The words on this site, in plain English.
Every term below is linked from the page where it first appears. Where a word has a precise meaning in the rules, the rules govern: see the methodology and the documents.
Funds and markets
- ETF / ETP
- Exchange-traded fund / exchange-traded product. A fund whose shares trade like a stock, and whose share count grows or shrinks as authorised participants create and redeem shares.
- Basket
- The set of assets, in fixed amounts, that makes up one unit of a fund — for example 0.5 cBTC and 8 cETH per share. An authorised participant delivers the basket to get shares.
- AP (authorised participant)
- A firm allowed to deal directly with the fund: it delivers the basket and receives new shares (creation), or hands shares back and receives the basket (redemption). Its buying and selling is what keeps a fund’s market price close to its NAV.
- Creation and redemption (in kind)
- Making new fund shares by delivering the basket itself rather than cash (creation), and the reverse (redemption). “In kind” means assets move, not cash.
- T+1
- Settlement on the next business day after the trade. The US standard settlement cycle since 28 May 2024; ETF creations settle this way through NSCC and DTC.
- Atomic settlement
- Both sides of a deal move in one transaction, or neither does. There is no moment when one party has delivered and the other has not, so there is no principal settlement risk between the two legs. The ledger records still have to agree with the custodian’s and the register’s, which is what the reconciliation seats check.
- Transfer agent
- The firm that keeps a fund’s share register — who owns how many shares — and processes creation and redemption orders. In the US it must be registered.
- Fund administrator
- The firm that strikes the fund’s daily NAV, keeps its books and accrues its fees.
- Custodian
- The firm (or, for some tokens, the protocol’s own contracts) that actually holds the assets backing a token or a fund.
- Index provider / benchmark administrator
- The firm that publishes the official price a fund or contract settles against, under published rules — for example CF Benchmarks or ICE. In the UK and EU, administering a benchmark is a licensed activity; ETP Foundry is not licensed.
- bp (basis point) and AUM
- One basis point is 0.01%. AUM is assets under management, the total size of a fund.
The price and the committee
- Fixing
- One official price, struck once at a declared time, that contracts and funds settle against. An asset can trade at thousands of prices a day; a contract can reference only one. The LBMA Gold Price and the ECB’s daily euro reference rates are fixings.
- Strike
- The moment a fixing describes (“struck”): once a day for crypto; the home market’s close for anything with a stock in it. The observation window is the 60 minutes ending at the strike. Crypto strike time: 16:00 London, adopted 28 September 2026 (15:00 UTC in British Summer Time, 16:00 UTC in winter).
- Committee
- The parties who sign a fixing for one asset: typically its issuer, its custodian, a lender that takes it as collateral, a venue where it trades, and for a fund, its transfer agent. Chosen because they want different answers.
- Seat
- One member’s place on a committee, with a role (venue, lender, issuer, custodian, transfer agent) that decides which numbers it submits. A seat is issued by ETP Foundry to a named person; nobody can self-register.
- K of N
- N is the number of seats on a committee; K is how many must sign for the price to exist. “3 of 5” means three of the five members signed. K is at least 2, no single interest may reach K alone, and ETP Foundry is never a member.
- Submit / confirm / refuse
- What a member does each day: submit the numbers its seat holds (a venue’s trades, a lender’s mark, an issuer’s reserve snapshot, a reconciliation) and confirm the fixing with them. A submission that fails its seat’s rule is recorded as a refusal, with the numbers. A member is never asked for its opinion of the price.
- VWAP (volume-weighted average price)
- The average price of a venue’s trades in the window, each weighted by its size: Σ(price × quantity) / Σ quantity. Each venue seat submits its window VWAP, with the trade count, volume, low, high and any halt time.
