatewaysigns and submitsSettlement chain · 1117710Money movement · the Tawa ReserveQBFT · Besu · IEC validatorsInsureBio chain · 1140615Identities, entities, policies, grantsQBFT · Besu · five partner validatorscheckpoints Merkle rootsOff chain: record bodies stay in the registriesand the audit log. Chains hold fingerprints.
Writes go through the gateway. Only fingerprints and pointers are placed on either chain.

Networks

NetworkChain IDValidatorsStatus
Settlement mainnet11177104, run by IECLive
Settlement testnet111771024, run by IECPlanned
InsureBio mainnet11406155: IEC, IBC (BindDesk), InsureCap, Paragon, SanteeLive
InsureBio testnet114061524, run by IECLive

InsureBio mainnet went live on 3 October 2026. Tennessee and Lloyd's Lab each run a read-only full node on it.

Common to every network

SettingValueNotes
ClientHyperledger Besu 26.9.0Pinned
ConsensusQBFTFinal in one block, no confirmations needed. Tolerates f faulty validators out of 3f + 1
Block time2 sSet in the chain configuration
EVMShanghaiActive from block 0. Cancun is off, so no TSTORE, MCOPY or blobs
GasZeroMinimum gas price is 0. Platform usage is metered off chain, not by the chain
Starting balancesNoneNo premine
DiscoveryOffPeers are explicit: static nodes and firewall allow-lists

Node tiers

TierSigns blocksFull copyWhoRPC
ValidatorYesYesSettlement: IEC. InsureBio: the five partnersLocal to the node only
WriterNoYesPlatform services and, later, agenciesPrivate network; ETH, NET, WEB3, TXPOOL
FullNoYesTennessee, Lloyd’s Lab, developersRead-only (ETH, NET, WEB3), allow-listed
LightNoSummariesViewersThrough the explorer and its API

Hard rule: no application calls a validator's RPC. The QBFT API controls validator voting, so it stays local to the validator and is used only by operators.

Nothing is open to the public internet. Nodes talk to each other on port 30303 from allow-listed peers only. The public explorer API requires a free Bio-ID sign-in.

Connecting

Public testnet: coming Public RPC endpoints will be published with the public testnet. Until then, partners get access by request.

Platform services will receive the RPC URL as an injected environment variable and write through the chain gateway. Do not hardcode node addresses. Until the gateway ships, write access is operator-only.

viem · read (TypeScript)

import { createPublicClient, http, defineChain } from 'viem'

export const settlement = defineChain({
  id: 1117710,
  name: 'PolicyBlockchain Settlement',
  nativeCurrency: { name: 'none', symbol: 'NONE', decimals: 18 },
  rpcUrls: { default: { http: [process.env.PBC_SETTLEMENT_RPC_URL!] } },
})

const client = createPublicClient({ chain: settlement, transport: http() })
const block = await client.getBlockNumber()

bash · health check

curl -s -X POST -H 'content-type: application/json' \
  --data '{"jsonrpc":"2.0","id":1,"method":"eth_chainId","params":[]}' \
  $PBC_SETTLEMENT_RPC_URL
# {"result":"0x110e0e"} = 1117710

Sending transactions

  • Gas price is zero. Send legacy transactions with gasPrice: 0, or EIP-1559 with maxFeePerGas: 0 and maxPriorityFeePerGas: 0. A tool that defaults the priority tip to 1 wei will be refused, so set it explicitly.
  • Compile for Shanghai. Use evm_version = "shanghai" and Solidity 0.8.24 or newer. Cancun-only opcodes fail.
  • Finality is one block, about 2 seconds. Do not wait for confirmations.
  • Services never hold chain keys. The chain gateway signs.

foundry · cast

cast send $CONTRACT 'fn(uint256)' 42 \
  --rpc-url $PBC_SETTLEMENT_RPC_URL \
  --legacy --gas-price 0

Contracts

Not yet deployed Four contracts for the Settlement chain are built and tested (OpenZeppelin v5, Foundry, 92 tests). They are not deployed: they go live after review. They are not upgradeable in version 0.

ContractPurposeGuarantees
ReserveThe Tawa Reserve: records deposits and daily bank attestationsEach settlement ID is used once. Minting pauses if the latest attestation is stale or failing
TawaPlatform credit, issued against the ReserveIssued only against a recorded, unused deposit. Peer-to-peer transfers are off by default
PromoTawaExpiring promotional creditIssued in lots that expire, within a funded budget. Not transferable
PolicyPointsInsured rewardsIssued only while the Reserve covers what is outstanding. Not transferable

Separation of duties

Roles are held by different parties: an admin multisig, a checker that records deposits and signs the daily attestation, a minter (the chain gateway), a meter role, and a pauser for emergencies. No role can both record a deposit and mint against it.

Environments

LevelWhatUse for
LocalAnvil (chain 31337), or the four-node Besu network from the network repositoryUnit and integration tests on your machine
Testnet11177102 and 11406152Sandbox and partner integrations. Test money is free and the network is resettable
Fork rehearsalanvil --fork-url $PBC_SETTLEMENT_RPC_URLRehearsing any mainnet change on real state. Required before every mainnet change
Mainnet1117710 and 1140615Production only

Release path: local, then testnet, then fork rehearsal, then mainnet.

Running a node

Partners and developers can run a full node. Validators join by vote of the existing validator set.

  1. Get genesis.json and static-nodes.json for the network from IEC. Never generate your own genesis.
  2. Run Besu 26.9.0 with discovery off, minimum gas price 0, and the RPC APIs for your tier.
  3. Generate the node key on the machine and back it up encrypted. It never leaves the node in plain text.
  4. Send IEC the node's enode and public IP address. IEC adds it to the peers' allow-lists and static nodes.
  5. Sync to the tip, then check that eth_chainId is correct and that you have peers.
  6. Validators only: the existing validators vote you in. Taking over a seat means a new key on your machine plus a vote. There is no new genesis.

besu · full node (generic)

docker run -d --name besu --network host \
  -v $PWD/config:/opt/besu/config:ro -v $PWD/data:/opt/besu/data \
  hyperledger/besu:26.9.0 \
  --genesis-file=/opt/besu/config/genesis.json \
  --static-nodes-file=/opt/besu/config/static-nodes.json \
  --data-path=/opt/besu/data --discovery-enabled=false \
  --min-gas-price=0 --rpc-http-enabled \
  --rpc-http-api=ETH,NET,WEB3 --rpc-http-host=127.0.0.1