Continuity
When Outside Services Are Unavailable
A community, resort, campus, or co-working facility may still have people, staff, devices, local power, and a local network even when outside services are slow or unavailable. A payment provider may be unavailable. A booking or access system may be offline. A registry, health-record system, or cloud application may be temporarily inaccessible. The community still needs to coordinate the work in front of it.
The people, funds, and records have not disappeared. The paths used to reach them have. Mainstay provides a local point of continuity: keeping nearby records and payment capabilities understandable and usable, supporting community coordination, and reconciling with external systems when connectivity returns.
That distinction is architectural. Service npubs, wallet npubs, Clear
keyset IDs, and Grove content hashes can remain stable while their reachable
paths change. Mainstay resolves an eligible path for the current context rather
than treating a Docker name, domain, or public IP address as the durable
identity. Losing one path therefore does not require losing or renaming the
thing it reached.
Continuity means that keys, records, and value remain usable when external conditions change. It does not mean pretending every action has the same level of finality.
Availability is the outcome
Mainstay uses availability in the established security sense: authorized people can obtain and use the service, information, or value they need when they need it. Availability sits alongside confidentiality and integrity; local operation should preserve all three rather than trading privacy or correctness for access.
Reachability is the narrower network question of whether one endpoint can be reached from the current location. It is one input to availability, not a synonym for it. A reachable service may be unhealthy or unable to complete a request, while a service can remain available through another eligible route when one path is interrupted.
Four operating modes
| Mode | Meaning |
|---|---|
| Connected Mode | Hosted services, public relays, external mints, synchronization, and updates are available. |
| Local Mode | The user reaches local and nearby Mainstay services directly without depending on upstream internet. |
| Mobile Mode | A phone or nearby device supplies temporary upstream connectivity while local services remain primary. |
| Community Mode | Participating Mainstay instances exchange signed events, encrypted records, and value across a local network or mesh. A Lockbox can host one of those instances. |
The same user app works across all four. A mode change alters availability and finality messaging without forcing people into an unfamiliar emergency interface.
Good boundaries, not barriers
Continuity requires clear boundaries because different components fail in different ways and answer to different authorities. A relay can preserve an event but cannot declare an ecash proof spendable. Mainstay can preserve and present a record but does not become its institutional authority. A local service can keep operating without pretending that an unavailable external service has confirmed anything.
These boundaries contain failures, preserve honest status, and make each component independently replaceable. They must not become barriers. Open protocols allow signed events, encrypted records, proofs, and control evidence to move or synchronize across compatible local and remote infrastructure. Continuity comes from maintaining those connections without erasing the meaning of the boundaries they cross.
Records and evidence
Spurline preserves relevant Nostr events locally. Grove preserves encrypted blobs. Acorn retains portable keys, records, and recovery material. When a network path returns, local activity can synchronize outward without losing its original signatures or evidence trail.
Two payment continuity paths
Mainstay must distinguish two different situations.
External mint unavailable
Acorns can transfer previously issued ecash locally when an external Cashu mint or Lightning path is unavailable. The receiver preserves the proofs as pending until the mint can confirm, refresh, or reject them.
Local transfer accepted
Mint finality pending
Reconciliation required when connected
If exact change cannot be made without the mint, the app shows the closest available amounts and asks for explicit approval.
Local Clear mint available
A Clear mint on the local network can validate, swap, issue, and retire its own currency without Bitcoin, Lightning, or global internet access. That provides mint-level finality for that bounded currency while the local mint remains available.
This is useful for resorts, ships, campuses, remote communities, food-bank networks, and shared facilities that retain a local network during an upstream outage.
Honest status is a feature
Mainstay makes three signals obvious:
- confirmed value has finality from the relevant mint;
- pending value is preserved but still needs finalization; and
- local availability explains which services can currently be used.
The product promise is not uninterrupted access to every external dependency. It is continuity without ambiguity.