Risks addressed

  • The books drift from the register.
  • An act cannot be traced.
  • An investor’s data reaches another investor.
  • Data leaves your perimeter.

Controls

  • Reconciliation matches every mint and burn to the order that planned it, and the register to outside records, on a schedule. A blocking finding holds the asset at the venue until two approvers release it. A backed instrument’s reserve is matched to its locked holdings, to the backed instrument’s supply and to its minimum cover.
  • Every act of the venue is recorded with who asked, who approved and the ledger transaction it became, alongside an ordered event feed and exports.
  • Every read names the point on the ledger it was read at, and can be read again at that point, so reports can be reproduced.
  • Each party sees only what it is party to, and investors never see each other’s orders or holdings. No personal data reaches the ledger.
  • NodeAsset and its stores run on your infrastructure, so your data stays with you.

Evidence

  • Reconciliation runs, findings and releases.
  • Operations, approvals, events and exports.
  • Each party’s view of the ledger.
Matrix rows CTL-16 to CTL-19: see the control matrix.

Reconciliation

The venue’s plans and outside records are compared with the ledger. Reconciliation is the venue’s own control: a blocking disagreement holds the asset at the venue.
Outside records arrive as statements, kept exactly as received with their hash: statements of holdings as semt.002, bank statements as ISO 20022 camt.053, and files from administrators and transfer agents. Reconciliation compares three kinds with the ledger: distribution lists, statements of holdings and NAVs. A bank or custody statement is kept as received, and not compared. Findings about who holds, about supply, or about an unplanned mint or burn stop the asset; findings about an amount or a time are listed for review. See Reconciliation.

Audit trail

Contracts live on each party’s node; the venue’s database holds what was decided and who decided it.
By default every row is kept. A deployment may set an age per kind of history (reconciliation runs, events, operations, approvals), and a daily pass deletes older rows, never one a hold, an open settlement or a kept operation still names. A backup keeps what retention later deletes. See Configuration reference.

Who sees what

Canton shares a contract only with its parties, so each party sees the transactions it takes part in and nothing else.
DA’s operator observes every settlement on its registry, and the venue, as a registry’s provider, sees every holding on that registry: for a tokenized deposit, the bank’s whole deposit book.
  • The ledger holds party ids, and each holder’s claims as codes with their expiry, but no name and no document.
  • The venue’s database holds each holder’s id and party, an optional display name, its KYC provider and case reference, and its attributes with their proof hash, each version kept, as well as the person behind every operation and approval.
  • NodeAsset does not hold the KYC evidence itself, which stays with whoever ran the KYC.
Through the API, every read is confined to the caller’s role: an investor reads only its own holder, a monitoring system only health and redacted control events.
Related: Reconciliation · Reporting · Backup and recovery