Does the total reach the amount we require?
Each row is a custodian's figure for the subject. In this demo one demonstration source reports every row, so the sum shows no independence between custodians.
VTE · Veridex Threshold Evidence
VTE answers one narrow question about a private position on Canton, and records the answer and its evidence on the ledger.
Harbour Point Fund II keeps its money with Northbridge Custody Bank. A lender about to release funds needs to know the fund really has enough behind it. Today that leaves two bad choices.
Northbridge asks a shared ledger one narrow question, and the ledger answers it.
Does this account hold at least $10 million?
They are four shapes of answer that one mechanism produces about one attested position, so whoever is asking gets the shape they need. All four describe the same case, and the mechanism checks that they share subject, scope, epoch, governance parties and book. It compares values across modes only in a strict mode, which the full case does not use.
Pick a mode below. A real answer comes back in about a minute, from the ledger, not from this page.
One case, asked four ways. The only thing that changes is how much crosses. The grid shows what the asking party sees. In VTE Match the value never reaches the ledger. The ledger records one yes-or-no fact (above the lowest band or not) and the demo service names the band. In VTE Reveal the governance parties see the total and a random split of it, and the requesting party receives only the total. In VTE Policy and VTE Trade Check the governance parties of the ledger see the values.
| Exact total | Category mix | Per-source split | Pass / fail | Band |
|---|
The asking party sees the answer, not the account.
Six fields, all optional. They label the evidence; they do not change what the ledger is asked.
Which parties a deployment accepts as an attesting source is decided when that deployment is configured; the mechanism shown here does not itself check whether a source is a custodian or the subject. All names and amounts on this page are fictional example data.
Each row is a custodian's figure for the subject. In this demo one demonstration source reports every row, so the sum shows no independence between custodians.
Same VTE fact in a demo semt.002-shaped rendering (an institutional mapping preview). It is not validated against the real XSD and it is not an ISO 20022 export.
In this demo the balance is sent to the integration API, and the governance parties of the ledger can see it. The record shared with the counterparty is a pass/fail and a salted digest of the value.
In this demo the balance goes no further than the band calculation. What is sent onward is a tier index, not the value.
This step does not exist if the four modes are used separately.
Five more Daml choices layered on the case above. They are not four more answer shapes; they are extra checks and records around the four above.
Each card below calls its own real endpoint against the same Canton participant. Most need the case above to have run at least VTE Reveal and Compose first.
A composed package can sit unused while the subject's books move on. This re-checks the package against the subject's CURRENT book commitment, right now, and issues a time-boxed receipt, instead of a third party trusting a package that may already be stale.
Several signers is not the same as several separate controllers; one operator can hold every key. This attests whether the parties behind a registry really sit on distinct topology roots, or share one, using the same identifier Canton itself uses to tell participants apart.
Honest expectation: this demo runs every party on ONE shared participant, so a strict check here is expected to reject: that is the mechanism correctly detecting this deployment's own single-root Sybil residue, not a bug.
Composing a package is the step that travels to a third party. This gives it a budget the composer must claim a slot from before it can compose.
The rule says the decision to rely on this evidence stays with the client, never VERIDEX. Until today that lived only in a string and a contract clause. This is a receipt signed ONLY by the client (VERIDEX cannot even gate its creation) recording that decision, under the client's own responsibility.
What each mode discloses has lived in code comments and an evidence package, never in something a third party could cite. This publishes it on the ledger, co-signed by governance and versioned, the fixed reference a real leak-vs-declared comparison needs to exist against.