Join a committee: send the numbers only you hold, once a day, from a program on your side, for $0.

A committee is the handful of firms whose data makes one asset’s daily price. You already hold a position in the asset — you trade it, lend against it, issue it, hold it or keep its register — so you already have the numbers we ask for. A small program on your own servers reads them from your systems and submits them, signed, every day. The venues’ trades set the price, a lender checks it against its own mark, and the issuer can stop it while the peg is in doubt. You never send your order book, your trade tape or client data, and you are never charged.

Status. No fixing has been published for commercial use and no seat is held by a third party. The only committees on the ledger are ones whose seats ETP Foundry operates itself (including the test seat used to prove L2), and every value they attest says so on its face. A seat operated by ETP Foundry or its affiliates never counts toward K, whatever its trust level (Methodology §6.4 condition 3). What follows is Methodology v1.0 and Signer Protocol v4 (28 September 2026), implemented and unit-tested in the desk; the live desk serves v4 once that release is deployed. Methodology v1.0 is the sole governing methodology; the Rulebook v0.2 describes process only where it is consistent with it, and where any text differs, Methodology v1.0 governs.

What we ask you

One submission a day: numbers from your own systems, about your own records.

Nobody is asked whether the price is “right”, and nobody votes. Each seat submits a few numbers only it holds. The desk computes the price from the venues’ numbers and checks it against everyone else’s. A number outside its rule is recorded as that seat’s refusal, with the numbers, and the value does not publish on it.

Your seatEach day, you submitRead fromWhat it does to the price
Venue
the asset trades on you
  • Your trades in the hour before the strike: how many, the total volume, their VWAP, and the lowest and highest price.
  • How many seconds of that hour trading was halted.
  • That the figures exclude self-matched and affiliate trades (selfTradesExcluded, required).
  • Nothing traded? Your average best bid and ask over the hour instead, and how long you quoted both sides.
Your trade database and your halt log Sets it. The fixing is the volume-weighted median of the venues’ VWAPs.
Lender
you take it as collateral
  • Your own mark for the asset, and when your system produced it.
  • Whether you accept it as collateral today, and the haircut you apply.
  • How the mark is made (markSource), and whether it comes from a public reference price (markFromPublicReference, required).
Your risk or collateral system and your haircut table Challenges it from the risk side. It publishes only within your declared tolerance of your mark (25 bp by default), a check modelled on independent price verification. If your mark comes from a public reference price, it is a basis check, and the fixing says so.
Issuer
you issue the token
  • Your reserves and your token supply, as of a stated time.
  • Where the evidence is: your proof-of-reserve report or reserve addresses, the contract and block you read, or the custodian’s statement.
  • Whether redemptions are open, and whether minting or burning is paused.
Your reserve attestation, your registry and your redemption desk Gates it, never sets it. A peg-integrity gate: nothing publishes while reserves are short or redemptions are shut.
Custodian
you hold a fund’s assets
  • The units you hold for the fund, the units the ledger says it holds, any units pledged or lent, and your statement time.
Your custody statement and pledge register Gates the fund’s NAV: holdings must match, with nothing encumbered.
Transfer agent
you keep a fund’s register
  • The shares on your register, the shares on the ledger, and the register time.
Your share register Gates the fund’s NAV: the two share counts must match.

A venue that did not trade reports zero trades (and its quotes, if it quoted): that is recorded, and the price falls to the next input level, labelled. The exact field names, units and rules are in the five seats, in full below and in methodology §4. A printable one-page brief per seat: venue · lender · issuer · custodian · transfer agent. The whole ask, one page per seat, with what is public and what only you provide: What we ask committee members (v2).

