Platform architecture

Evidence decides.
AI explains.

Most security tools return a score. XemaS returns the evidence that produced it, the reasoning model behind it, and an explicit statement of what could not be assessed. Every finding is traceable from blockchain to human decision.

Context

Four approaches to Web3 security

Each approach has a genuine strength. Understanding the limits of each is what the evidence-first layer adds.

Token scanners

Fast risk indicators from aggregated APIs

A score without provenance cannot be explained or audited. When a finding is wrong, there is no trace to follow.

Static analyzers

Code-level vulnerability detection before deployment

Designed for pre-deployment review, not continuous monitoring. Does not assess ownership state, liquidity risk, or behavioral history.

Runtime monitors

Real-time exploit detection at the transaction level

Reactive by design - observes exploits after they begin. Not built for pre-exposure due diligence or compliance evidence.

Compliance platforms

Entity tracing and AML investigation workflows

Strong on attribution; typically thin on contract security, behavioral scoring, and real-time market intelligence.

XemaS - Evidence-first intelligence

Pre-exposure due diligence + compliance evidence + institutional market context - one traceable finding

XemaS does not replace specialized tools. A runtime monitor, a code auditor, and an AML platform each do things XemaS does not. What XemaS provides is the unified evidence layer that connects the question ("should I interact with this?") to the verified on-chain facts that answer it. Every conclusion shows what was checked, what was not, and how confident the assessment is.

Principles

What evidence-first means in practice

Traceable

Every finding links back to the specific on-chain data that produced it. When a verdict is wrong, the evidence chain shows exactly where - and allows it to be corrected. A score without provenance is a black box.

Honest about limits

The platform records what it could not assess alongside what it did. A finding at 40% certainty shows the coverage gap - not a confident-looking number that obscures it. Unknowns remain unknown.

Evidence decides. AI explains.

AI reads the verified evidence model and explains the verdict in plain language. It does not generate the verdict. The risk model runs on verified evidence; the AI runs on the risk model. The order matters.

Architecture

From blockchain to human decision

Every finding passes through each layer in order. Nothing skips a step. Every step is recorded.

Blockchain

The ground truth

Every claim traces back to an on-chain state or transaction. Not an API. Not an aggregator. The chain itself.

Evidence Collection

What did we observe?

Four independent channels: direct RPC queries, static analysis, ML behavioral signals, entity intelligence.

Canonical Facts

What does each observation mean?

Raw signals normalized into one authoritative record per fact. Correlated sources are merged, not double-counted.

Evidence Verification

Do independent sources agree?

Independence check, provenance recording, recency weighting. Sources that share an upstream are treated as correlated, not confirming.

Coverage State

How much was assessed?

Every finding carries a coverage state: VERIFIED, PARTIAL, UNVERIFIED, UNKNOWN, or CONFLICTED. Gaps are made explicit, not hidden.

Conflict Resolution

What happens when sources disagree?

Conservative default applies. CONFLICTED state is surfaced, not averaged. The disagreement itself becomes the finding.

Risk Model

What is the security consequence?

Score derived from verified evidence. Confidence reflects depth of evidence, not optimism.

AI Explanation

How should a human interpret it?

AI reads the verified evidence model. It does not generate the verdict - it explains what the evidence already determined.

Human Decision

Informed, not replaced

Evidence supports judgment. XemaS does not make decisions for you. It removes blind spots so the decision you make is better-informed.

Scope

What XemaS is not

An honest positioning requires naming the limits alongside the strengths.

Not a code auditor

A formal code audit involves manual review, adversarial testing, and a signed report. XemaS automates evidence collection and risk scoring at scale - it is not a substitute for a code audit on a critical deployment.

Not a runtime exploit detector

Runtime monitors watch individual transactions as they propagate and can halt or alert on exploits in flight. XemaS scans state and history - it surfaces structural risk before an event, not mid-transaction.

Not a legal determination

XemaS characterizes on-chain evidence: what was observed, what patterns are present, what the on-chain behavior looks like. It does not make legal determinations and does not substitute for legal counsel or a licensed compliance function.

Try it

Scan any token, wallet, or contract

Every scan returns the evidence chain, coverage states, and confidence levels. Not just a score.