- Volume-weighted median (VWM)
- How the venues’ VWAPs become one price. Sort them from low to high and take the first at which the running total of volume reaches half of all volume. It is one venue’s reported VWAP (at an exact half, the midpoint of two, under the specified tie rule), and one venue printing a distorted price cannot drag it the way it drags an average. SOFR and the CME CF Bitcoin Reference Rate use volume-weighted medians too.
- Outlier
- With three or more eligible venues, a venue whose VWAP is more than 300 bp from the simple (unweighted) median of the venues’ VWAPs, so the largest venue cannot become the yardstick it is tested against (built). It is excluded from the price and named on the record, and the median is recomputed without it. No remaining venue may then carry more than 50% of the weight (built). Modelled on CF Benchmarks’ rule, which uses 5% for the BRR; ours is tighter because a thin venue is cheaper to move.
- IPV (independent price verification)
- The bank control in which a price is checked against a second, separately sourced number, by someone who does not benefit from it, against a threshold set in advance. The lender seat’s check is modelled on it: it submits the mark its own risk system uses, and the fixing publishes only within the tolerance the lender declared beforehand (25 bp by default). This is a risk-side challenge: the lender is the seat that loses money if the value is too high. “Independent” means independent of whoever benefits, not necessarily a separate source of information; see basis check.
- Basis check
- What the lender’s check amounts to when its mark is derived from a public
price for the underlying, for example the BTC reference rate × a factor for a wrapped-BTC token. It then caps
how far the token’s fixing may sit from that public price (its basis); it is not an independent valuation of
the token. The lender declares which it is (
markSource, andmarkFromPublicReference, both required), and every fixing discloses it. Only a mark from the lender’s own trades or liquidations in the token is independent price evidence. - Peg-integrity gate
- The issuer seat’s role. A wrapped token is worth its underlying only while reserves cover supply and holders can redeem, so the issuer signs its reserves and supply as of a stated time, with the evidence, and whether redemptions are open and mint/burn is paused. If any of that fails, nothing publishes. The gate can stop the price; it can never move it.
- Input level
- What data a value came from: (a) venues’ trades, (b) venues’ executable quotes, (c) a reference price × the par factor, (d) the prior value carried forward. Published next to the tier.
- Tier
- Who stood behind a published value (Methodology §6.4). 0 not attested
(computed by the desk; includes a committee fixing held back because a condition is unmet) · 1
committee fixing, attested by K of N · 2 committee fixing after escalation ·
3 fallback: reference × par, not a committee price, and only with a licensed reference (none today)
· 4 the prior value, carried forward and flagged · 5
NO FIXING, a gap published as a gap. Today every value is tier 0, and no exchange-derived value is published at any tier. - Indicative value
- A value no party attested: unsigned, tier 0, binding on nobody. That is the only meaning of “indicative” here. No indicative value built from exchange prices is published: none is licensed for publication. Not to be confused with an OFF-HOURS SIGNED fixing.
- OFF-HOURS SIGNED fixing
- A value struck at a fixed off-hours time — 00:00, 08:00
and 16:00 UTC, every day, weekends and holidays included — signed K of N (at least one signature a venue’s)
and published with a data-quality band, label
OFFHOURS. Once attested, it is for margin, liquidation, health factors and collateral haircuts on assets that trade 24/7 while their home market is shut, such as tokenised stocks; until the conditions for any value above tier 0 hold, it is published at tier 0 labelledpilot — not attested, and the licence forbids its use for liquidation. It is never a NAV, and creation and redemption never settle against it; they wait for the next OFFICIAL fixing. A wrong one is never restated: it is corrected by a new, linked record. Specified in methodology §3A; not built. - Data-quality band
- The published uncertainty around an OFF-HOURS SIGNED fixing, written as the value
± b. It widens with the time since the last hard information (the home market, futures, an overnight
session), with disagreement between inputs, and with the token’s bid–ask spread. In the methodology’s
worked example it is about 21 bp on a weeknight with futures trading and about 114 bp on a Sunday morning with futures
closed (illustrative; that Sunday example is itself
NO FIXINGunder the rules as built). The band is not yet calibrated: at z = 1 its nominal coverage would be about 68% if errors were normal, which has never been measured. z = 2 (about 95% nominal) is recommended for haircuts, and a back-test of at least 12 months must precede any attested off-hours fixing. The band never widens a lender’s tolerance. Above 1,000 bp the result is NO FIXING. - NO FIXING
- The published result when a fixing cannot be made honestly: fewer than two live inputs of distinct signal types (token trades count as one type), two inputs that disagree by more than 5%, a band wider than its limit, fewer than K signatures by the cut-off, a halted underlying, a failed issuer gate, or a corporate action whose terms are not final. It says why, and the last good value stays visible with its age. Nothing is guessed, and there is no fallback value.