Schedule at a glance: three layers, 24/7

A tokenised stock such as SPYx trades around the clock, but the NYSE is open about 32.5 of the 168 hours in a week, and a lender still needs a number at 02:00 on a Sunday. Every value ETP Foundry publishes carries one of three labels (methodology §3A.0):

LayerWhenWho stands behind itUse it forNever use it forStatus
1. LIVE indicativeContinuousNobody: tier 0, unsigned. Venue dispersion shown, no bandScreens, monitoringAnything contractualnot published: no licensed source (exchange prices are never shown)
2. OFF-HOURS SIGNED fixing00:00, 08:00 and 16:00 UTC, every day, weekends and holidays includedK of N seats, signing automatically, at least one of them a venue, with a published data-quality band (± b; uncalibrated until back-tested)Margin, liquidation, health factors, collateral haircuts, once attested; until then tier 0, labelled pilot — not attested, and not for liquidationNAV, creation, redemption, fund reportingspecified, not built
3. OFFICIAL fixingOnce a day. Crypto: 16:00 London, adopted 28 Sep 2026 (why). Any equity, and any basket with an equity leg: 16:00 New York on NYSE trading daysK of N seats and every gate; published with its tier and input levelNAV, creation and redemption, reporting—built for wrapped crypto and funds on DevNet; equities planned

If fewer than two live inputs of distinct signal types remain (token trades on any number of venues count as one), nothing is guessed: the result is NO FIXING, and the last good value stays visible with its age. A move of more than 10% since the previous value is published and flagged EXCEPTIONAL, never suppressed; that is the word’s only meaning. Nobody may present an off-hours or indicative value as a NAV, and the licence says so. What it means for your seat: today, one submission a day. On a tokenised-stock committee, once the off-hours layer is built, your checker also submits at 00:00, 08:00 and 16:00 UTC by itself: venues describe the 15 minutes before the fixing time, a lender’s mark may be at most 15 minutes old and is checked against the off-hours tolerance the lender declared in advance (never widened by the band), and the cut-off is the fixing time + 10 minutes. If K seats have not signed by + 30 minutes, the result is NO FIXING. No person at your firm is needed per fixing (§3A.6).

You send numbers, never your books.

Your order book, your individual trades, your client identities and positions, your wallet keys and your statements stay on your systems. The checker sends only the aggregate numbers listed for your seat. What you send is recorded on the fixing record with a SHA-256 digest, visible to the committee and its auditor, and not otherwise published: the price is public, and per-seat figures are published only with that seat’s consent. That is enforced by Canton’s signatory model, not by an API filter.

Why this is not rubber-stamping. Every submission is a number that can be wrong in a checkable way: a VWAP must sit inside its own low and high, a venue’s range must contain the value it signs (the ledger refuses otherwise), a lender’s mark must fall within a tolerance it declared in advance, and an issuer’s reserves must cover supply at a stated time. The seats check each other in opposed directions, disagreement is recorded with the numbers rather than averaged away, and ETP Foundry cannot sign. The full argument, and what it does not solve.

How it’s automated

A checker on your side does the daily work. Nobody at your firm has to.

Hosted, your cloud, or your server

The checker (signer-service) is a small program we supply, with a ready-made configuration for every seat. We can host it for you (nothing to install), or you run it in your own cloud or on your own server (below).

Reads your systems

Each number comes from a source you declare: an HTTP endpoint or a command against your own systems. It never reads the proposed price to build your numbers.

Submits by itself

It builds your submission and sends it; the desk applies your seat’s rule and records a pass, or a refusal with the numbers. A source it cannot read: it stops and sends nothing. It never widens your tolerances.

Tells you, so you don’t have to watch

A signed webhook reaches the checker the moment a proposal is waiting, and e-mail notices tell your team when one is waiting, about to expire unsigned, or missed.

Your own key (L2)

An Ed25519 key only you control, in your own cloud KMS or generated on your server; only its public half leaves your control. From then on your key signs for your seat; we cannot sign for it through the Ledger API. We can still refuse or delay your submission, and a participant running modified software is the one remaining path, which L3 closes. L2 is built and was proven on DevNet on 26 Sep 2026. It is switched off on the running desk today, and will be on before the first seat onboards.

API and MCP

Everything the portal does is on the API, under a key scoped to your seat. An AI agent can connect to etpfoundry.com/mcp under the same key and role. The MCP tools and the in-console assistant are for signed-in users only and are labelled internal; neither relays an exchange price.

How you run it: hosted, own cloud, or self-run

You choose where your checker runs. You can start hosted and move later; the seat stays the same.

