> For the complete documentation index, see [llms.txt](https://docs.optivalux.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.optivalux.com/technical/terminology.md).

# Terminology

Optivalux uses product language in public and user-facing material. The protocol uses implementation language. This page maps one to the other.

> **Implementation terms in the middle column are for technical readers.** They are not user-facing vocabulary and should not appear in owner-facing or general product explanations.

## Public term → implementation term

| Public term                                                               | Implementation term                                                                               | Notes                                                                                                                                                               |
| ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Product certificate                                                       | ERC-721-based, restricted-transfer certificate in the `ProductCertificate` ledger                 | ERC-721 **read** compatibility only. Standard ERC-721 transfers and approvals are disabled. No burn path. Not soulbound: it changes owner through controlled flows. |
| Certificate number                                                        | Certificate identifier (`tokenId`), derived deterministically from brand, batch and authenticator | Shown to users as a certificate number.                                                                                                                             |
| Registration                                                              | Provisioning (`provision`)                                                                        | Requires fresh, context-bound possession evidence. The certificate is created into brand custody.                                                                   |
| Made available to be claimed (no public status label; shown as Unclaimed) | Release (`PROVISIONED → CLAIMABLE`)                                                               |                                                                                                                                                                     |
| Claim                                                                     | Claim (`ClaimIntent` + possession evidence + `ClaimAuthorization`)                                | Credentials are consumed off-chain.                                                                                                                                 |
| Transfer                                                                  | Bilateral transfer (`TransferIntent` + `TransferAcceptance` + possession evidence)                | Recipient-bound; no open or bearer intents.                                                                                                                         |
| Registered authenticator                                                  | Bound authenticator (`scheme`, `authenticatorId`)                                                 | `authenticatorId` is a domain-separated hash of the hardware identifier.                                                                                            |
| Verification evidence                                                     | Possession evidence / possession proof; for symmetric tags, a `PossessionAttestation`             | "Proof of possession" in the protocol means proof of **recent access**.                                                                                             |
| Optivalux verification service                                            | Attestation service (KAS) and its attester keys                                                   | Trust anchor for symmetric authenticators only.                                                                                                                     |
| Symmetric authenticator                                                   | Model S (e.g. NTAG 424 DNA with SUN messages)                                                     | Not ERC-5791 / PBT.                                                                                                                                                 |
| Asymmetric authenticator                                                  | Model A (secure element with on-chip key pair)                                                    | Reuses chip-signature verification ideas; does **not** adopt ERC-5791 transfer semantics.                                                                           |
| Certificate standing                                                      | Standing (`ACTIVE`, `SUSPENDED`, `VOIDED`)                                                        | Independent of phase, owner lock and binding.                                                                                                                       |
| Unclaimed / Owned                                                         | Phase (`PROVISIONED`, `CLAIMABLE`, `OWNED`)                                                       |                                                                                                                                                                     |
| Owner report of loss or theft (descriptive; not a public status)          | Owner lock (`LOCKED`)                                                                             | Owner-only. Public product term not yet established.                                                                                                                |
| Brand security role                                                       | Brand security authority (SA), a contract account (multi-signature in deployments)                | Separate from brand admin and operators.                                                                                                                            |
| Brand continuity role                                                     | `BrandContinuityAuthority`                                                                        | Objective activation after SA inactivity; narrow powers.                                                                                                            |
| Request submission service                                                | Relayer                                                                                           | Submits signed requests; untrusted for authorization. Fee policy not yet fixed.                                                                                     |
| Temporary protocol safety restrictions                                    | Guardian                                                                                          | Restrictions ≤ 14 days, non-extendable, ≥ 14-day cooldown.                                                                                                          |
| Brand-assisted recovery                                                   | **R1**: issuer-assisted recovery (`recoverWithBrand`)                                             | Owner `RecoveryIntent` + SA `RecoveryAuthorization` + possession of the new authenticator.                                                                          |
| Recovery Authenticator recovery                                           | **R2** (`requestRecovery` → 14 days → `completeRecovery`)                                         | Owner intent + fresh proof from the reserved Recovery Authenticator; cancellable; vetoable by a fresh trusted primary proof.                                        |
| Recovery Authenticator                                                    | Reserved Recovery Authenticator                                                                   | Asymmetric, on-chain verifiable, write-once, unique forever.                                                                                                        |
| Authenticator replacement                                                 | Rebind (`TAG_REBIND`); old authenticator `RETIRED`                                                | Retirement is permanent.                                                                                                                                            |
| Protection Mode                                                           | Slow escape (≥ 14 days, `SlowEscapeModule`) into the escape harbor (`EscapeHarbor`)               | Public name is Protection Mode; internal names are never shown to users.                                                                                            |
| Protection Mode without the protection period                             | Emergency (fast) escape into the harbor                                                           | Only while the pinned version is frozen or its code no longer matches.                                                                                              |
| Protected state                                                           | Pinned to the harbor (`PINNED(HARBOR)`)                                                           | Non-operational: no transfer, claim or rebind from the harbor.                                                                                                      |
| Leaving the protected state                                               | Harbor exit                                                                                       | Owner authorization + fresh possession, into a historically consented, usable version.                                                                              |
| Challenge (of recovery or Protection Mode)                                | Veto by a fresh, trusted proof of the current primary authenticator                               | Symmetric vetoes limited to one per certificate per 30 days.                                                                                                        |
| Protocol software version                                                 | Controller version (`CertificateController`)                                                      | Each certificate is pinned to one.                                                                                                                                  |
| Moving to a new software version                                          | Voluntary migration (re-pin)                                                                      | Owner-authorized; new version must be approved, matured and brand-consented.                                                                                        |
| Protocol governance                                                       | Governance (Safe + `TimelockController`)                                                          | Approves versions; cannot change ownership.                                                                                                                         |
| Indexes / databases                                                       | Indexer and database projection                                                                   | Never authoritative for ownership.                                                                                                                                  |
| Blockchain infrastructure                                                 | EVM network (not yet selected)                                                                    | See [Network & Finality](/technical/network-and-finality.md).                                                                                                       |

## Terms Optivalux does not use publicly

These implementation terms are avoided in public, owner-facing and brand-facing product explanations. They may appear on technical pages such as this one when genuinely required.

| Avoid in product copy       | Use instead                                              |
| --------------------------- | -------------------------------------------------------- |
| NFT, token                  | Product certificate                                      |
| tokenId                     | Certificate number                                       |
| mint                        | Register / issue a certificate                           |
| gas                         | (not shown)                                              |
| nonce                       | (not shown)                                              |
| controller                  | Protocol software version                                |
| EIP, ERC                    | (not shown)                                              |
| transaction hash            | (not shown; technical detail only)                       |
| attester                    | Optivalux verification service                           |
| wallet, seed phrase         | Account                                                  |
| escape, harbor, slow escape | Protection Mode, protected state                         |
| R1, R2                      | Brand-assisted recovery, Recovery Authenticator recovery |

## Internal names

Protocol source documents use an earlier internal project name in places. Public documentation always uses **Optivalux**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.optivalux.com/technical/terminology.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
