Risks addressed
- The books drift from the register.
- An act cannot be traced.
- An investor’s data reaches another investor.
- Data leaves your perimeter.
Controls
- Reconciliation matches every mint and burn to the order that planned it, and the register to outside records, on a schedule. A blocking finding holds the asset at the venue until two approvers release it. A backed instrument’s reserve is matched to its locked holdings, to the backed instrument’s supply and to its minimum cover.
- Every act of the venue is recorded with who asked, who approved and the ledger transaction it became, alongside an ordered event feed and exports.
- Every read names the point on the ledger it was read at, and can be read again at that point, so reports can be reproduced.
- Each party sees only what it is party to, and investors never see each other’s orders or holdings. No personal data reaches the ledger.
- NodeAsset and its stores run on your infrastructure, so your data stays with you.
Evidence
- Reconciliation runs, findings and releases.
- Operations, approvals, events and exports.
- Each party’s view of the ledger.
Reconciliation
The venue’s plans and outside records are compared with the ledger. Reconciliation is the venue’s own control: a blocking disagreement holds the asset at the venue.How it works: what is matched
How it works: what is matched
Outside records arrive as statements, kept exactly as received with their hash: statements of holdings as
semt.002, bank statements as ISO 20022 camt.053, and files from administrators and transfer agents. Reconciliation compares three kinds with the ledger: distribution lists, statements of holdings and NAVs. A bank or custody statement is kept as received, and not compared. Findings about who holds, about supply, or about an unplanned mint or burn stop the asset; findings about an amount or a time are listed for review. See Reconciliation.Audit trail
Contracts live on each party’s node; the venue’s database holds what was decided and who decided it.How it works: the records and where they are kept
How it works: the records and where they are kept
How it works: exports and retention
How it works: exports and retention
By default every row is kept. A deployment may set an age per kind of history (reconciliation runs, events, operations, approvals), and a daily pass deletes older rows, never one a hold, an open settlement or a kept operation still names. A backup keeps what retention later deletes. See Configuration reference.
Who sees what
Canton shares a contract only with its parties, so each party sees the transactions it takes part in and nothing else.How it works: each party's view
How it works: each party's view
DA’s operator observes every settlement on its registry, and the venue, as a registry’s provider, sees every holding on that registry: for a tokenized deposit, the bank’s whole deposit book.
How it works: personal data
How it works: personal data
- The ledger holds party ids, and each holder’s claims as codes with their expiry, but no name and no document.
- The venue’s database holds each holder’s id and party, an optional display name, its KYC provider and case reference, and its attributes with their proof hash, each version kept, as well as the person behind every operation and approval.
- NodeAsset does not hold the KYC evidence itself, which stays with whoever ran the KYC.

