# The Citrate Constitution

Version 2.0. Adopted September 2026. Version 1.0 and every change since are kept in the repository, each with a date and a reason.

---

## Preamble

Most of the compute that trains the models people use sits in a few enormous buildings, owned by a few companies, paid for with data the rest of us hand over in exchange for a chat window. That arrangement is efficient, and it is fragile, and it concentrates something that ought to be spread out. We started Citrate to spread it out.

The network runs on machines people already own: a laptop in a house, a rack in a school, a small cluster in a hospital wing. It treats a modest node and a tiny data center as real infrastructure, not as a rounding error next to a hyperscaler. The point is not to build one more giant. The point is to make ten thousand small, well-run nodes add up to something a giant cannot match: compute that stays close to the people who own it, pays them for the work it does, and can be checked by anyone.

This document records what that commits us to. It is written to be held against us. A member, a regulator, or a critic should be able to read a sentence here and check whether we kept it. One rule sits above the rest.

> We are stewards of software. We are not owners of your data.

That line decides the hard calls. It appears again in the economics, in the architecture, and in how we treat a classroom and a defense prime alike. If our conduct ever contradicts it, the line wins and the conduct is the error.

---

## Article 1 · What the network is

Citrate is a network for AI work that runs on machines its members own. You download one application and your computer becomes a full node: the chain, a local model, encrypted messaging, your files, and your keys, all on your device. The network settles work on a public ledger, chain 40204. The software is open source.

We build for distribution on purpose. AI infrastructure does not have to mean one more warehouse of accelerators drawing the power of a small city. It can mean compute placed where people already are, at a scale they can actually run and afford: a single node, a grove of a dozen, a small on-premises cluster that a district or a business stands up on hardware it already maintains. We treat scaling down as seriously as scaling up. Making a tiny data center easy to run well, and worth running, is a design goal, not a courtesy. The social and economic case is the same as the technical one: keep the compute, the data, and the pay in the hands of the people and places doing the work.

Members form groves. A grove is a small group with a real goal, pooling its machines for storage, training, inference, or apps, and sharing what the grove earns for the work it actually does. An organization is a grove. A school is a grove. The same network serves the enterprise and the classroom, because underneath, the work and the proof are the same.

---

## Article 2 · Who owns what

A member owns their keys, their data, their models, and their node. Nothing in the network can move a member's funds or sign on a member's behalf without that member's approval, given on their own device. Citrate Inc. does not hold member keys, and the system is built so it cannot see what a member computes.

We steward the software, the design, and the integrity of the public ledger. We never own the content of your work: what your models learn, what your workloads contain, what your people produce. When an engineer here chooses between an architecture that would let us see customer activity and one that keeps us blind, the blind one wins, even when it is harder to build. That is the constraint we accept in exchange for being trusted with a hospital's floor and a child's schoolwork.

---

## Article 3 · What members are owed

Every settled job leaves a receipt, exportable, that a third party can check. Members are owed notice of any change to how reward is calculated before it takes effect. Every capability the network claims carries a published status and a date, and where a feature is not yet live, the member sees an honest empty state rather than a promise dressed as a fact. A member signs in on any machine with their wallet and their groves are waiting. Membership follows the person, not the hardware.

---

## Article 4 · How reward works

Reward is paid for verified work. Groves are scored by a formula in which work is linear and dominant, and headcount and capital have diminishing returns. Effort beats size, and effort beats capital. Work a member does only for themselves counts as nothing. A free identity can take part, earns nothing, and dilutes no one. No one is paid for recruiting a person who does not contribute. The parameters are published and simulated against fairness rules before they change, and the simulator and its invariants are kept in the open.

---

## Article 5 · The token

SALT is the network's unit of stake and settlement. It meters compute and settles work. It is not a product to hold. SALT has no cash value until mainnet, which is targeted for the second quarter of 2027, and testnet balances may be reset before then. Citrate Inc. will not describe SALT as an investment, and the company is structured so its revenue comes from software, a small fee on real compute changing hands, and services, not from the price of the token. We will not promise cash earnings we cannot yet deliver, and we will not promise more than the market clears.

---

## Article 6 · What Citrate will not do

We will not train on a member's data without that member's explicit, revocable grant. We will not read group messages; the relay carries ciphertext only, and we cannot decrypt it. We will not publish who invited whom. We will not promise a service to any group for free in order to win it, and we will not claim a certification the network does not hold. We will not let a deadline override a serious security finding. Each of these costs us something, and we pay it on purpose.

---

## Article 7 · Verification over trust

Every claim the network makes about itself is either reproducible from source or carries a status and a date. Where a claim cannot be reproduced, it is withdrawn. We state, module by module, what is audited, what is pre-audit, and what is specified but not yet built. We use plain language with people who did not ask for jargon, cite the source, and state the conservative number. Scrutiny is something we design for, not something we defend against.

---

## Article 8 · Amendment

This Constitution changes only by a published proposal, a public comment period of at least thirty days, and a recorded vote of the governing body named in the repository. Every version is kept, with the date it took effect and the reason it changed. When a future decision conflicts with a sentence written here, one of two things is true: the decision is wrong, or the sentence needs to change in the open, with a reason, on the record. We will not let a contradiction stand in silence. A constitution that is quietly ignored teaches the team that the words mean nothing. These words mean something.

> We are stewards of software. We are not owners of your data.

---

Citrate Inc. · Carpinteria, California · Version 2.0 · September 2026
