The engine and its API run at the venue and act only as the venue’s party. Register keepers, price sources and investors act on their own systems; see Who runs what.
NodeAsset runs inside your perimeter, beside your own Canton node. The DA Registry holds every unit of every asset, and every party acts on its own node: NodeAsset prepares and settles the venue’s acts, and each other party signs its own.

The parts

NodeAsset is the engine and its API. It ships no screens: the venue builds its own on the API, or has its systems integrator build them, and the demo shows a screen for each role. The ledger is the source of truth. Every holding, reserve, subscription, credential and price is a contract on the parties’ Canton nodes, and the engine reads them back through PQS. Its own database holds only what it decided: the requests it took, who approved them, what it stopped, and what reconciliation found. Every asset runs on the same Daml packages. Adding an asset records its configuration, under four eyes, and deploys no contract.

Who runs what

Each party above can be a firm of its own, or a desk of the venue’s own organization. Either way, each keeps its own party and its own key, so the same signatures and the same separation hold. Deployment patterns lists who can be internal or external, the rules every combination keeps, and five named patterns. The parties and what each signs are on Parties and the DA Registry; how the API protects itself is on API security. Related: Install · Parties and the DA Registry · Deployment patterns