Permissioned validators, access control, and confidential payloads. Not everyone can read or write. That is deliberate — commercial and operational data should not be fully public by default.
Cryptographic commitments (for example state roots) are posted to a public chain. Outsiders can verify that an anchor exists and matches expected structure; they do not automatically receive private transaction contents.
No system is “unhackable.” Relayers, key custody, validator sets, and client software remain attack surfaces. Security maturity tracks implementation, review, and operations — not marketing slogans.