- EXCEPTIONAL
- A flag on a value that moved more than 10% from the previous one. The value is
published, every signer and licensee is notified, and each consumer decides how to treat it. A real move is never
suppressed. It has no other meaning: a missed attestation or an outage is
NO FIXING, and a chain event such as a fork or a de-peg is flaggedEVENT-<type>. - Par factor
- For a wrapped token such as cBTC: how much the wrapper is worth relative to the asset it wraps (1.0 means at par). A reference price multiplied by the par factor is the fallback (input level c) when no venue traded; it requires a licensed reference, of which there is none today, so it is not published. With venue trades, the price comes from them.
- Proof of reserve
- A statement, from the issuer’s attestors or verifiable on-chain, that the assets backing a token exist and cover its supply. It is point-in-time and covers assets, not liabilities. The issuer seat cites it as the evidence for its signed reserve snapshot, which must be under 24 hours old by default.
- Restatement
- A public correction of a wrong fixing. It needs the same K of N as the original; the original stays on the record with the correction pointing back at it.
Schedule at a glance: three layers, 24/7
A tokenised stock such as SPYx trades around the clock, but the NYSE is open about 32.5 of the 168 hours in a week, and a lender still needs a number at 02:00 on a Sunday. Every value ETP Foundry publishes carries one of three labels (methodology §3A.0):
| Layer | When | Who stands behind it | Use it for | Never use it for | Status |
|---|---|---|---|---|---|
1. LIVE indicative | Continuous | Nobody: tier 0, unsigned. Venue dispersion shown, no band | Screens, monitoring | Anything contractual | not published: no licensed source (exchange prices are never shown) |
2. OFF-HOURS SIGNED fixing | 00:00, 08:00 and 16:00 UTC, every day, weekends and holidays included | K of N seats, signing automatically, at least one of them a venue, with a published data-quality band (± b; uncalibrated until back-tested) | Margin, liquidation, health factors, collateral haircuts, once attested; until then tier 0, labelled pilot — not attested, and not for liquidation | NAV, creation, redemption, fund reporting | specified, not built |
3. OFFICIAL fixing | Once a day. Crypto: 16:00 London, adopted 28 Sep 2026 (why). Any equity, and any basket with an equity leg: 16:00 New York on NYSE trading days | K of N seats and every gate; published with its tier and input level | NAV, creation and redemption, reporting | — | built for wrapped crypto and funds on DevNet; equities planned |
If fewer than two live inputs of distinct signal types remain (token trades on any number of venues count as one), nothing is guessed: the result is NO FIXING, and the last good value stays visible with its age. A move of more than 10% since the previous value is published and flagged EXCEPTIONAL, never suppressed; that is the word’s only meaning. Nobody may present an off-hours or indicative value as a NAV, and the licence says so.
Technology
- Canton Network
- A blockchain network built for regulated finance, where a contract is visible only to the parties on it. ETP Foundry’s rules run there as smart contracts.
- Daml
- The language Canton smart contracts are written in. ETP Foundry’s committee rules — K of N, one fixing per day, the venue’s range check — are Daml contracts, so the ledger enforces them.
