Skip to main content
Coming soon. This page describes the planned mechanism at the architecture level. Parameters - cycle timing, discount schedules, fee splits - are design decisions that publish at launch, not promises made here.

Two Ways to Settle

The platform’s settlement modes are a choice, per leg: Every settlement makes the same choice, whoever created the trade behind it. Leave it instant and it moves now, in full, exactly as quoted. Opt it into clearing and it joins the next run instead of settling alone - netted multilaterally against the whole network, so only the net difference ever moves. The saving is real for whoever opts in: a market maker quotes tighter, a desk settles a day of flow in one figure, a treasury moves the difference instead of the gross. You also pick the deadline - an hours-class tier or T+1 / T+2 - and a tier is no lock-in: need out early, a vault on the Shared Collateral Network buys your position at its published discount.
Hold, don’t move. Because your obligations net against the network’s opposing flow, you settle by adjusting net positions - your inventory stays where it already sits. No bridging a position across chains to cover an obligation, no rebalancing round-trips; only the net difference ever moves. Netting replaces the moving - capital efficiency by construction.

The Clearing Run

Obligations accumulate first: participants opt settlements from executed trades onto one shared graph - by asset and , gated by compliance policy and per-participant exposure caps. One signature records each debt and pre-approves its future collection; nothing leaves any wallet yet. Then a run takes five steps:

Freeze

One snapshot of every open obligation, locked - debts, published liquidity, and one price per asset. Everyone solves the same input, and everyone can check the same answer.

Solve

The engine hunts for loops first - debts that go round in a circle cancel with nothing moving - then clears open chains by routing a single unit of liquidity through them: value no single desk could see from its own book. Your consent and your caps are constraints inside the maths, not filters after it.

Prove

A validity proof that the answer follows the rules, checked on-chain. The chain checks the proof, not the operator - a wrong answer cannot execute.

Notice

Each participant sees one number per asset and corridor - plain arithmetic over debts it already signed. Silence accepts; the same window is the objection window. The notice says hold, don’t pay: keep enough balance for your net, and nothing more happens yet.

Commit

One transaction commits the run, and chain finality makes it irreversible before any money moves. Matched debt is extinguished by set-off - cancelled, not transferred. Then only the net movements touch the rails, and any remainder takes the first priced exit in the backstop waterfall: vault liquidity, the wholesale desk, a discount auction, or external settlement at market cost - never left waiting.
The clearing run: obligations enter the clearing engine, which nets them multilaterally per asset and corridor. Matched flow cancels on the record at bookkeeping cost with no bridge or rebalance. The residual takes the first priced exit in the backstop waterfall - vault liquidity, wholesale desk, discount auction, external settlement. Both paths converge on a net settlement that reaches the rails.

One run: obligations net multilaterally, the matched portion is extinguished on the record, and only the residual and the final net figure ever reach the rails.

Untouched Until the End

Take one obligation from birth to discharge and watch the wallet:
  • Accepted at T+0. One signature - the debt, the pull authorization, the window it may fire in. Nothing leaves.
  • Runs pass. Set-off only; no funds move. A run your policy excludes it from simply carries it forward - still nothing moves.
  • Notice. The window opens, net positions publish, silence accepts.
  • Pull. The only moment your wallet is touched - only for the residual, from sources you ranked.
  • Deadline. The tier you chose. Still unpaid after grace? The backstop ladder prices it out. Nothing lingers.
The run is final before anything moves: the commit lands on-chain first, and the physical legs - one message per chain, collection running pull-then-push per edge, all-or-nothing per unit - execute after finality, never before it.

Fund It From Anywhere

After the run, one amount is due at your deadline - one number per asset and corridor, not five separate settlements. You rank the sources once, in the app - wallet balance, a yield position redeemed at collection, an exchange balance withdrawn into the window, a bank rail last - ordered by when the money becomes pullable. One atomic pull takes the net from the first source that can pay; a failed pull is loss-free for the protocol - it reverts, severs that piece, and re-nets it next run. No margin calls, no cascade. Or settle a debt entirely your own way - a bank transfer off-protocol, an exchange ledger move - and prove it: both signatures, a custody balance change, or a receipt proven cryptographically. The record is checked and the obligation closes on the graph; the protocol only needs evidence that the debt was paid.

