Live on Testnet

Settlement

Multilateral netting engine for cross-border institutional settlement. Corridor-level obligation compression with cross-corridor aggregation, bilateral pre-netting, and residual carry-forward.

← Back to Products
11
corridors exercised on testnet
Up to 95%
multilateral compression, testnet; depends on corridor and flow mix

All figures are from the Lagrange testnet on generated test flow, as at September 2026. Participant profiles are synthetic. No production traffic.

How a window settles, and who moves the money

Technical execution is atomic; settlement finality and the enforceability of the net are subject to per-corridor legal opinions.

How a window settles

Institutions submit obligations by API or ISO 20022 while a corridor's netting window is open. FX reference rates are fixed at window open so every obligation carries one accounting value; NETTA never executes FX. At window close the multilateral net positions are computed on the ledger. Netting is per corridor; positions offset across corridors only where they share a settlement currency.

Who moves the money

NETTA holds no funds and issues no payment. Each net instruction is executed by the participant's own licensed settlement institution over its existing rails, under a participation agreement and corridor rulebook, and confirmed back to the ledger. Ledger determination is final in seconds. Finality of funds occurs on the settlement institution's rail under that rail's legal framework; NETTA holds no statutory finality designation.

Currencies and settlement

Obligations in any currency are valued at reference rates fixed when they are recorded and netted on that basis. Each corridor settles its net positions in a single designated settlement currency or asset, named in the settlement institutions' standing instructions. Any conversion into that currency is sourced by the participant or its settlement institution on existing venues; the protocol executes no FX and carries no currency risk. First pilots settle one-for-one in the corridor's settlement currency with no FX leg.

If a participant cannot fund

A participant whose settlement institution has not committed to its net position by window close does not settle in that window. Its position is carried forward intact at face value; it is never failed and never left half-settled.

The remaining positions are then recomputed so that the set which does settle is fully backed. Recomputation can move a remaining participant’s position, and it can move it adversely, because removing a participant removes both what it owed and what it was owed. The protection is the cap: no participant is ever required to fund more than the amount its own settlement institution committed in advance for that window. If recomputation would carry a position beyond that amount, that participant does not settle either, and its position carries forward on the same terms.

There is no loss-sharing, no default fund and no member assessment. No participant is ever liable for another’s failure. Positions are fixed when the window settles: one computation, one outcome, no intermediate state and no choice about whose position fails first. A participant may record a contest against its own exclusion.

Status. Exercised on testnet with synthetic participants. No finality or netting-enforceability opinion has yet been obtained; opinions are commissioned per corridor before any live-funds pilot.

Who may participate

Access criteria

A corridor is defined by a currency pair, not drawn from a fixed list: the protocol nets across the ISO 4217 universe, and a corridor opens wherever a licensed settlement institution on each side will counter-attest. Participation is open to licensed financial institutions — banks, payment institutions and money-transfer operators licensed in the corridor's jurisdictions — and to settlement institutions willing to counter-attest net positions. Admission requires a verified licence, a confirmed sanctions and financial-crime programme, and data-protection compliance; each corridor opens only with participants on both sides and a counter-attesting settlement institution on each side. Admission and suspension decisions are taken under the corridor rulebook, with suspension available on regulatory order, participant default or sanctions event; exclusion from a settlement window is by objective, on-chain-recorded rule, and commercial disputes are resolved under the participation agreement. Full participation criteria are set out in the Participant Access Agreement, available to institutions under NDA.

Sanctions and financial crime

NETTA performs no customer due diligence and holds no customer relationship; KYC, AML and Travel Rule obligations sit with the licensed participants. Obligations are screened at admission against published sanctions lists and rejected before they enter a netting window; every screening outcome is recorded for participants and their supervisors.

Settlement engine capabilities

Exercised on the Lagrange testnet. 11 precompiles deployed at the consensus layer.

01

Multilateral Netting

Per-corridor multilateral netting with O(n) complexity. Configurable settlement windows with FX reference rates fixed at window open. ISO 20022 CBPR+ native obligation recording.

02

Cross-Corridor Netting

Second layer of netting across corridors sharing the same currency. Additional savings on residual net positions after per-corridor netting. Effect scales with every new corridor per currency.

