Skip to main content
Every workspace gets its own on-chain router: an immutable contract deployed for you, owned by you. Trades enter through it, flow through shared immutable venue modules, and settle delivery-versus-payment through a compliance-gated escrow: the counterparty delivers, or you are refunded. TetraFi holds no custody key and no upgrade key anywhere in the stack.

The Contract Stack

Never send funds directly to a settlement address. Value moves only through a signed order’s flow; preflight nextActions say what to sign and where funds travel.
Your router’s address is deterministic, predicted before deployment, and yours permanently. Module and escrow addresses vary by chain and version. Never hardcode any of them: the addresses in quote responses and preflight plans are authoritative.

Settlement Lifecycle

Every quote carries its own EIP-712 escrow-v0 payload. Your signature authorizes it, your router locks the input into escrow on those terms, and only a delivery proof moves the funds onward. If the expiry passes without a delivery proof, the escrow refunds your input through a path that is permissionless and unpausable. There is never a half-settled state.

Where the Next Layers Plug In

Coming soon. Multilateral Netting and the Shared Collateral Network are in design.
A settlement opted into clearing posts an obligation, and only the net residual later takes the escrow path above. A vault draw funds a fill or settlement leg through the same opener and escrow, whose release repays the vault. Integration shapes: netting, shared collateral.

Rolling Out on the Rails

  • Bonded firm quotes - a proven no-show refunds you; the bond is slashed only on positive evidence
  • A governed compliance plane - a delayed main lane and an instant emergency lane
  • Per-corridor settlement oracles
  • An add-only module catalogue - a refund is bound to the version that opened the trade
  • The same escrow model on Solana and Tron

Funding Locks

Preflight selects the lock for the corridor and token; Token Approvals covers the check-and-approve flow.

Signed Payloads

Each quote carries its complete typed payload in quote.order: for escrow-v0, the StandardOrder typed data. Sign exactly what the quote returns; the integrityChecksum binds your submission to the quote shown, so any mutation is rejected. Signing flows: RFQ Order Submission guide, Router API quickstart.