Skip navigation
XChain Docs

3 · Architecture

Last updated: 08/06/20264 min read

This section describes the same system three times, at increasing resolution: first the invariant boundary (2 Domains), then the functional split (3 Layers), then the fine grain (5 Tiers). Each pass adds detail; none replaces the previous. A reader who stops after the Domains still has the law of the system; the Layers and Tiers are two zoom levels of the same picture — not separate technology stacks.

TermCountWhat it is
Domain2The invariant security boundary: value-bearing data / value-free data.
Layer3The functional split: Settlement · Execution · Data.
Tier5The fine grain T0–T4: cryptographic assurance + storage policy matched to data value.

Relationship: 2 Domains → 3 Layers → 5 Tiers (increasing resolution). "Domain" is the law; "Layer" and "Tier" are two views of the same system at two resolutions.

Pass one — 2 Domains: the binary question (invariant)

Every piece of data answers one question:

Does this data need double-spend protection or composability?

  • Yes → the value Domain: it must live on a consensus chain.
  • No → the data Domain: high-volume, low-value events (likes, views, chat, IoT logs) that only need an immutable record, no per-record consensus.

The UAC (Universal Asset Commitment) primitive enforces this boundary: the data Domain is structurally forbidden from holding value. This is a test-checked invariant, not a loose convention. The two Domains are the foundation — the number of Layers or Tiers underneath can be presented differently, but the Domains are always two.

Pass two — 3 Layers: the functional split

Inside the value Domain, one slice of data is different in kind from the rest: it does not execute everyday transactions but finalizes and aggregates proofs for all of them. Separating that slice gives three Layers — matching the industry-standard mental model Settlement / Execution / Data:

LayerDomainRoleVolume*
① SettlementvalueCross-region finality, aggregate & verify ZK proofs (PAI), root of trust (SC).< 0.01%
② ExecutionvaluePrevent double-spend, keep state consistent, composability across chains.~10%
③ Data (Availability)dataNamespaced append-only logs: tamper-evident + timestamp + inclusion-provable. No per-record consensus.~90%

*Design estimates by expected data mix — not point-in-time operational figures.

Layers ① and ② both sit in the value Domain (consensus chains: Cosmos SDK + CometBFT + IBC); Layer ③ is the data Domain. Splitting ① from ② is a functional distinction: Settlement is where proofs are aggregated and value is finalized — different in kind from Execution, where transactions run.

Pass three — 5 Tiers: the fine grain (T0–T4)

Look closer and the three Layers spread into five Tiers. Each Tier has cryptographic assurance and a storage (DA) policy matched to the value of the data, not its speed:

LayerTierFunctionDA storageVolume*
① SettlementT0 · RootFinal settlement, ZK proofPermanent< 0.01%
② ExecutionT1 · ValueDouble-spend protectionLong-lived~1%
② ExecutionT2 · InteractiveState consistencyMedium-term~9%
③ DataT3 · EventsTamper-evidence, timestampPrune ~weekly~85%
③ DataT4 · EdgeAttestation at checkpointEphemeral~5%

*Design estimates.

The core idea: tiering makes large-scale economics feasible by concentrating the expensive cryptographic guarantees on the data that truly carries value — instead of a monolithic chain paying consensus prices even for "likes".

XChain throughput pyramidWidth = throughput capacity (cheapness per op) · apex = root of trustSETTLEMENTEXECUTIONDATAvalue Domainvalue Domaindata DomainT0 · RootT1 · ValueBFT finality · ~10³–10⁴ TPS/chainT2 · Interactivestate consistency · ~10⁴ TPS/chain— 2-Domain boundary · enforced by UAC —T3 · Eventsappend log (VLC) · ~10⁶⁺ ops/sT4 · Edgebatched attestation at checkpoint · ~10⁶⁺ ops/sverify, don't re-executeData → Execution~10⁶ events → 1 commitment(VLC); the chain only verifies.Execution → Settlementcompress chains' activity into1 proof (PAI).At T0 · Root1 pairing verifies ~10⁶–10⁸ tx;root cost ~constant (SC).Figures are design ceilings (nominal), not measurements. Consensus-final TPS is orders of magnitude lower — see Network Status.
Figure 3 — Most "transactions" never touch consensus (Data Layer); value is sharded in parallel (Execution); the apex only verifies proofs (Settlement).

How the Layers connect: "verify, don't re-execute"

The principle joining the Domains is verify, don't re-execute:

  • Data → Execution/Settlement: data committed on the Data Layer is retrievable/sampleable per the Tier's policy (DA Interface). The consensus chains do not re-run that volume — they only verify an inclusion/availability proof when a single event needs to be anchored into the value Domain.
  • Execution → Settlement: the value chains do not push their whole state to the Root. They compress it into proofs; the Settlement Layer aggregates and verifies (PAI) then finalizes (SC). The Root only verifies — one pairing on a small proof — never re-executing the child chains' transactions.

So the cost at the root of trust stays nearly constant no matter how much the edge volume (Tiers T3/T4) grows. The concrete testnet realization of this — three consensus chains plus namespaces on a DA node — and its live numbers are in Status & Live Network.

Takeaway: the architecture settles where data lives. What it has not yet said is how chains talk across these boundaries — and that interaction, not raw speed, is where multi-chain systems usually break. The cross-chain model is next.