03

Bilateral Pre-Netting

Per-pair bilateral position tracking at the settlement layer. A single transaction records sender debit, receiver credit and bilateral flow data. Basis for pacs.008 and pacs.009 settlement instruction generation.

04

Residual Carry-Forward

CHIPS-model carry-forward. Sub-threshold net positions carry to the next window, expanding the netting pool across windows for genuine compression improvement. Configurable per corridor.

05

Cryptographic Privacy

Homomorphic netting on committed values — amounts are never disclosed to the chain. Transparent proofs with no trusted setup. Distributed key custody. No single-party key, no trusted hardware.

06

Post-Quantum Authentication

ML-DSA (FIPS 204) signatures and ML-KEM (FIPS 203) key encapsulation, hybrid with ECDSA for migration. Deployed on testnet.

Per-corridor isolation on a shared chain

Access Control

Per-corridor role-based access control with a tiered supervisory view — from full supervisory visibility to aggregate-only statistics.

Corridor Isolation

All Settlement Computer products coexist on one chain with isolated corridor configurations.

  • Idempotent corridor creation
  • Per-corridor configuration limits
  • Per-corridor privacy configuration
  • Independent settlement windows
  • Jurisdiction-specific compliance rules

Participant-sovereign data delegation

Participants control who sees their data. Delegation is granular, time-limited, revocable, and produces an immutable on-chain audit trail.

Delegation Model

  • Grant view access — scoped, with expiry, revocable
  • Revoke view access — instant, on-chain
  • On-chain audit trail of every delegated access

Designed For

  • Regulators and central bank supervisors
  • External auditors and compliance officers
  • Correspondent banking partners
  • Insurers and credit assessors
  • Legal and dispute resolution

Tiered view key model

Five tiers of data access, from full supervisory visibility to aggregate-only. Each tier uses distinct cryptographic key material.

Governance
Full supervisory visibility
Admin
Corridor key — all obligations
Participant
Own obligations + net positions
Delegate
Scoped, time-limited, revocable
Observer
Aggregate statistics only

ISO 20022 CBPR+ validated

Native generation of pacs.008 and pacs.009 at the settlement layer; pain.001, pacs.002, camt.053 and camt.054 via the institutional API. CBPR+ Level 1 (schema) and Level 2 (usage guideline) validation passed.

pain.001 pacs.008 pacs.009 pacs.002 camt.054 camt.053

Reference FX rates

All Settlement Computer products use institutional FX reference rates fixed at netting window open, ensuring no execution slippage and no ordering advantage. The protocol executes no FX.

Patent-pending

Twenty US provisional patent applications on file: sixteen held by FiatRails Foundation Ltd; four covering the Qedis privacy and post-quantum runtime, owned by Digitalyze Labs Ltd and licensed perpetually to the group. Documentation for qualified institutions under NDA.

What exists, and what a participant receives

The settlement model is written down. These are the instruments and analyses that sit behind it, available to institutions and their supervisors under a non-disclosure agreement. Participant-facing instruments are released in a form prepared for counterparty review.

Legal architecture

  • Multilateral versus bilateral netting — legal memorandum
  • Legal architecture executive summary
  • Legal architecture master matrix, jurisdiction by jurisdiction
  • Default management and recovery waterfall
  • Cross-border settlement regulatory architecture brief
  • Legal-opinion scoping pack
  • Islamic-finance structuring memorandum

Operational and contractual

  • Corridor rulebook — the constitutional instrument of a corridor
  • Participant access agreement
  • Master counter-attestation agreement
  • Participant-default and recovery framework
  • Default testing policy and drill catalogue
  • Operational resilience and business continuity plan
  • Recovery and orderly wind-down plan
  • PFMI conformance self-assessment, all 24 principles
  • Pilot entry conditions, gate analysis and disclosure pack
  • Obligation matrix and proposition register

The pack is versioned and carries a changelog. It is legally un-opined: opinions are scoped and commissioned per corridor before any live-funds pilot, and that position is stated on every document rather than hidden.

Request an institutional briefing

Controlled pilots in 2026–27 for banks, payment institutions and market infrastructures. Technical documentation and NDA available to qualified participants.

Request Briefing