Hosted by ETP Foundry (default)Own cloud, one clickSelf-run (advanced)
Your effortDone in the dashboard: sign in, connect your data, and confirm daily. No install, no servers, no Docker. Your own legal and compliance review will take longer, and we go at your paceA developer deploys our ready template into your own Google Cloud (Cloud Run) or AWS (ECS Fargate) account, once your cloud and security teams approve it. It restarts itself; a second, standby instance is optionalOur Docker image on your own server
Your dataIssuers often connect nothing: we read your public reserve proof or on-chain reserves, and you set two status toggles (redemptions open, mint/burn paused). Venues and lenders paste a read-only API link or keyRead inside your own cloud accountRead on your own server
SigningL1 (we sign for your seat, disclosed on every value), or your own Google Cloud KMS key (one-click permission; the key never leaves your vault)Your Ed25519 key in your own KMS (Google Cloud KMS or AWS KMS)Your Ed25519 key, generated on your server
Counts asOperator-run: tier 0 (not attested), even with your own key, because we fetch the inputs. Ideal for the pilotCounts toward tier 1Counts toward tier 1

In every mode: a readiness alert 15 minutes before the 16:00 London strike (by webhook, and by e-mail once e-mail notices are on), live status in the dashboard, and manual submission in the dashboard as a last resort. A missed strike is not fatal: three unexplained misses in a row trigger a review. Stated plainly: hosted and own-cloud modes are built and live on the desk since 29 Sep 2026. No third-party member has run either yet. Level 2 own-key signing stays switched off on the running desk until the ledger JSON API is opened to it. Members’ read-only data credentials are encrypted (AES-256-GCM); the encryption key is held in Google Secret Manager, not in the code or on disk. The cloud templates have not yet been applied in a member’s account. Tier 1 also needs the other §6.4 conditions, so today every value is tier 0 whatever the mode.

Prefer to do it by hand? One submission a day in the portal, with your numbers, does the same. The engineer’s version is below.

What’s in it for you

What you get, and what happens if you say no.

SeatWhat you getIf you decline the seat
Issuer Your token becomes something funds can hold and lenders can mark against. Every fund that holds it reuses your signature. Other seats may still cover the asset, but nobody attests that it can be redeemed — and lenders and funds see that.
Venue Your own trades would anchor the fixing once two independent venues submit, and the ledger refuses a price outside your reported range. Settling your products against it is free while you hold the seat. The price is anchored by other venues. Settling your products against it without a seat is licensed separately, on request.
Lender Nothing publishes outside the tolerance you declared around your own mark, and every refusal is on the record with both numbers. Your firm is named on the committee of record. You can still use the price under a separate licence, on request, or not use it.
Custodian Your statement becomes the proof investors rely on, without being published. You are part of every fund that holds the asset. For an asset held off the ledger, a custodian seat is mandatory: without one, it cannot be fixed.
Transfer agent You keep your appointment and your register. Your daily reconciliation becomes part of the signed NAV. The fund keeps its own register, and that seat is disclosed as issuer-controlled.

Cost: $0

Members are never charged and never paid. Fund and ETP issuers take the licence. That licence has a component linked to funds’ assets under management: a conflict of the administrator, disclosed in methodology §9.

Saying no on a given day

Your submission is recorded as a refusal, with the numbers that failed their rule. Below K signatures there is no price that day: a gap is published as a gap. A refusal that shows its numbers is the system working, not a mark against you.

Leaving

Nothing binds you: either side may stop at any time. Three unexplained silences in a row trigger a review of the seat.

How real benchmarks do this

  • The CME CF Bitcoin Reference Rate is the volume-weighted median of its constituent exchanges’ trades in a 60-minute window. Our venue seats supply the same kind of input: their own trades, not a view.
  • The LBMA Gold Price is set twice a day in an auction run by ICE Benchmark Administration, among participants who trade at that price with their own money — a price made by parties with positions, not by an outside referee.
  • Proof-of-reserve attestors already confirm, on a cadence, that a token’s reserves exist and cover its supply. The issuer seat signs its reserves and supply as of a stated time, daily, with the evidence reference: a gate on the price, never an input to it.
  • After LIBOR, benchmarks moved away from banks’ estimates of where they could borrow, which some banks bent to suit their positions, towards rates built on actual transactions. Every number a member submits here comes from its own records, is kept with a digest, and the venue’s traded range is checked by the ledger itself. The LIBOR objection, answered.
  • Continuous trading is the reason fixings exist: EUR/USD trades every millisecond and the ECB still publishes one daily reference rate; bitcoin trades around the clock and CME still settles its futures on one daily price.

