# What we ask committee members (v2) **Version 2, 28 September 2026.** Signer Protocol v4, ETP Foundry Methodology v1.0. A plain-English summary, per seat, for firms considering a seat on an ETP Foundry committee. Methodology v1.0 is the sole governing methodology; the Rulebook v0.2 describes process only where it is consistent with it, and where any text differs, Methodology v1.0 governs. It supersedes [version 0.1](/documents/what-we-ask-committee-members-v0.1.md) (Signer Protocol v3, yes/no answers), which stays published. The rules themselves are in the [methodology](/methodology), the [committee terms of reference](/documents) and the signer protocol, served at etpfoundry.com/api/signer-protocol; where this summary and those differ, they govern. > **Each seat submits, once a day, a few numbers that only it holds, from its own systems. A > checker on its own servers builds and sends them. The venues' numbers set the price, the lender's > mark challenges it from the risk side, and the issuer, custodian and transfer agent can stop it. > Nobody is asked for an opinion, and nobody pays.** For tokenised stocks, the same checker will also > answer three times a day, off-hours included (section 6; specified, not built). **The one-paragraph version.** At each strike the desk looks at the **observation window**, the 60 minutes ending at the strike. Each **venue** reports its own trades in that window as totals (count, volume, VWAP, low, high, halt time). The fixing is the **volume-weighted median** of the eligible venues' VWAPs, after an outlier rule. A **lender** submits the mark its own risk system uses, and nothing publishes unless the fixing sits inside the tolerance it declared in advance (a risk-side challenge, or basis check). The **issuer** signs a timestamped reserves/supply snapshot with redemption and mint/burn status, and nothing publishes while the peg is in doubt. For a fund, the **custodian** and **transfer agent** each reconcile their records against the ledger. The administrator (ETP Foundry) computes and publishes, and the ledger refuses it as a signer. **Crypto strike time: 16:00 London, adopted 28 September 2026** (the time of the CME CF Bitcoin Reference Rate; the window is 15:00–16:00 London). **Status, stated plainly.** DevNet only. Every published value is tier 0 (indicative). No seat is held by a third party. ETP Foundry is not an authorised or registered benchmark administrator anywhere. The rules below are implemented and unit-tested in the desk; none has yet run on a third party's data. **Rules for every seat.** Prices are USD per unit of the instrument; numbers carry at most 10 decimal places (the ledger's `Numeric 10`); times are ISO-8601 UTC. A **malformed** field is refused with an error naming it, and nothing is recorded. A **well-formed** submission that fails its gate is recorded as that seat's **refusal**, with the numbers, and nothing is signed. Every accepted submission is stored with a SHA-256 digest of what was received. ## 1. Venue: price contributor (`window-trades`, required) **Who:** head of market data or market operations at a venue with a book in the asset. **Why only you:** only you hold your own trade tape. Without a venue there is no transaction data for the asset in the room. **Your data sets the price.** | Field | Unit | Rule | |---|---|---| | `windowStart` | UTC instant | Start of the period your figures cover; not before the observation window opens | | `windowEnd` | UTC instant | After `windowStart`; not after the confirmation window closes, not in the future | | `tradeCount` | trades (integer) | ≥ 0 | | `volume` | units of the instrument, ≤ 10 dp | ≥ 0; exactly 0 when `tradeCount` = 0 | | `vwap` | USD per unit, ≤ 10 dp | Required when `tradeCount` > 0; Σ(price × qty) / Σ qty; `low` ≤ `vwap` ≤ `high` | | `low` | USD per unit, ≤ 10 dp | Required when `tradeCount` > 0; > 0 | | `high` | USD per unit, ≤ 10 dp | Required when `tradeCount` > 0; ≥ `low` | | `haltSeconds` | seconds (integer) | 0 ≤ value ≤ the window's length | | `bidTwap`, `askTwap` | USD per unit, ≤ 10 dp | Only when nothing traded and you quoted: time-weighted best bid and ask, 0 < bid ≤ ask | | `quotedSeconds` | seconds (integer) | With quotes: seconds the book was two-sided, ≤ the window's length | | `selfTradesExcluded` | true / false | **Required.** You attest that the figures exclude self-matched trades, trades between affiliated accounts, and trades with the venue or its affiliates as principal. `false` (or absent, once required) makes the window ineligible for the price | **What happens to it.