Short answers to the questions evaluators ask most. Each links to the page with the detail.

The product

The Registry holds the assets: holdings, credentials, mint, burn, transfer and settlement batches. NodeAsset is the engine on top, served as one API: the primary market at a signed price, servicing, four-eyes controls and reconciliation. The screens on it are the venue’s own, or its systems integrator’s. See Why NodeAsset.
Funds, tokenized deposits, stablecoins, commodities and products backed by other assets. Each asset is configuration on one shared set of contracts: its record, its price source and its policy, approved under four eyes. Only a new kind of behaviour on the ledger needs a new release. What a deployment configures, and what an integration project connects, is on Implementation.
Yes: setup, onboarding, pricing, subscriptions and redemptions, dealing cycles, distributions each period, freezes and holds, exit, and reporting. Each stage is an API call or a counterparty’s own signed act. See The RWA lifecycle.
Yes. Its issuer (for a tokenized deposit, the bank) mints it when an investor’s custodian asks, and burns it on withdrawal, on its own registry, as often as needed. In between, it pays for fund units in the same transaction as the units move. See The on-ledger payment leg.

A new asset

The issuer creates the asset on its registry. The venue records it under four eyes: how it is valued, who prices it, what backs it, and its policy. Then it admits investors. No contract is deployed. See Set up an asset.
Every asset runs on the same package of contracts, and the package you review is the package that runs. Every build checks the package’s identity against the recorded one, and each party’s node approves the package itself before acting on it. See Upgrades and package versions.

Operations and IT

They see the screens the venue builds on the API, or its systems integrator builds: NodeAsset is the engine and its API, and the demo shows a screen for each role. Each role reaches only its own calls. Operations, which also sets each asset up, approvers, risk and audit work the book; compliance freezes investors and asks for forced transfers and recoveries; IT reads health, the ledger connection and system status; an investor reads only its own holdings and statements. See Actors and roles.
The engine is a client of your own Canton node: it writes through the Ledger API and reads a projection of the ledger in PostgreSQL. Health reports the ledger connection, its latency and the projection’s lag. Control events go to signed webhooks and an event feed, and a monitoring role reads the verdicts without the book’s detail. See Monitoring.
Each party’s own node holds the contracts it is party to. NodeAsset keeps operations, approvals, events and reconciliation runs in its own database, inside your perimeter. Data moves through the API, signed webhooks, uploaded statements (the NAV, distribution lists, the register) and CSV or JSON exports. See Data and retention.
One OpenAPI document, served by every deployment, with each operation’s roles, its approval rule and its possible refusals. Each release ships it too, and a client for the API can be generated from it in any language. See the Quickstart and Build a client.

Controls and compliance

Yes. One access table names, for each action, who may ask for it and how many must approve. Each asset has a versioned policy: tightened at once, loosened only by two approvers after a day’s notice. Each investor’s credential shows the claims it carries and when they expire. See Roles and permissions.
Each investor sees only its own holdings, orders and statements. The issuer sees its asset’s register, and the issuer of the cash paying for an order sees only its own leg. The DA Registry’s operator sees the activity on its registry. See Who sees what.
Limits are rules in each asset’s policy: holder caps, countries, investor types, holding limits, fund size, lock-ups, daily limits and dealing windows, each checked before NodeAsset acts. The administrator’s NAV and distribution list arrive with no person in between, and a dealing cycle nets a day’s orders. Under a standing approval, a period’s distribution runs by itself on a clean book. See Compliance policies.
The controls a mapping cites are built in: four eyes with distinct people, two approvers to release a hold, reconciliation that stops the book, freezes, versioned policies and a full audit trail. Your auditor maps them to the framework you report against, starting from the control matrix: every risk, its control, owner, evidence and test, also as a CSV.
NodeAsset makes no claim about any jurisdiction’s rules. It provides neutral controls that a deployment configures: eligibility claims, policies, segregation of duties, freezes, forced transfer with consent, and records. Your adviser maps them to your rules, and every store can stay on your own infrastructure. See Mapping to your regulation.