The numbers

$0
Committee members never pay: issuer seat, venue, lender, custodian, transfer agent, asset issuers. Authorised participants pay no per-order fee at launch. Fund and ETP issuers take a licence; pricing on request.
1 / day
One fixing per series per day, guaranteed by the ledger. Automated: minutes of machine time. Manual: one submission in the portal, with your numbers.
K ≥ 2
A quorum of at least two, from differing interests. No single party may reach K alone.
L1 · L2 · L3
Every published value states the trust level each signature was made at. Pilots start at L1. L2 (the seat holds its own key) is built and was proven on DevNet on 26 September 2026; it is switched off on the running desk today, and will be on before the first seat onboards. L3 is not built. Nothing settles for a third party until every signer is at L2 or above.

The five seats, in full

Each seat wants a different answer

The issuer wants the wrapper marked at par. The lender wants it marked conservatively — it is the one under-collateralised if the mark is too high. The venue wants it marked where the asset actually traded. The custodian and the transfer agent are neutral and liable. A committee of three issuers is not a committee. Below is each seat’s required submission under Signer Protocol v4, with the exact field names the API accepts (methodology §4). A malformed field is refused with an error naming it; a well-formed submission that fails its rule is recorded as that seat’s refusal, with the numbers. The v3 yes/no conditions remain accepted as optional extras.

seat · issuer

Issuer

Who sits here. The party that issues the wrapped asset. TradFi analogue: a benchmark contributor under a code of conduct (IOSCO Principle 14 / BMR); an LBMA direct participant with the ability to settle.

“Reserves covered supply at this time, and holders can redeem.”

Submission: reserve-snapshot (peg-integrity gate)

  • reservesReserves backing the token, in units of the underlying (e.g. BTC).number · ≥ 0 · up to 10 dp
  • supplyTokens outstanding at asOf.number · > 0
  • asOfWhen reserves and supply were measured.UTC instant · not in the future · within the asset’s freshness limit (24 h default)
  • evidenceRefThe evidence behind the numbers.text · attested: the proof-of-reserve report URL or reserve address list · on-chain: contract address(es) and block number · custodial: the custodian statement reference
  • redemptionsOpenAre redemptions open to holders right now?yes / no
  • mintBurnPausedIs minting or burning paused right now?yes / no

Gate: reserves ≥ supply, the snapshot is fresh, redemptions are open and mint/burn is not paused. The desk records the coverage ratio and the snapshot’s age. You never set the price: the venues’ trades do. Your seat can only stop publication when your own numbers say the peg is in doubt. Much of this is public (you publish reserve information; supply is on-ledger); what only you add is the signed, timestamped snapshot tied to the strike, the real-time redemption and mint/burn status, and accountability for both. You never send wallet keys, client identities, redemption-queue detail or bank statements.

On refuse

A snapshot that fails the gate is recorded as your refusal, naming each failure, and no fixing of the wrapped asset is finalised: it falls back, labelled (tier 3, then 4), or is published as a gap.

Eligibility and ongoing obligations

  • A named legal entity with disclosed principals and licence; the four on-ledger facts (registrar party, instrument id, registry URL, HoldingV1); a declared reserve model and attestation cadence; a signed attestation agreement.
  • Publish reserve attestations on cadence (< 24h); submit on every fixing; annual re-attestation of fitness, conflicts and confidentiality; notify any change of control.
  • Exactly one issuer seat per instrument. Issuer-controlled parties may never reach K. The issuer may not also hold the custodian or venue seat for its own instrument.
  • Suspension on a missed attestation; mandatory resignation if sanctioned for manipulation; removal for false evidence; three consecutive unexplained silences trigger a review.
Cost
$0 — never charged, never paid
Time
Automated: minutes/day · Manual: one submission/day
Checker
Reference config shipped (examples/v4/issuer.yml)
seat · lender

Lender / risk taker

Who sits here. A platform holding the asset as collateral. TradFi analogue: a financial-intermediary / auction-participant member of a price oversight committee (IBA PMOC); a direct participant with bilateral credit lines.