A Debt Only Ever Gets Smaller

Every obligation carries three numbers - signed, set off, remaining - and there is no edit path: a correction is a signed offsetting entry, so the record itself can replace bilateral confirmations. Set-off only grows; nothing reopens a cancelled amount. And every ending is one you chose, one you proved, or one that is priced: settled in a run, proven settled outside, torn up by both signatures, severed when a leg fails (surgical - one leg out, everyone else settles), or expired to the backstop at its deadline. That is the complete list. Two rules never bend: nobody cancels a debt alone, and a default hits the pair, never the pool - you can only ever lose your own position with the defaulter, not a share of someone else’s.

The Netting Premium

Settlement cost scales with the value that settles, not the value that trades - and by collapsing gross flow to its residual, netting cuts that cost by an order of magnitude, tightening every spread priced against it. Capital efficiency scales with it: clearing the residual ties up a fraction of what gross settlement needs, and capital nobody has to hold is spread nobody has to pay.

The Architecture

The clearing layer is hub-and-spoke: trades keep settling on the per-chain rails they already use, while a clearing hub sees only the legs participants opt in and nets them across the whole network.
Hub-and-spoke clearing architecture across three domains. In the origin domain, participants opt an executed trade's settlement leg into clearing at a per-chain spoke, which sends an obligation via the messaging layer to the clearing hub. Inside the hub, the clearing ledger feeds the cycle engine, which nets multilaterally and passes the residual to the backstop layer. Both the cycle engine and the backstop emit net settlements back across the messaging layer to a spoke in the settlement domain, where the participant receives one net figure.

Hub and spoke: trades keep settling on the per-chain rails they already use, while the clearing hub sees only the legs participants opt in - and the net figure can land on any domain the participant has configured.

Three records move through the clearing layer:

Obligation

Posted when a participant opts an executed settlement into clearing - the record of what is owed: asset, amount, corridor, counterparty.

Net position

What the run reduces each participant’s obligations to - one signed figure per asset and corridor, netted against the whole set at once.

Settlement

The only record that moves value - each participant’s net figure, dispatched to a settlement domain it has configured.

Flow of Funds

A settlement left instant moves now, in full, through the normal escrow path. A settlement opted into clearing posts an obligation to the hub instead of settling alone; between runs it sits as a balance on the clearing record. Each run, the engine nets every participant’s obligations multilaterally - against the whole set at once, not pair by pair - so matched flow cancels on the record with nothing moving on-chain. Only the residual, and each participant’s final net figure, ever reach the rails. Settlement isn’t tied to where the trades executed: a participant’s net figure can settle on any domain it has configured, so settlement is decoupled from routing - one settlement footprint across every chain the participant operates on.

Components

  • Clearing record. Holds each participant’s obligations and net balances, by asset and corridor - on-chain, so the record outlives any operator.
  • Clearing engine. Runs each run inside sealed hardware: nets obligations multilaterally, prices the residual, and emits net settlements - the only place the graph is ever readable.
  • Verifier. Checks each run’s validity proof on-chain before anything executes. The chain checks the proof, not the operator.
  • Backstop layer. The priced exits for the residual - vault liquidity, wholesale desk conversion, discount auction, external settlement.
  • Compliance gates. KYB, sanctions, and jurisdiction checks at membership and at every run entry - and compliance can only ever exclude a pairing, never redirect money somewhere new.
  • Spokes. The per-chain settlement endpoints where trades fill and net movements land.
  • Messaging layer. Carries obligations in and net settlements out across chains.

Keep Going

Where It Applies

One clearing layer, many kinds of debt - and why every new lane raises everyone’s ratio.

Privacy & Control

Who sees what, who you end up facing, and the lines the protocol never crosses.

Overview

The settlement-cost case and who this is for.

Shared Collateral Network

The programmable vaults that double as the clearing backstop and early exit.