** Your window counts toward the price if it has ≥ `minTrades` trades (pilot: 1), ≥ `minNotionalUsd` notional (pilot: USD 1,000) and was halted ≤ 50% of the window. With three or more eligible venues, a venue below 10% of the eligible volume does not enter the median, any venue more than 300 bp from the simple median of venue VWAPs is excluded and named, and no venue carries more than 50% of the weight. With exactly two venues there is no cap: the larger venue's VWAP is the value only if it lies inside the other venue's range. **Two independent venues are a condition of any value above tier 0**; with one venue every value is tier 0. Your `low` and `high` also go to the ledger, which refuses to let you sign a value outside them; if the value falls outside, your submission is recorded without a signature and still feeds the calculation. Nothing traded: report `tradeCount` 0 and, if you quoted, your time-weighted quotes. **Already public:** your displayed book, if you publish one. **Only you provide:** your executed trades in the window, aggregated and signed, and your halt record. **Never sent:** individual trades, your order book, resting orders, participant or client identities. Per-venue figures are published only with your consent. **Conditions for your windows to count (specified, not yet contracted).** Your data counts toward a tier 1 price only while: (1) you have signed the committee terms' data-sharing clause, giving the administrator (and the oversight function, once constituted) the right to receive the trade-level records behind any submission within **5 business days** of a request; (2) you exclude and attest self-trades as above; (3) you run surveillance over the token's book (at least spoofing, layering, wash and marking-the-close alerts) and report any alert touching an observation window within 1 business day; (4) you have 90 days of trading history in the token. This is the audit right behind the aggregates: individual trades are produced only on request, never with each submission. ## 2. Lender: risk-side challenge (`independent-mark`, required) **Who:** head of risk, or whoever owns the liquidation engine, at a lender that takes the asset as collateral. **Why only you:** only you know your own mark, your eligible-collateral schedule and your haircut, and you are the party that loses money if the value is too high. **Your mark challenges the price from the risk side:** the value must agree with the number your own risk system uses. | Field | Unit | Rule | |---|---|---| | `mark` | USD per unit, ≤ 10 dp | > 0; from your own risk or collateral system | | `markAsOf` | UTC instant | Not in the future; at most **60 minutes before your submission itself** (changed: today's desk measures from the opening of the observation window) | | `eligible` | true / false | Is the asset on your eligible-collateral schedule today; `false` is a refusal | | `haircutPct` | percent, ≤ 2 dp | Required when `eligible`; 0 ≤ h < 100 | | `markSource` | text, ≤ 200 chars | **Required** (changed; optional today). The method behind the mark, e.g. "risk engine: BRR × 0.998" or "own liquidations, 7-day VWAP". Recorded, not checked | | `markFromPublicReference` | true / false | **Required.** `true` when your mark is derived from a public reference price for the underlying (e.g. BRR × a factor). Published with the fixing, so every reader knows which kind of check was made | **The gate.** |proposed value − mark| / proposed value must be within **your declared tolerance** (`tolerances.markBps`, default **25 bp**; 1 bp = 0.01%). You set it in advance in your seat settings, never per submission. Outside the band is your refusal, recorded with the numbers: *"your mark 64 700 is 43.1 bp from the proposed value 64 980; your declared tolerance is 25 bp"*. The fixing publishes only if at least one lender's mark passed. **The precedent.