“Our own mark agrees, within the tolerance we declared in advance.”

Submission: independent-mark (risk-side challenge)

  • markYour own valuation of one unit, from your own risk or collateral system.USD per unit · > 0 · up to 10 dp
  • markAsOfWhen your system produced the mark.UTC instant · not in the future · at most 60 minutes before the submission itself (built; 15 minutes for an OFF-HOURS SIGNED fixing)
  • eligibleIs the asset on your eligible-collateral schedule today?yes / no · no is a refusal
  • haircutPctThe haircut you apply to it as collateral.percent · 0 ≤ h < 100 · required when eligible
  • markSourceThe method behind your mark, e.g. “risk engine: BRR × 0.998”.optional today, required under v1.0 · recorded, not checked
  • markFromPublicReferenceIs your mark derived from a public reference price for the underlying (for example BRR × a factor)?yes / no · required · published with the fixing

Gate: |proposed value − your mark| / proposed value ≤ your declared tolerance (tolerances.markBps, 25 bp by default), set in advance in your seat settings and never per submission. The fixing publishes only if at least one lender’s mark passed. This is the validation check, modelled on bank independent price verification. Send markSource: where your mark is derived from a public reference for the underlying (for example BRR × a factor), the check works as a cap on the token’s basis to that reference, not as an independent valuation of the token, and it is disclosed that way. Your mark, haircut and eligibility are recorded for the committee and its auditor, not published. You never send your loan book, positions, borrowers or margin model.

On refuse

Outside your band, your submission is your refusal, with the numbers: “your mark 64 700 is 43.1 bp from the proposed value 64 980; your declared tolerance is 25 bp” is actionable; a vote of no confidence is not. The disagreement is resolved openly, by restrike or fallback, never averaged away.

Eligibility and ongoing obligations

  • Actually holds the instrument as collateral (position evidence at onboarding, re-checked quarterly); balance sheet at risk; disclosed licence and principals; a declared tolerance in bp.
  • A submission on every fixing; the tolerance may not be widened silently; quarterly position re-confirmation.
  • Position drops to zero: the seat lapses at the next quarterly review. Three refusals without cause trigger a review. Same manipulation-sanction rule as every seat.
  • At least one lender or venue in every K. A lender that is an affiliate of the issuer counts as issuer-controlled.
Cost
$0 — never charged, never paid
Time
Automated: minutes/day · Manual: one submission/day
Checker
Reference config shipped (examples/v4/lender.yml)
seat · venue

Venue

Who sits here. A venue where the wrapped asset actually trades. TradFi analogue: a constituent exchange under CF Benchmarks’ Constituent Exchange Criteria; a regulated electronic trading venue at the first tier of the ICE Swap Rate waterfall.

“These are our executed trades in the observation window.”

Submission: window-trades (price contributor)

  • windowStart, windowEndThe window your figures cover.UTC instants · inside the observation window (the 60 minutes ending at the strike) · not in the future
  • tradeCountTrades executed on your venue in the window.integer · ≥ 0
  • volumeTotal quantity traded.units of the instrument · 0 exactly when tradeCount is 0
  • vwapΣ(price × qty) / Σ qty over the window’s trades.USD per unit · required when tradeCount > 0 · low ≤ vwap ≤ high
  • low, highThe lowest and highest trade price in the window.USD per unit · required when tradeCount > 0 · the ledger refuses a signed value outside them
  • haltSecondsSeconds of the window trading was halted, paused or unavailable.integer · 0 to the window length
  • bidTwap, askTwap, quotedSecondsIf nothing traded: your time-weighted best bid and ask, and how long you were two-sided.when tradeCount = 0 and you quoted · 0 < bid ≤ ask

Your data sets the price. A window is eligible with at least 1 trade, USD 1,000 of notional and no more than 50% halted (pilot defaults). The fixing is the volume-weighted median of the eligible venues’ VWAPs; with three or more venues, a venue more than 300 bp from the preliminary median is excluded and named (an outlier). Your low and high become the traded range the ledger checks: the ledger refuses a price outside the venue’s reported range. You never send individual trades, your book, resting orders or participant identities, and per-venue figures are published only with your consent.

