Skip to content

terminode.xyz

A product surface for spatial truth, not just map display.

TermiNode turns governed datasets, versioned features, bounded queries, oracle proof workflows, and export evidence into a live DApp.

TermiNode live map with bounded spatial records, version context, proof receipt, and evidence export controls.
Live product surface on terminode.io: bounded map reads, feature history, proof context, and portable evidence.

Core workflow

Publish, query, verify, export

Create datasets, ingest spatial features, inspect current geometry, compare versions, verify high-value coordinates, and archive evidence packages.

Dataset catalog

Dataset records group one GIS collection or product layer with visibility and policy controls.

Feature history

Each feature carries current geometry and version context for audit review.

Evidence package

Snapshots and proof receipts can be copied or exported for review.

Organization access

Fund the workspace, not every operator wallet

The local release candidate adds bounded organization-sponsored writes beside personal prepaid credits. A sponsor funds one workspace while importers remain identifiable through RBAC and per-member usage.

Bounded budget

Total spend, per-member spend, optional expiry, active state, and remaining balance are enforced by the spatial canister.

Tokenless importer

An authorized importer can write a linked dataset without receiving TRMG or managing a ledger approval.

Fail-closed controls

Revoked, expired, archived, over-limit, or unauthorized delegated writes stop before feature state changes.

Repeatable delivery

Synchronize source records without duplicating spatial history

The local release candidate binds a stable source-system key to one TermiNode feature. Expected revisions stop stale jobs, while exact retries return a no-op instead of another feature version or write charge.

Source binding

Source system, layer, and feature ID identify one upstream GIS record inside a governed dataset.

Conflict protection

A changed payload must name the currently accepted revision before it can create a new spatial version.

Reconciliation evidence

Bounded batch reports expose created, updated, no-op, archived, conflicted, and failed entries with a deterministic checksum.

Controlled decisions

Accept one exact feature version and preserve every prior decision

The local release candidate separates importer, reviewer, and approver responsibilities. Each decision binds an exact geometry version to actors, timestamps, safe evidence references, and a checksum-backed report.

Exact-version scope

A decision names one feature and version, so a later geometry update cannot silently inherit an older approval.

Role separation

Review and approval are distinct canister-enforced transitions with owner and controller recovery paths.

Durable supersession

A newer accepted version becomes current while the former accepted record remains readable as Superseded.

Operations

Production discipline is part of the product

Launch evidence, controller drift checks, metrics snapshots, hardened asset headers, and domain smoke tests reduce operational guesswork.

ICP hosting

The canonical DApp is served from the `frontend_assets` canister.

Config guardrails

Production env checks prevent incomplete frontend configuration from shipping silently.

Controlled market boundary

Internal market, fiat, custody, and exchange-like surfaces remain outside the default launch.