** Modelled on independent price verification (IPV) in bank valuation control: prices verified by a unit independent of those who benefit (CRR Art. 105(8)), against thresholds set in advance (Delegated Reg. (EU) 2016/101 Art. 19(3)(e); BCBS fair-value guidance, April 2009, Principles 1 and 4). No regulator publishes the number; each lender declares its own. "Independent" in the IPV sense means independent of the party that benefits, not an independent source of information. **Stated plainly:** where your mark is derived from a public reference (for example BRR × a factor), the check is a **basis check**: a cap on the token's basis to its underlying, not an independent valuation of the token. `markFromPublicReference` discloses that on each fixing. Only a mark from your own executed trades or liquidations in the token counts as independent price evidence. Where eligible venue prints and a reference-derived mark disagree by more than your tolerance, the refusal is published with both numbers and escalated; the fixing is not forced to the reference. **Already public:** nothing about your book. **Only you provide:** your own mark, your eligibility decision and your haircut, stated against your own exposure. **Never sent:** your loan book, positions, borrowers, liquidation queue or margin model. Your mark and haircut are recorded for the committee and its auditor, not published. ## 3. Issuer: peg-integrity gate (`reserve-snapshot`, required for wrapped assets) **Who:** head of operations or treasury at the token's issuer (BitSafe for CBTC, onRails for cETH). **Why only you:** only you can state, with accountability, what your reserves and redemption desk looked like at a given time. **You never set the price.** Your seat can only stop publication, when your own numbers say the wrapper may not be worth its underlying. | Field | Unit | Rule | |---|---|---| | `reserves` | units of the underlying (e.g. BTC), ≤ 10 dp | ≥ 0 | | `supply` | tokens outstanding, ≤ 10 dp | > 0 | | `asOf` | UTC instant | Not in the future; age ≤ the asset's freshness limit (default 24 h) | | `evidenceRef` | text, ≤ 500 chars | The evidence behind the numbers: proof-of-reserve report URL, reserve address list or auditor report reference (attested); contract address(es) and block number (on-chain, e.g. cETH); custodian statement reference (custodial) | | `redemptionsOpen` | true / false | Redemptions open to holders now | | `mintBurnPaused` | true / false | Minting or burning paused now | **The gate.** All four must hold, or the snapshot is your refusal naming each failure: `reserves` ≥ `supply`; the snapshot is fresh; `redemptionsOpen` = true; `mintBurnPaused` = false. The desk records the coverage ratio (reserves / supply, 6 dp) and the snapshot's age. **Already public, and why the signature still matters.** Much of this is observable: you publish reserve information, and supply is readable on-ledger. The signed snapshot adds four things a web page does not: (1) a named party states the numbers, on a permanent record; (2) a timestamped as-of snapshot, so the fixing is gated on reserves *at that time*; (3) contractual accountability, since a knowingly false submission is grounds for removal (committee terms §11.7); (4) the **real-time** redemption and mint/burn status, which only you can state. A proof of reserve is point-in-time and covers assets, not liabilities; the gate inherits that limit. Your snapshot is your own statement, not an audit or an examination. **Never sent:** wallet keys, client identities, redemption-queue detail, bank statements or internal ledgers. ## 4. Custodian: holdings reconciliation (`custody-reconciliation`, required for funds) **Who:** client-service or operations lead at the custodian holding a fund's assets. **Why only you:** only you can see the account. | Field | Unit | Rule | |---|---|---| | `holdings` | units of the asset, ≤ 10 dp | ≥ 0; units held in custody for the fund | | `ledgerHoldings` | units of the asset, ≤ 10 dp | ≥ 0; units the ledger shows the fund holding at the strike | | `encumbered` | units of the asset, ≤ 10 dp | ≥ 0; pledged, lent or otherwise encumbered | | `statementAsOf` | UTC instant | Fresh (default 24 h), not in the future | **The gate.** `holdings` = `ledgerHoldings` and `encumbered` = 0. A break is your refusal, recorded with the difference, and no fund NAV is signed that day. **Already public:** nothing. **Only you provide:** the units actually in custody and any encumbrance. **Never sent:** the statement itself, account numbers, other clients or their positions. ## 5. Transfer agent: register reconciliation (`register-reconciliation`, required for funds) **Who:** the transfer-agency or fund-accounting lead appointed under a tokenised fund's governing documents. **Why only you:** only you keep the register. | Field | Unit | Rule | |---|---|---| | `registerShares` | shares, ≤ 10 dp | ≥ 0 | | `ledgerShares` | shares, ≤ 10 dp | ≥ 0; shares outstanding on the ledger at the strike | | `registerAsOf` | UTC instant | Fresh (default 24 h), not in the future | **The gate.