Settlement
Multilateral netting engine for cross-border institutional settlement. Corridor-level obligation compression with cross-corridor aggregation, bilateral pre-netting, and residual carry-forward.
← Back to ProductsAll figures are from the Lagrange testnet on generated test flow, as at September 2026. Participant profiles are synthetic. No production traffic.
How a window settles, and who moves the money
Technical execution is atomic; settlement finality and the enforceability of the net are subject to per-corridor legal opinions.
How a window settles
Institutions submit obligations by API or ISO 20022 while a corridor's netting window is open. FX reference rates are fixed at window open so every obligation carries one accounting value; NETTA never executes FX. At window close the multilateral net positions are computed on the ledger. Netting is per corridor; positions offset across corridors only where they share a settlement currency.
Who moves the money
NETTA holds no funds and issues no payment. Each net instruction is executed by the participant's own licensed settlement institution over its existing rails, under a participation agreement and corridor rulebook, and confirmed back to the ledger. Ledger determination is final in seconds. Finality of funds occurs on the settlement institution's rail under that rail's legal framework; NETTA holds no statutory finality designation.
Currencies and settlement
Obligations in any currency are valued at reference rates fixed when they are recorded and netted on that basis. Each corridor settles its net positions in a single designated settlement currency or asset, named in the settlement institutions' standing instructions. Any conversion into that currency is sourced by the participant or its settlement institution on existing venues; the protocol executes no FX and carries no currency risk. First pilots settle one-for-one in the corridor's settlement currency with no FX leg.
If a participant cannot fund
A participant whose settlement institution has not committed to its net position by window close does not settle in that window. Its position is carried forward intact at face value; it is never failed and never left half-settled.
The remaining positions are then recomputed so that the set which does settle is fully backed. Recomputation can move a remaining participant’s position, and it can move it adversely, because removing a participant removes both what it owed and what it was owed. The protection is the cap: no participant is ever required to fund more than the amount its own settlement institution committed in advance for that window. If recomputation would carry a position beyond that amount, that participant does not settle either, and its position carries forward on the same terms.
There is no loss-sharing, no default fund and no member assessment. No participant is ever liable for another’s failure. Positions are fixed when the window settles: one computation, one outcome, no intermediate state and no choice about whose position fails first. A participant may record a contest against its own exclusion.
Status. Exercised on testnet with synthetic participants. No finality or netting-enforceability opinion has yet been obtained; opinions are commissioned per corridor before any live-funds pilot.
Who may participate
Access criteria
A corridor is defined by a currency pair, not drawn from a fixed list: the protocol nets across the ISO 4217 universe, and a corridor opens wherever a licensed settlement institution on each side will counter-attest. Participation is open to licensed financial institutions — banks, payment institutions and money-transfer operators licensed in the corridor's jurisdictions — and to settlement institutions willing to counter-attest net positions. Admission requires a verified licence, a confirmed sanctions and financial-crime programme, and data-protection compliance; each corridor opens only with participants on both sides and a counter-attesting settlement institution on each side. Admission and suspension decisions are taken under the corridor rulebook, with suspension available on regulatory order, participant default or sanctions event; exclusion from a settlement window is by objective, on-chain-recorded rule, and commercial disputes are resolved under the participation agreement. Full participation criteria are set out in the Participant Access Agreement, available to institutions under NDA.
Sanctions and financial crime
NETTA performs no customer due diligence and holds no customer relationship; KYC, AML and Travel Rule obligations sit with the licensed participants. Obligations are screened at admission against published sanctions lists and rejected before they enter a netting window; every screening outcome is recorded for participants and their supervisors.
Settlement engine capabilities
Exercised on the Lagrange testnet. 11 precompiles deployed at the consensus layer.
Multilateral Netting
Per-corridor multilateral netting with O(n) complexity. Configurable settlement windows with FX reference rates fixed at window open. ISO 20022 CBPR+ native obligation recording.