- DevNet, TestNet, MainNet
- Canton’s three networks. DevNet is for development and holds no real money; MainNet is production. ETP Foundry runs its own validator on DevNet.
- Validator / participant
- A node that connects to the Canton network and hosts parties’ contracts. ETP Foundry runs one; a member at trust level L3 would run its own.
- CIP-56
- Canton’s token standard (Canton Improvement Proposal 56). A token that follows it — cBTC, Canton Coin — can be held and transferred the same way as any other, so ETP Foundry can add it to a fund by configuration instead of new code.
- Vault
- A smart contract on another chain (Ethereum-style “EVM” chains today) that carries fund shares there, so investors can hold them on the chain they already use. Testnets only: ten internal mechanism tests holding MOCK tokens we deployed ourselves (not products), and one vault on Robinhood Chain Testnet holding Robinhood’s own test stock tokens. No mainnet vault exists.
- Checker (signer-service)
- A small program that does a committee member’s daily work. It reads the member’s own systems, builds the day’s submission and sends it, and stops (sends nothing) when it cannot read a source. It never reads the proposed price to build its numbers. It runs hosted by ETP Foundry, in the member’s own cloud, or on the member’s own server (how you run it).
- Hosted checker
- The default way to run a seat: ETP Foundry runs the checker for you. You set it up in the dashboard, with no install, no servers and no Docker. An issuer often connects nothing (we read its public reserve proof or on-chain reserves, and it sets two status toggles); a venue or lender pastes a read-only API link or key. It signs at L1 (we sign for the seat, disclosed) or with the member’s own Google Cloud KMS key. Because we fetch the inputs, a hosted seat counts as operator-run and publishes at tier 0 (not attested), even with its own key. Ideal for a pilot. Built and live on the desk since 29 Sep 2026; no third-party member has run it yet. Members’ read-only data credentials are encrypted (AES-256-GCM); the encryption key is held in Google Secret Manager, not in the code or on disk.
- Own-cloud checker
- The checker deployed in one click into the member’s own Google Cloud (Cloud Run) or AWS (ECS) account from a ready template, with its Ed25519 signing key in its own KMS (Google Cloud KMS or AWS KMS). It restarts itself, and a second, standby instance is optional; a developer deploys it. Because the member runs it, it counts toward tier 1. Built and live on the desk since 29 Sep 2026; no third-party member has run it yet, and the templates have not yet been applied in a member’s account. Level 2 own-key signing stays switched off on the running desk until the ledger JSON API is opened to it. (Self-run, the Docker image on the member’s own server, counts the same way.)
- KMS (key management service)
- A cloud vault, such as Google Cloud KMS or AWS KMS, that holds a signing key and signs with it without ever releasing it. A member can keep its seat’s key there, so the key never leaves the member’s own account.
- Trust levels L1, L2, L3
- Where a member’s signing key lives. L1: on ETP Foundry’s node (fine for a pilot; we could technically sign). L2: the member’s own key, in its KMS or on its own machine; we cannot sign for it through the ledger API, but we can still refuse or delay a submission, and a participant running modified software is the one remaining path, which L3 closes. L2 is built and was proven on DevNet on 26 Sep 2026; it is switched off on the running desk today, and will be on before the first seat onboards. L3: the member’s own Canton node (not built yet). Every value states the mix. A seat run by ETP Foundry never counts toward K, at any level.
- Ed25519 key
- The kind of signing key an L2 member holds, in its own cloud KMS or generated on its own machine. Only its public half is ever shared.
- Webhook
- A signed message ETP Foundry sends to a member’s system the moment a proposal is waiting, so its checker can act without polling. E-mail notices go to the member too.
- MCP and API
- Two ways for software to use the service. The API is for programs; MCP (Model Context Protocol) at etpfoundry.com/mcp lets a signed-in member’s AI agent read and act under the member’s own API key and role. The MCP tools and the in-console assistant are internal, for signed-in users only, and never relay an exchange price.