Protocol

No principal risk

The KeyStone Protocol coordinates delivery-versus-payment between institutions on separate ledgers, applies your policy before anything moves, and anchors the result where anyone can check it. A ledger here is any book that can commit, public or private. Assets never leave the custodian already holding them, and no leg ever rests anywhere except where it started or where it ended.

Commercials

Free to join.Capture new revenue.

Give your clients access to more products and secure capability, branded as yours, and capture new revenue on the flow that would otherwise route around you for want of access.

Free to integrate

Unlock new capabilities for your clients while your development budget goes to client experience rather than to plumbing.

Maintain billing relationship

Fees are borne by the transacting parties at settlement finality, paired with a white labelled client specific receipt and audit bundle.

Your margin on the flow

Set your own margin on the flow you route, earned under your own name and funded automatically at trade closure.

Mechanism

How a settlement happens

  1. 01

    Separate ledgers

    Each institution holds its leg where it already holds it.None of them can reach the others.

  2. 02

    One instruction

    Each side states its own leg and the terms.No side is shown another side's book.

  3. 03

    Your policy runs first

    Permissioned assets, screening and eligibility are checked before anything is committed.

  4. 04

    All legs committed

    Each leg is held on its own ledger.Nothing has moved, and every leg can still be released.

  5. 05

    All legs, or none

    They cross in the same instant.There is no moment in which one side has delivered and the others have not.

  6. 06

    Anchored

    A proof is struck that anyone can check against every ledger involved, without asking us.

  7. 07

    And it is multilateral

    Many legs, many parties, many ledgers.Still one instruction, and still one movement.

Ledgers

A ledger is any book that can commit

Not only public networks. Most of the books that will matter to this market are being built by the market itself, and the protocol treats every one of them the same way. It does not care what a ledger is built on, only that it can hold a leg and commit it.

/ Public networks

Ethereum, Solana and their kind, permissionless and open to anyone.

/ Consortium ledgers

Canton, Besu and member-run networks operated by the firms that use them.

/ Depository ledgers

A central securities depository's own book of record, run under its own rules.

/ Clearing house ledgers

A clearing house's own book, where positions and margin already live.

/ Exchange ledgers

An exchange's own issuance and settlement book for the instruments it lists.

/ Institutional ledgers

A bank's or a provider's internal book, private and never exposed.

Atomic Settlement Engine

All legs commit together or none commits. There is no window in which one side has delivered and the others have not.

Principal risk is not reduced here. It is absent, because the state in which it exists is never reachable.

This is the risk CLS was built to take out of foreign exchange. Tokenization is reintroducing it, in every asset class at once.

Anchored Settlement

Every settlement writes a proof that can be checked against the ledgers involved, by anyone, without asking us and without trusting us.

Finality is evidenced rather than asserted, which is what makes it usable in a dispute.

Compliance and Screening

Your rules run before anything moves: permissioned assets, counterparty screening, jurisdiction and eligibility.

A settlement that would fail your policy never reaches the engine, so there is nothing to unwind.

Perimeter

Between everyone, rival to no one.

Never custodial

Assets stay with the custodian that already holds them. There is no KeyStone wallet, no omnibus account, and nothing for your client to fund with us.

Never a counterparty

We are not on either side of the trade. There is no KeyStone exposure for your risk team to price, and no limit to set against us.

Never a bridge

Nothing is wrapped or re-issued. Each leg settles natively on the ledger it already lives on.

Never in the flow

No value passes through KeyStone at any point in a settlement.

Never in your book

The instruction carries what each side must know and nothing more.

Neutrality

Why you cannot build this yourselves

Every provider in this market can build settlement. None of them can build this one, and the reason is structural rather than technical.

Standing between two institutions means seeing both sides of a trade that neither wants the other to see, and holding a position neither wants a competitor to hold. A provider who builds it becomes a counterparty inside its rivals' flow, and its rivals will not route through it. No contract and no internal wall changes that, because the objection is to the position itself.

KeyStone can occupy that position for exactly one reason: it cannot use it. It holds nothing, matches nothing, reads no book, and has no product to sell into the flow it coordinates. It cannot compete with the providers it connects, which is what lets the protocol coordinate settlement between firms that cannot settle with each other.

Neutrality here is not a policy that a future commercial team could revise. It is the precondition, and the architecture is what enforces it.

Integration

An invisible connection

Request participant access

The protocol sits inside what you already run. Your clients settle in your product, on your screens, under your terms. There is no bilateral onboarding to every counterparty, no second interface, and no account to pre-fund.

What changes for them is that reaching beyond your boundary stops costing them. What changes for you is that the revenue which used to leave, stays.

By design

Not by promise.