** `registerShares` = `ledgerShares`. A break is your refusal, recorded with the difference, and no fund NAV is signed that day. **Already public:** nothing. **Only you provide:** the shares on the register. **Never sent:** the register itself, holder identities or holdings. ## 6. Off-hours: OFF-HOURS SIGNED fixings for tokenised stocks (specified, not built) A tokenised stock trades 24/7; its home market does not. Lenders need a number at 02:00 on a Sunday. The methodology therefore specifies **OFF-HOURS SIGNED fixings (label `OFFHOURS`) at 00:00, 08:00 and 16:00 UTC, every day**, weekends and holidays included, each published as a value **± a data-quality band**. Once attested they are for margin, liquidation, health factors and haircuts, and **never a NAV**: creation and redemption wait for the next OFFICIAL fixing. Until the four conditions for any value above tier 0 hold, they are published at tier 0 labelled `pilot — not attested`, and the licence forbids their use for liquidation. The band is not yet calibrated: at z = 1 its nominal coverage would be about 68% if errors were normal, which has never been measured; z = 2 is recommended for haircuts, and a back-test of at least 12 months is required before any is attested. At least one venue signature must be among the K for any off-hours fixing. The same wire format is reused; what changes for each seat: | | Venue (`window-trades`) | Lender (`independent-mark`) | Issuer (`reserve-snapshot`) | |---|---|---|---| | Window | The **15 minutes** ending at the fixing time | Mark at most **15 minutes** before your submission | Custodial snapshot at most **96 hours** old (a Friday statement covers a weekend and a Monday holiday) | | New fields (planned) | `quoteCurrency` (USD, USDC or USDT); `depthSizeUsd` (the size S, default USD 25,000); `bidAtSize` / `askAtSize` (best price at which S could be sold / bought); `bookAsOf` (within 1 minute of the fixing time); `selfTradesExcluded` | As section 2, including `markSource` and `markFromPublicReference` | `multiplier` (shares per token, must equal your published multiplier); `multiplierNext` / `multiplierActivatesAt` when a change is pending; `primaryLevel` / `primaryLevelAsOf` while primary issuance is open; `corporateActionPending` | | Gate | Your range must contain the value, or you are recorded without a signature; no trades: attest no prints, and the value must sit inside your quote | \|value − mark\| / value ≤ **`markBpsOffHours`**, the off-hours tolerance you declare in advance in your seat settings (default: your `markBps`). The published band is shown beside your result but **never widens your tolerance**. Your haircut is recorded with the band | Unchanged. A refused issuer gate means **NO FIXING**, never reference × par. `redemptionsOpen` means you are accepting requests, even if processed next business day | **Timing.** The **submission cut-off is the fixing time + 10 minutes**; a later submission is recorded as late and does not count. If K signatures are not reached by the fixing time + 30 minutes, the result is **NO FIXING**, with the reason, and the last good value stays visible with its age. There is no tier 3 or 4 fallback off-hours. **The custodian and transfer agent are not used**: an OFF-HOURS SIGNED fixing is never a NAV. Your checker runs this automatically; **no human is in the loop per fixing**. ## Why this is not rubber-stamping 1. **The price comes from the committee's data, not from outside it.** The fixing is the volume-weighted median of the venues' own signed window VWAPs. The external reference price is a fallback, published at tier 3 and labelled as such. One qualification: while the lender's mark is derived from a public reference, the venues' data can move the fixing only inside the lender's band around that reference, and `markFromPublicReference` says when that is the case. 2. **Every submission is a number that can be wrong in a checkable way.** A venue's VWAP must lie within its own low and high, and its range must contain the value it signs (the ledger refuses otherwise). A lender's mark must fall within a tolerance it declared in advance. An issuer's reserves must cover supply, as of a stated time, with a reference to the evidence. A yes/no cannot be checked like this; a number with a timestamp and a digest can. 3. **The seats check each other, and their interests differ.** The venues set the price from trades; the lender, which is harmed by an overstated value, challenges it against its own risk-system mark; the issuer, which would prefer par, cannot move the price at all and can only stop publication. 