Cross-Corridor Netting
Second layer of netting across corridors sharing the same currency. Additional savings on residual net positions after per-corridor netting. Effect scales with every new corridor per currency.
Bilateral Pre-Netting
Per-pair bilateral position tracking at the settlement layer. A single transaction records sender debit, receiver credit and bilateral flow data. Basis for pacs.008 and pacs.009 settlement instruction generation.
Residual Carry-Forward
CHIPS-model carry-forward. Sub-threshold net positions carry to the next window, expanding the netting pool across windows for genuine compression improvement. Configurable per corridor.
Cryptographic Privacy
Homomorphic netting on committed values — amounts are never disclosed to the chain. Transparent proofs with no trusted setup. Distributed key custody. No single-party key, no trusted hardware.
Post-Quantum Authentication
ML-DSA (FIPS 204) signatures and ML-KEM (FIPS 203) key encapsulation, hybrid with ECDSA for migration. Deployed on testnet.
Per-corridor isolation on a shared chain
Access Control
Per-corridor role-based access control with a tiered supervisory view — from full supervisory visibility to aggregate-only statistics.
Corridor Isolation
All Settlement Computer products coexist on one chain with isolated corridor configurations.
- Idempotent corridor creation
- Per-corridor configuration limits
- Per-corridor privacy configuration
- Independent settlement windows
- Jurisdiction-specific compliance rules
Participant-sovereign data delegation
Participants control who sees their data. Delegation is granular, time-limited, revocable, and produces an immutable on-chain audit trail.
Delegation Model
- Grant view access — scoped, with expiry, revocable
- Revoke view access — instant, on-chain
- On-chain audit trail of every delegated access
Designed For
- Regulators and central bank supervisors
- External auditors and compliance officers
- Correspondent banking partners
- Insurers and credit assessors
- Legal and dispute resolution
Tiered view key model
Five tiers of data access, from full supervisory visibility to aggregate-only. Each tier uses distinct cryptographic key material.
ISO 20022 CBPR+ validated
Native generation of pacs.008 and pacs.009 at the settlement layer; pain.001, pacs.002, camt.053 and camt.054 via the institutional API. CBPR+ Level 1 (schema) and Level 2 (usage guideline) validation passed.
Reference FX rates
All Settlement Computer products use institutional FX reference rates fixed at netting window open, ensuring no execution slippage and no ordering advantage. The protocol executes no FX.
Patent-pending
Twenty US provisional patent applications on file: sixteen held by FiatRails Foundation Ltd; four covering the Qedis privacy and post-quantum runtime, owned by Digitalyze Labs Ltd and licensed perpetually to the group. Documentation for qualified institutions under NDA.
What exists, and what a participant receives
The settlement model is written down. These are the instruments and analyses that sit behind it, available to institutions and their supervisors under a non-disclosure agreement. Participant-facing instruments are released in a form prepared for counterparty review.
Legal architecture
- Multilateral versus bilateral netting — legal memorandum
- Legal architecture executive summary
- Legal architecture master matrix, jurisdiction by jurisdiction
- Default management and recovery waterfall
- Cross-border settlement regulatory architecture brief
- Legal-opinion scoping pack
- Islamic-finance structuring memorandum
Operational and contractual
- Corridor rulebook — the constitutional instrument of a corridor
- Participant access agreement
- Master counter-attestation agreement
- Participant-default and recovery framework
- Default testing policy and drill catalogue
- Operational resilience and business continuity plan
- Recovery and orderly wind-down plan
- PFMI conformance self-assessment, all 24 principles
- Pilot entry conditions, gate analysis and disclosure pack
- Obligation matrix and proposition register
The pack is versioned and carries a changelog. It is legally un-opined: opinions are scoped and commissioned per corridor before any live-funds pilot, and that position is stated on every document rather than hidden.
Request an institutional briefing
Controlled pilots in 2026–27 for banks, payment institutions and market infrastructures. Technical documentation and NDA available to qualified participants.
Request Briefing