Under the hood

Rexy in One Page

Rexy is a network of real people who can prove their worth and actions online. Each user can privately seal facts from their online history into proofs, on their own device: a ten-year account, a paid subscription, a funded wallet, an order history. Brands, on the other side, fund offers that name the sealed facts needed to claim them. The network verifies each match, settles the reward, and charges a fee only when a match completes.

[TK]people carrying proofs
[TK]earned by users to date

The network settles every match on-chain.

Proofs as Assets

A sealed proof is one verified fact about a person. Cryptography builds it on the person’s device, and anyone can check its truthfulness without seeing the underlying data. It works like a stamped envelope: anyone can check the stamp, but only the owner can open the letter.

One sealed proof answers one question and nothing else. A proof that an account is ten years old says nothing about what the account did, who owns it, or what it is worth.

A sealed proof is built with zkTLS. The person’s session with an app runs over TLS, the encryption behind the browser padlock. zkTLS proves one fact from that live session. The app does not take part, and the session never leaves the device. A verifier checks the proof in seconds, and the data behind it stays private.

HTTPS wraps the session in a private tunnel. zkTLS proves one fact from it without opening the tunnel.

A sealed proof carries a validity window. When the window closes, the person reseals the fact in one action.

The Proof Object

When a person seals a fact, the device produces one object:

{
  "proof_id": "proof_b3d4",
  "subject_binding": "pseudonymous commitment",
  "claim_schema": "claim/account_tenure/v2",
  "verification_method": "session_derived_proof",
  "generated_at": "...",
  "expires_at": "...",
  "purpose_binding": "offer_eligibility",  // one purpose
  "audience_binding": "brand_51",          // one verifier
  "nonce": "anti-replay value"
}

For example: one sealed proof states that an exchange account has held more than $10,000 for a full year. The person sealed it on June 3, bound it to one campaign, and it expires on September 1.

Proof Lifecycle

A proof runs through a fixed sequence, from the discovery of a fact to one of three end states. Expire, revoke, and delete are alternatives after verify, not later steps:

StageWhat happens
DiscoverThe device spots a provable fact in an app the person already uses
RequestA funded offer asks for that fact
AuthorizeThe person approves one check, scoped to purpose and window
GenerateThe device builds the sealed proof, on the device
PresentThe proof is shown to the verifier for one match
VerifyThe verifier checks the proof against the policy and returns a decision
ExpirealtThe validity window closes, and the proof no longer counts
RevokealtThe person withdraws the proof, and matching stops at once
DeletealtThe proof record is removed for good

Proof Sources

A sealed proof can come from four kinds of evidence. Every route ends in the same shape: one fact, verified, with the source data left in place.

Four evidence routes converge on one policy check and one sealed proof.

RouteEvidenceExample fact
Private accountA zkTLS proof over the person’s own session, and the app is untouchedSubscription held for six years
On-chainPublic chain state, with the wallet bound to the personWallet older than four years
PartnerA signed report from the platform itselfFunded account confirmed
IssuerA portable credential signed by a bank, employer, or universityEmployment attested by the employer

The person does not pick the route. The network sends each claim to the strongest evidence its source can produce. The person approves the proof before it exists.

A session proof has limits. It does not prove that the source data is true, or that the claim fits every offer. It proves one thing: the signed-in session stated the fact.

How a Match Works

A match is one funded offer meeting one person who can prove the fit. The path runs across three lanes: the person, Rexy, and the business.

One match crosses three lanes: the person, Rexy, and the business.

StepActorProduces
1 · Name the criteriaBusinessA funded offer that names the criteria: which facts, which sources, how fresh
2 · Find candidatesRexyA candidate set, computed on sealed proofs, with no data read
3 · AuthorizePersonOne permission, scoped to fact, purpose, and window, so silence means no
4 · VerifyRexyA structured decision, where a stale proof fails
5 · Act and confirmPerson & businessA signed completion event
6 · SettleRexyThe reward clears and the fee is charged, and every step leaves an audit event

Hard requirements pass or fail before ranking. An offer reaches only the people who qualify.

Proof = Sealed Verified Action

A verified action is the unit the network settles. One real action, by one proven person, confirmed by the person and the brand.

An action counts as verified when five conditions hold. A separate record confirms each one:

ConditionConfirmed by
The person fits the offerA sealed proof, checked against the offer’s policy
The person approved the checkAn authorization naming the purpose and the window
The action reached completionA signed confirmation from the brand
The action counts onceA duplicate check on the action’s deduplication key
Every step can be auditedAn event record written at each step, from authorization to settlement

The reward follows a state machine. Funds move only on the last step:

reserved → action_pending → verification_pending → eligible → clearing → cleared → paid

Proof Without Exposure

The network keeps one rule: the minimum sufficient fact. A zero-knowledge proof gives a brand the answer it paid for, and the data behind that answer stays on the device. One yes covers one proof, for one offer, for one window, and silence means no.

One row of the record, account age, crosses the proof policy. Every other row stays on the device.

A verification returns this object to the brand:

{
  "claim": "premium_customer_eligibility",
  "result": true,
  "valid_until": "...",
  "authorization_valid": true
}

The object carries the claim’s result and its validity window. A figure is checked against a band, so a balance clears a set size or a volume tops a set amount, and that band is the whole answer. Each brand sees a different scoped identifier, and those identifiers keep every brand’s records separate.

ControlWhat it does
ViewEvery connected source, every live authorization, and every brand that received a result, in one list
RevokeAny authorization ends and any source disconnects, at once
Export and deleteThe person takes a full copy of the record, and deletion follows where the law allows
ChallengeThe person contests a result or a reward decision, and the network reviews it

The Six Proof Checks

Every proof claim must pass six mechanical checks, and each check fails closed.