On refuse

If the proposed value lies outside your range, your submission is recorded without a signature, still feeds the calculation, and the desk restrikes at the determined value. Nothing traded: report tradeCount 0 (with your quotes, if you quoted); the fixing falls to the next input level, labelled.

Eligibility and ongoing obligations

  • An admitted constituent venue: all six rulebook §4.0 tests plus an executed data-sharing agreement, an API with trade and order data, KYC/AML compliance, and cooperation with inquiries. Volume above 5% over 30 days, trending to CF’s 3% over 90–180 days.
  • Annual conformance review presented to the committee; surveillance alerts reviewed as a standing item; a submission on every fixing.
  • The administrator may suspend ad hoc; the committee decides permanence; the decision is published. Anyone may nominate an addition or removal.
  • Pilot: one eligible venue is accepted and flagged single-source on every value (minVenues = 1). Two independent venues (different operators) are a condition of any value above tier 0; with one venue every value is tier 0 (methodology §6.4). A venue owned by the issuer or the administrator is disclosed and does not count toward the two.
Cost
$0 — never charged, never paid
Time
Automated: minutes/day · Manual: one submission/day
Checker
Reference config shipped (examples/v4/venue.yml)
seat · custodian

Custodian / reserve holder

Who sits here. Whoever actually holds the backing — a regulated custodian, or the protocol-controlled contracts for an on-chain-verifiable asset. TradFi analogue: an LBMA direct participant with the ability to settle and clear; the custodian and securities-lending communities FTSE Russell draws committees from.

“This is what is actually in the account.”

Submission: custody-reconciliation (reconciliation gate, funds)

  • holdingsUnits you hold in custody for the fund.units of the asset · ≥ 0
  • ledgerHoldingsUnits the ledger shows the fund holding at the strike.units of the asset · ≥ 0 · the desk’s read-only API supplies it
  • encumberedUnits pledged, lent or otherwise encumbered.units of the asset · ≥ 0
  • statementAsOfTime of your custody statement.UTC instant · fresh (24 h default) · not in the future

Gate: holdings = ledgerHoldings and encumbered = 0. The difference is recorded. You never send the statement itself, account numbers or other clients’ positions.

On refuse

A break is your refusal, with the difference, and no fund NAV is signed that day. Notify any lien or rehypothecation immediately.

Eligibility and ongoing obligations

  • A regulated custodian (or protocol-controlled contracts); holdings segregated from own assets; statement age within the declared freshness; an independent control report (SOC 1 / ISAE 3402) or on-chain proof.
  • A submission on every fixing; immediate notice of any lien or rehypothecation.
  • Insolvency: immediate suspension. Must not be the issuer or an issuer affiliate.
  • Mandatory for any asset whose native network is not the settlement ledger.
Cost
$0 — never charged, never paid
Time
Automated: minutes/day · Manual: one submission/day
Checker
Reference config shipped (examples/v4/custodian.yml)
seat · transfer-agent

Administrator / transfer agent

Who sits here. The party appointed under the fund’s governing documents that keeps the share register and does the fund’s accounting today — already liable for it, which is exactly why its signature carries information. TradFi analogue: a calculation or dissemination agent overseen under a benchmark oversight committee’s terms of reference.

“This is the share count the NAV is divided by.”

Submission: register-reconciliation (reconciliation gate, funds)

  • registerSharesShares outstanding on your register.shares · ≥ 0
  • ledgerSharesShares outstanding on the ledger at the strike.shares · ≥ 0 · the desk’s read-only API supplies it
  • registerAsOfTime of your register extract.UTC instant · fresh (24 h default) · not in the future

Gate: registerShares = ledgerShares. The difference is recorded. You never send the register itself, holder identities or holdings.

