TEST DEPLOYMENT - all 4 modes submit live through an integration API to a Canton participant operated by the VTE team. Synthetic data, demonstration sources. Not a pilot, not a production system.
VTE - Veridex Threshold Evidence Team-operated Canton participant
checking backend…

VTE - Veridex Threshold Evidence

One position. Four questions. Each answer is shaped to its question.

One mechanism, four answer shapes, one cross-checked package.

Evidence only No custody Does not settle No legal conclusion
How the mechanism works
  1. Held by the custodian The position The fund's balance sits with its custodian.
  2. Held by the custodian The question Does it reach the amount asked for?
  3. Held by the custodian The ledger checks Canton tests the attested amount.
  4. Goes to the counterparty The answer Yes or no, checkable on the ledger.
Read the full explanation

What you're actually looking at

  1. The problem today

    Harbour Point Fund II keeps its money with Northbridge Custody Bank. A lender about to release funds needs to know the fund really has enough behind it. Today that leaves two bad choices.

    Hand over the whole statement Reveals everything, including what nobody asked about.
    Take the fund's word for it Verifies nothing.
  2. The third option

    Northbridge asks a shared ledger one narrow question, and the ledger answers it.

    Does this account hold at least $10 million?

    • The asking party gets the answer, not the account.
    • The lender does not have to take Northbridge's word for it: it can read the recorded answer on the ledger itself. The ledger records what was attested and checks it for consistency. It does not verify that the figure is true.
  3. Four modes, not four products

    They are four shapes of answer that one mechanism produces about one attested position, so whoever is asking gets the shape they need. Because all four describe the same case, the mechanism can compare them against each other and refuse to assemble a set that contradicts itself.

  4. Try it

    Pick a mode below. A real answer comes back in about a minute, from the ledger, not from this page.

What each answer gives away

One case, asked four ways. The only thing that changes is how much crosses. The grid shows what the asking party sees. In VTE Policy and VTE Trade Check the governance parties of the ledger also see the values; only VTE Reveal and VTE Match hide values cryptographically.

What each answer gives away
Exact total Category mix Per-source split Pass / fail Band

The asking party sees the answer, not the account.

Each button opens a fresh case, runs the four ceremonies against the Canton participant in order, and composes the result.

Step 1 of 3

Case

Six fields, all optional. They label the evidence; they do not change what the ledger is asked.

Which parties a deployment accepts as an attesting source is decided when that deployment is configured; the mechanism shown here does not itself check whether a source is a custodian or the subject. All names and amounts on this page are fictional example data.

Step 2 of 3

The same case, asked four ways

The position
Who holds it -
What it is made of -

Does the total reach the amount we require?

Each row is a custodian reporting what it holds for the subject. Two custodians reporting separately is the point: the total exists without either of them, or the subject, being the sole word on it.

-
disclosed total (factTotal)
view raw response
not submitted
LIVE - real Canton participant

What is that total made of?

-
disclosed total (grandTotal)

Same VTE fact in a demo semt.002-shaped rendering (an institutional mapping preview). It is not validated against the real XSD and it is not an ISO 20022 export.

Demo semt.002-shaped rendering, not validated against the XSD

              
view raw response
not submitted
LIVE - real Canton participant

Is there enough behind this trade to proceed?

In this demo the balance is sent to the integration API, and the governance parties of the ledger can see it. The record shared with the counterparty is a pass/fail and a salted digest of the value.

-
view raw response
not submitted
LIVE - real Canton participant

Which band does it sit in?

In this demo the balance goes no further than the band calculation. What is sent onward is a tier index, not the value.

-
view raw response
not submitted
LIVE - real Canton participant
Step 3 of 3

Cross-mode composite result

This step does not exist if the four modes are used separately.

Strict value coherence
    view raw response
    New, 2026-08-26

    Six mechanisms layered on the case above

    Six more Daml choices layered on the case above. They are not four more answer shapes; they are what makes the four above safer to rely on.

    What each one adds, and what to run first
    • P1Re-checks a composed package against the subject's book as it stands now, not as it stood when the package was made.
    • P2Tests whether "several signers" really are several parties, or one controller holding every key.
    • P3Meters how many evidence packages get issued, so they cannot be minted without limit.
    • P4Gives the client its own record of its own decision, on the same ledger.
    • P5Publishes what each mode discloses, so the leak is stated rather than inferred.
    • P6Reserves a slot for a future cryptographic proof, without claiming one today.

    Each card below calls its own real endpoint against the same Canton participant. Most need the case above to have run at least VTE Reveal and Compose first.

    P1

    Revalidate at reliance

    P1
    not submitted

    A composed package can sit unused while the subject's books move on. This re-checks the package against the subject's CURRENT book commitment, right now, and issues a time-boxed receipt - instead of a third party trusting a package that may already be stale.

    view raw response
    P2

    Topology diversity

    P2
    not submitted

    Several signers is not the same as several separate controllers - one operator can hold every key. This attests whether the parties behind a registry really sit on distinct topology roots, or share one, using the same identifier Canton itself uses to tell participants apart.

    Honest expectation: this demo runs every party on ONE shared participant, so a strict check here is expected to reject - that is the mechanism correctly detecting this deployment's own single-root Sybil residue, not a bug.

    Strict (reject if namespaces collide)
    Off checks and records the namespaces without rejecting; on enforces distinctness.
    view raw response
    P3

    Evidence issuance budget

    P3
    not submitted

    Composing a package is the step that travels to a third party, and until today it was the only one of the three provisioning surfaces with no cap. This gives it one: a budget the composer must claim a slot from before it can compose, same pattern already audited twice for VTE Match and VTE Trade Check.

    Strict value coherence
    view raw response
    P4

    Client reliance decision

    P4
    not submitted

    The rule says the decision to rely on this evidence stays with the client, never VERIDEX. Until today that lived only in a string and a contract clause. This is a receipt signed ONLY by the client (VERIDEX cannot even gate its creation) recording that decision, under the client's own responsibility.

    view raw response
    P5

    Leak baseline declaration

    P5
    not submitted

    What each mode discloses has lived in code comments and audit PDFs, never in something a third party could cite. This publishes it on the ledger, co-signed by governance and versioned - the fixed reference a real leak-vs-declared comparison needs to exist against.

    view raw response
    P6

    Proof-binding reservation

    P6
    not submitted

    VTE Reveal and VTE Policy are attested, not proven - the real cryptographic proof is future work. This reserves the exact field names a future cryptographic verifier would bind to, on a real fact, so nothing needs to migrate if such a proof is ever added.

    Honest limit: proofSystemId stays "ATTESTED_SECP256K1_QUORUM" today - this is a nomenclature reservation, not a claim that a proof exists yet.

    view raw response