A sealed proof passes six checks before the match clears. A proof that fails a check drops out at that gate.

CheckStops
FreshnessStale proofs, because a valid proof still fails once stale
Purpose bindingReuse across offers, brands, or questions, because a proof serves one verifier, one purpose, one window
ReplayDouble-clearing inside a campaign, since every check carries a fresh challenge and a single-use presentation
RevocationWithdrawn proofs, because the person revokes and matching stops at once
Content isolationInstructions hidden in pages an agent reads, because pages are evidence and permissions stay out of their reach
Signed callbacksForged or duplicated completion events, because brand confirmations are signed, timestamped, and counted once

Every component, agent, and brand signs each action, and the network checks that signature before the action counts.

$REX: The Token

The network has one token: $REX. Its design follows one principle: as the network earns, the supply of $REX falls.

The token stays separate from the payments that move through the network. Brands invest in campaigns, while users collect their rewards as offers, discounts, exclusive experiences, or early access. Because the network charges a fee on that spending, $REX connects to the revenue at a single point: the fee on each verified action.

Primary mechanism: buyback and burn

Every verified action pays the network a fee, and a fixed part of that fee buys $REX on the open market, so every purchased token passes straight from the buyback transaction to the burn address. As a result, each burn permanently removes tokens from the supply, and each one leaves a public record that anyone can audit.

The buyback scales with usage: more verified actions generate more fees, so more revenue flows into the buyback, and the supply shrinks faster as the network grows. Because the buyback runs on revenue alone, its pace follows one number: how much the network earns.

The payment splits at settlement: the user receives the reward, and the fee buys $REX and burns it.

PointWhat happens
PayThe brand invests in a campaign, and that budget covers both the rewards and the fee
SettleA verified action clears, and the reward and the fee separate at this point
RewardThe user receives the reward the offer names: a discount, an experience, early access, or a payout
FeeA fee applies to each verified action, and the buyback draws from it
BuybackA fixed part of each fee buys $REX on the open market, where every purchase is public
BurnEvery purchased token is destroyed, so the supply falls, and the transaction stays auditable on-chain
Fee revenue reaches the token through the buyback alone, and the buyback ends in a burn. Because each burn lowers the supply, the value of each remaining $REX rises mechanically with the network’s revenue.

Fee revenue, the token purchase, and the burn repeat with every verified action, so together they form one loop:

The flywheel: brands invest to reach verified people, fees buy $REX, the tokens burn, and a scarcer $REX strengthens the reason to hold it.

Secondary mechanisms

The fee buyback is the core mechanism. Everything below is secondary: one utility for holders, and two optional add-ons that build on top of the buyback.

Priority access

Holding $REX unlocks one benefit: priority access. When a funded offer has more qualified users than places, holders enter first.

A sealed proof decides who qualifies, so priority access orders only the queue of users who already qualify, and no amount of $REX replaces a proof. Holders therefore enter sooner, while a user who holds none keeps full access to every offer that fits their proofs.

Sealing seasons

A sealing season is a time-boxed proof drive, run as an optional growth add-on. Rexy names one proof, sets a public goal, and funds the rewards itself, before any brand pays for that proof. Each user who seals the proof carries one more proof, and each new proof opens more offers for that user.

When the network reaches the goal, Rexy burns a set amount of $REX from its own reserve. The amount is announced with the goal, and it is capped. Because the burned tokens come from Rexy’s reserve, the users who seal the proof trigger the burn while the tokens stay out of circulation, so a season adds growth with zero selling pressure.

Rail settlement

Rail settlement is an optional volume add-on that lives one layer down: beneath Rexy runs Regis, the rail where agents settle with agents. When one agent pays another to reach a verified person, the payment carries a fee, and that fee follows the same path as the marketplace fee: a token purchase, then a burn. More agent traffic therefore means more fees, and more fees mean more burn.

Supply

The supply of $REX is fixed at genesis, and burns are the only events that change it, so the total can only fall, one burn at a time.

[TK · total supply at genesis]

[TK · allocation: users, team, reserve]

[TK · unlock schedule per allocation]

Glossary

Sealed proofOne verified fact, built on a person’s device, checkable as true without the data behind it.
Zero-knowledgeA way to prove a statement is true without revealing the data that makes it true. A proof shares the answer, never the record behind it.
TLSTransport Layer Security: the encryption behind the browser padlock that protects data between a device and a website.
zkTLSZero-knowledge TLS: a method that proves one fact from a live, encrypted web session, without revealing the session data and without the website taking part.
ClaimThe plain statement a proof supports: an account older than ten years, a volume above a set amount.
Proof sourceThe place a fact lives: a bank, a subscription, a wallet, a platform account.
OfferA funded proposal from a brand: the facts that qualify, the action to take, the reward.
MatchOne offer meeting one person who can prove the fit.
Verified actionThe unit the network settles: a completed action by a proven person, confirmed and auditable.
SettlementThe on-chain step where the reward clears and the fee is charged.
AuthorizationThe person’s permission for one check: which fact, which purpose, how long.
CampaignA budgeted set of offers with a start, an end, and completion rules.
RegisThe settlement rail beneath Rexy. It verifies matches and clears rewards on-chain.
$REXThe network’s token. A fixed part of each fee buys $REX on the open market and burns it, while users receive their rewards separately.
BuybackThe open-market purchase of $REX, funded by a fixed part of each fee. Every purchased token is burned.
BurnThe destruction of tokens. A burned token leaves the supply and never returns.
Priority accessThe holder’s benefit: first entry into offers with limited places, among users who already qualify.
Sealing seasonA proof drive with a public goal, funded by Rexy. Reaching the goal triggers a capped burn from Rexy’s own reserve.