4. **Disagreement is visible, not averaged.** An excluded venue, a lender outside its band and a failed issuer gate are each recorded with the numbers, and a value does not publish when a seat's data says it should not. 5. **The administrator cannot fill the gap.** It computes and publishes, but it cannot sign, and the ledger refuses it as a member. If the gates fail, the result is a labelled fallback (tier 3 or 4) or a published gap (tier 5). **What this does not solve.** The desk cannot audit a seat's source systems. A seat that submits a false number has made a false statement on a permanent record, under its name. That residual trust is disclosed to every seat. Canton venue liquidity for CBTC and cETH is unproven: until venues submit, the transaction-based price is a design, not a demonstrated fact. ## Objections, and honest answers - **"Liability?"** Each seat states numbers about its own records and nothing else. It does not certify the other seats, the final value, or ETP Foundry. A knowingly false submission is on the record under its name and grounds for removal (terms §11.7). We offer no indemnity; send counsel the public terms of reference first. - **"Effort?"** An afternoon for one engineer to point the checker (`signer-service`) at the seat's own systems; then it runs unattended. It halts and sends nothing if a source cannot be read, never widens a tolerance, and never reads the proposed value to build the numbers. The portal takes the same submission by hand. - **"Confidentiality?"** Your submission goes to the administrator's desk and is kept in its append-only record. It is shown to the committee and its auditor, and published per seat only with your consent. That is the administrator's policy under the committee terms, not a property of the ledger. The on-ledger `SignerCheck` shows only your role, conditions and range. - **"Cost?"** None. Committee members never pay and are never paid. - **"What are your own conflicts?"** The fund and ETP issuer licence includes a component linked to the assets under management of funds that reference ETP Foundry fixings. AUM rises with the fixing level, so this is a conflict of interest for the administrator. It is disclosed; the controls are that the administrator computes but never attests, cannot sign (the ledger refuses it as a member), and does not trade the instruments. Those controls do not address a fee that rises with the level; the mitigation for that is Methodology v1.0 §6.4: no value above tier 0 without an independent oversight function, K signatures by third parties with their own keys, and no administrator seats. The administrator also operates the settlement desk and creation/redemption, and today operates every committee seat on DevNet; both are disclosed conflicts. - **"Can you sign for us?"** On hosted pilot seats (L1), technically yes: disclosed on every value and logged. At L2, not through the Ledger API: your key signs. We can still refuse or delay your submission, and a participant running modified software is the one remaining path, which L3 closes. L2 is built and was proven on DevNet on 26 Sep 2026. It is switched off on the running desk today, and will be on before the first seat onboards. Your own node (L3) is not built yet. - **"Is this a regulated benchmark?"** ETP Foundry is not authorised, registered, recognised or endorsed as a benchmark administrator anywhere. A fixing would be based on input data contributed by contributors (BMR Art. 3(1)(8)–(9)); Canton venues are not MiFID II / UK MiFIR trading venues, so it is not a regulated-data benchmark (Art. 3(1)(24)). Whether it is a "benchmark" under Art. 3(1)(3) depends on how it is used, not on our status, and we do not assert that it falls outside that definition. Canada (the administrator is in Ontario; nothing is designated under MI 25-102) and the US (Rule 2a-5 pricing-source oversight; Commodity Exchange Act anti-manipulation provisions) are open questions for counsel. The methodology is modelled on the IOSCO Principles for Financial Benchmarks (2013) and EU/UK benchmark practice, says where it falls short, and claims compliance with nothing. --- *ETP Foundry is operated by Lucilla, Inc., Toronto. ETP Foundry is not an authorised or registered benchmark administrator in any jurisdiction, and does not claim that status. Nothing in this document is investment advice or an offer of any financial product or service. committee@etpfoundry.com*