Risks addressed

  • An order settles at a wrong or stale price.
  • The venue or the issuer sets or alters a price.
  • The ledger’s price disagrees with the administrator’s official NAV.
  • Amounts are miscalculated, or rounded against the fund.

Controls

  • An order settles only at the price the asset’s own signed for it, once. The venue reads prices and never sets one, and a fund’s consent refuses a price source that is the venue, or the fund’s own registrar or treasury: neither the issuer nor the venue sets a price.
  • The administrator’s NAV carries an expiry and a kill switch. An expired NAV or a pulled switch holds the asset at the venue. Two approvers release the hold. A reserve that holds the asset refuses a price past its freshness window on the ledger.
  • Reconciliation, the venue’s own control, cross-checks the administrator’s official NAV against the price on the ledger. When they disagree beyond tolerance, it holds the asset at the venue.
  • Amounts are always computed the same way. Payments round up and payouts down, so the fund is never paid less, or pays more, than the units are worth. The remainders stay with the fund.
  • A market-data provider adds checks, but its figure never replaces the price source’s.

Evidence

  • Each signed price, with its expiry and the order it priced.
  • Holds and releases, with both figures named.
  • Each settlement’s amounts, recomputable from its units and price.
Matrix rows CTL-7 to CTL-9: see the control matrix.
A par asset, such as a tokenized deposit or a stablecoin, has no price source. A backed instrument’s reserve reads each of its assets’ price sources.
The administrator also sends its official NAV off the ledger, by API or file: the NAV, an optional indicative value that prices nothing, an expiry and a kill switch.A fresh NAV, or the switch lowered, clears the finding on the next run; the hold stays until risk asks for its release and two approvers sign. See Price source and oracles.
  • Every amount on the ledger has one number type: ten fractional digits, at most 38 digits in all.
  • A product rounds half-even at ten places, then once to the figure’s own places, in the direction given for that kind of figure.
  • For a subscription, the order fixes the units. When paid on the ledger, the payment is units × NAV, rounded up to the payment asset’s places. Example: 3 units at a NAV of 1.001 is 3.003, paid as 3.01.
  • For a redemption, the claim fixes the units. When paid on the ledger, the payout is units × the claim’s price, rounded down. Example: 80 units at 1.00711 is 80.5688, paid as 80.56. A payout that rounds to zero is refused.
  • In a dealing cycle, every order is priced at one NAV and rounded as if alone; the fund’s payment account moves the net, a sum that is never rounded.
  • For a distribution, income is computed from the NAV’s rise, withheld at the rate the period-end NAV carries, and paid rounded down to the asset’s payout decimals; the fraction carries to the next period.
  • A backed instrument’s reserve follows the cover rule: Σ units × price × (1 − haircut) ≥ outstanding × backed price × minimum cover, checked inside every act that changes it. Its roundings favour the reserve: a mint pays the price rounded up and its units round down; a redemption is paid at the price rounded down.
  • NodeAsset charges and computes no fees. A fund’s fees are in the NAV its administrator strikes.
Each fund’s administrator agrees these rules for its fund before go-live.
Related: Price the asset · Distributions and period end · Limits and settlement safety