On refuse

A register that does not reconcile is your refusal, with the difference; report the break the same day. No fund NAV is signed on an unreconciled register.

Eligibility and ongoing obligations

  • Appointed under the fund’s governing documents; maintains the share register; reconciles shares outstanding daily; an SLA with the administrator.
  • A submission on every fixing; breaks reported the same day.
  • Replacement by the fund, notified to licensees. Cannot be the benchmark administrator.
  • Where the fund self-administers, the seat is disclosed as issuer-controlled and excluded from K for issuer-majority purposes.
Cost
$0 — never charged, never paid
Time
Automated: minutes/day · Manual: one submission/day
Checker
Reference config shipped (examples/v4/transfer-agent.yml)

Every member discloses conflicts. The public roster follows IBA’s table: name, company, market position, seat and instruments covered, directorships and interests, date of the conflict-of-interest declaration — plus trust level and declared tolerance band. Tolerances are published in aggregate. Terms of office: six months initial, extended, maximum nine consecutive years, with an annual membership review. Removal is mandatory on a manipulation sanction, for any seat.

Automating a seat: for your engineers

Every condition is a query against your own systems

None requires a human to form a view. An unpaid committee that needs daily human attention decays into rubber-stamping within weeks, so a seat should run a checker that builds its submission from its own systems every day, lets the desk record a pass or a refusal with the numbers, and halts when a source cannot be read. A halt is never a confirm, and never a refusal either. A checker must never submit an estimate in place of data and must never widen its own tolerances — both are invisible on the ledger because the signature looks identical.

The reference checker

signer-service, supplied to every seat, is a small program that runs hosted by us, in your own cloud, or on your own infrastructure (how you run it). It reads each field from a source you declare — an HTTP endpoint or a command against your systems — and posts your v4 submission to POST /api/proposals/{cid}/confirm with a scoped API key. At L1 it holds no Canton key; at L2 it holds your seat’s own key, which never leaves your KMS or your machine. It never reads the proposed value to build your numbers, and never acts twice on the same proposal.

It hears about a proposal by signed webhook (X-CrossDesk-Signature, HMAC-SHA256) or by polling GET /api/proposals?status=open&mine=true. Reference v4 configs ship today for all five seats (examples/v4/); their stub adapter halts until you wire a real source.

Five minutes, before any account

npm ci && npm run build          # Node 20+
CROSSDESK_SANDBOX_USER=venue@sandbox.crossdesk \
  node dist/index.js --config examples/v4/venue.yml --check
CROSSDESK_SANDBOX_USER=venue@sandbox.crossdesk \
  node dist/index.js --config examples/v4/venue.yml

--check validates your config and reads every source without sending anything. The sandbox header works only against a sandbox desk, where nothing is at stake. On etpfoundry.com the key comes from the portal (Settings → API key), is shown once, stored hashed, and can only confirm or refuse fixings for the instruments your seat covers.

Header and variable names keep the project’s former name (CrossDesk) so existing integrations do not break.

The trust ladder

A signature is worth exactly what it costs to forge

Every published value states the level each signature was made at; the fixing record shows the mix, e.g. K=3 of N=5 — L1:2, L2:1. Scope limits apply at every level: a signer credential may only confirm or refuse fixings for the instruments its seat covers. It cannot move assets, propose a fixing, or act as another seat.

LevelWhere the signing key livesCould the administrator forge it?Your costWhat it requires from you
L1 · hosted partyOn the administrator’s participant; a scoped API key authorises and the administrator exercises the choice as your party.Yes, technicallyZeroYour e-mail on the roster. Nothing to run.
L2 · external signingWith you, off-ledger; the administrator submits a transaction you have already signed.No — not through the Ledger API (see below)ModerateYour own signing key, in your own cloud KMS or generated on your machine (signer-service keygen), plus an API key and a checker run in your own cloud or on your own server (a checker we host counts as operator-run, tier 0). The desk prepares each transaction; your signer recomputes its hash and signs only if it matches. Built; proven on DevNet, 26 Sep 2026; switched off on the running desk today, on before the first seat onboards.
L3 · own participantOn your own Canton participant.NoHigh — you run CantonYour own participant party id on the roster. Not built yet.

