Atomic multi-party DvP
ExecuteSettlement exercises all four settlement legs inside a single Canton transaction. Either every leg moves or none do — there is no partial state, no pre-funding window, and no moment where one party has delivered and another has not. Counterparty risk is eliminated, not merely mitigated.
Approximating this on a transparent ledger means escrow contracts, hash-time-locked swaps, or an external coordinator — each of which reintroduces a timing gap and a new trust assumption. On Canton, atomic delivery-versus-payment across independent parties is the base settlement model, so a single transaction covers all four legs — they commit together or not at all, leaving nothing to reconcile between them. Each party to the trade verifies the outcome from its own participant node rather than trusting a report: the settling transaction creates a settlement record that every counterparty observes.
Sub-transaction privacy
Canton enforces privacy at the protocol level: each participant’s node stores only the contracts it is a party to. There is no shared global state to read, no way to enumerate other participants, and no shared transaction history. This is what lets a market maker price an anonymized RFQ — currency pair, amount, and expiry only — and win a trade without receiving the sender’s or receiver’s identity. The identity data is not masked at the application layer; through quoting it is simply not transmitted to the market maker’s node. Approximating this on a transparent chain requires zero-knowledge proofs plus off-chain coordination plus new trust assumptions. On Canton it is a base primitive. The primitive has a stated edge. Settlement is one atomic transaction co-signed by four parties including the market maker, so the settled order is disclosed to every co-signer — and Canton’s confirmation metadata makes the participating-party set visible to the operators of the synchronizer. Both are written down in the Privacy Model; neither touches amounts or rates.Operator-less, minimal-trust authorization
Settlement requires cryptographic co-signatures from the independent parties. No single party — including the network operator — can move assets unilaterally. The operator coordinates the four-party settlement and co-submits the transaction; it never custodies tokens, sets FX rates, or acts as counterparty. Authorization is split by design across the four settling parties: no one of them can move assets alone, and the co-signatures are enforced cryptographically by the settlement protocol rather than by internal procedure — a rogue actor cannot back-date or reconstruct one. On the sending side the institution itself holds no ledger key; its staff act through the custodian’s console, and every such action is attributed to the authenticated individual in the custodian’s append-only audit record.Built for institutional finance
Canton is the substrate institutional finance already runs tokenized settlement on. Representative deployments of the same multi-party-atomic-settlement model:- Digital Asset × DTCC Project Ion — US securities clearing and settlement
- Goldman Sachs DAP — tokenized bond issuance
- HSBC Orion — tokenized gold
- Deutsche Börse Clearstream D7 — tokenized securities
- Progmat (Mitsubishi UFJ Trust / Datachain) — Japanese stablecoin settlement platform
FXOrder itself rather than merely observing and signing off out-of-band. That cryptographically enforces custodian authorization of every intent, which is the property a cross-border settlement rail between independently-owned custodians needs.