L1 is honest for a pilot and dishonest as a destination. It is the right level for a free shadow run or a design partnership, where nothing settles against the value. It is not acceptable for an OFFICIAL fixing a third party settles against. Target state: every signer at L2 or above before that happens. Disclosed at onboarding: the administrator can assume a mapped user’s identity for a single request (support). Every such act is recorded, and it is never used to confirm a fixing on a signer’s behalf.

What we can still do at L2, stated plainly. At L2, not through the Ledger API: your key signs. We can still refuse or delay your submission, and a participant running modified software is the one remaining path, which L3 closes. L2 is built and was proven on DevNet on 26 Sep 2026. It is switched off on the running desk today, and will be on before the first seat onboards. In detail: we prepare and submit your transaction, so we can refuse or delay it — a seat that is refused should say so publicly. Your external party is hosted only on our participant, so a participant running modified software is the one remaining path to a signature without your key; L3 (your own participant confirming as well) is what closes it. Your party’s id is derived from your key’s fingerprint, so anyone with synchronizer access can check that the party signing as you is controlled by the fingerprint you publish.

What the ledger enforces — since package 3.0.0 (live: 3.2.0)

  • The administrator signs every proposal and every fixing (signatory admin :: approvers). A proposal can only be born inside a choice on a committee the administrator signed; a forgery is not refused, it cannot be constructed.
  • K ≥ 2, K ≤ N, and the administrator is not a member. It proposes and publishes; it never attests.
  • A venue that traded confirms with its window’s low and high (from window-trades), and the ledger refuses a value outside them. One that did not trade reports zero trades, and the fixing falls to the next input level. Plain confirm is gone; every attestation carries a SignerCheck. A range from any other seat is refused on-ledger.
  • One fixing per series per day. Every proposal carries an attested asOfDate; one series contract per (administrator, instrument, session) is consumed and advanced by every finalise.
  • Any approver or the administrator may finalise — the proposer holds no veto. Members observe every fixing, so a member that did not sign can open a restatement.

The API enforces, before submission, that each seat’s v4 submission is well formed (fields, units, precision, windows) and applies its rule; the desk computes the determination and the gates. Nothing enforces the provenance of those numbers — that rests on your own systems, and on the fact that a false number is permanent, attributable, and made against your own money. This residual trust is disclosed to every seat rather than glossed.

How to start

A seat is issued, never self-registered

Open registration would let anyone self-declare as a lender, and the value of K-of-N is entirely in who the N are. So the roster is seeded by the administrator, and every row carries: e-mail · Canton party · seat · declared tolerances · API key hash.

Say which seat, and on what

One e-mail: the seat you hold (issuer, lender, venue, custodian or transfer agent), the instruments it covers, and the position that makes you eligible — the asset you issue, the collateral you hold, the book you run, the account you custody, the register you keep. An issuer adds the four facts: registrar party id, instrument id, registry base URL, HoldingV1 confirmation — and its reserve model.

Declare your tolerances and disclose conflicts

How far from your own valuation a mark may sit before you refuse (recommended 25 bp); any affiliation with the issuer, the administrator, or another seat on the same instrument. The seat is issued at L1 and your e-mail is added to the roster.

Sign in, read your seat, choose how you run it

The portal’s first screen shows exactly what your seat submits for each instrument, with every field’s unit and precision. Hosted is the default: set up in the dashboard, nothing to install. Your own legal and compliance review will take longer, and we go at your pace. Or run the checker in your own cloud or on your own server (the three choices) — or submit by hand, with your numbers, once a day.

Shadow run, then move up the ladder

Nothing settles against a shadow value. When your checker has run clean for a period you are comfortable with, you move to your own cloud or your own server with your own key (L2): the desk allocates your external party, and from then on your key signs for your seat (the remaining paths are stated in the trust ladder; L2 is switched off on the running desk today, and will be on before the first seat onboards). Every published value carries the level. (L3, signing from your own Canton participant, is not built yet.)

Request a seat → committee@etpfoundry.com

Sending the e-mail commits you to nothing. See the rulebook and signer protocol for the full text, and Governance for how the committee is composed.