Solstice Protocol

The settlement rail for institutional-grade digital assets.

The settlement layer beneath your institution — where digital assets and traditional money finally work as one machine.

Solana SPEPost-quantum cryptographyProgrammable reversibilityISO 20022 aligned
Scroll — follow one payment
Prologue · The gap

Today's rails move messages, then money. Everything in between is risk.

batch windows · T+1 · pre-funded nostros · Herstatt risk

Chapter 01 · The machine

Two layers. One rail.

The ledger

Solstice Core is the permissioned source of truth — every transaction recorded, enforced by programmable rules, and provably final.

The rail

Solstice Network is the bank-facing surface — connect your tokenization platform, route through compliance, settle atomically with any counterparty.

Together

They click into one settlement machine — rules below, movement above. Nothing settles that the ledger can't prove.

01 / 03
Layer 2 — Solstice Networkmovement
Compliance
Protocol-enforced
Settlement
Atomic DvP
Messaging
ISO 20022 aligned
Layer 1 — Solstice Coretruth
Rules
Programmable
Keys
Post-quantum
Record
Immutable audit
reconciliation gap — batch · T+1
one rail — atomic · 387 ms
In detail · The stack

Two layers, on paper.

What each layer owns — before the story moves on.

2 layers
Core — truth · Network — movement
Tower BFT
Permissioned validators · f < n/3
ISO 20022
pacs.008 / pacs.009 mapped
Chapter 02 · One payment

Follow $25M down the rail.

01 · Initiate

Bank A submits a payment instruction — a tokenized deposit, ISO 20022 mapped, destination Bank B.

02 · Pre-check

Compliance runs before money moves: identity, sanctions, policy. Attestations attach to the transaction itself.

03 · Atomic lock

Both legs bind cryptographically. Either everything settles, or nothing does — no partial fills, no daylight exposure.

04 · Finality

One slot, deterministic. At t+387ms the payment is done — not "probably done."

05 · Reconcile

Value redeems to Fed rails on your schedule. Solstice settles M1; the Fed settles M0. Additive — not replacement.

01 / 05
Initiate
Instruction accepted
→ pacs.008 · USD-TD · $25,000,000
Pre-check
Compliance attests
✓ kyc · ✓ sanctions · ✓ policy window
Atomic lock
Legs bind — DvP
⬒ locked · no partial state possible
Finality
Single slot, irreversible
■ slot 48,201,337 · 387ms
Reconcile
M0 redemption queued
↳ fedwire ref 0720-8841
t+000
Pending
Anatomy of an instruction

Read a settlement like the network does.

Four fields carry the whole story — amount, corridor, hooks, delegate. Scroll walks them the way the network reads them.

amount27,060,000 · EUR-M1
corridorEUR → CHF · PVP
hooks[jurisdiction, sanctions]
delegatepermanent_delegate
FIELD 1 / 4

Denominated in tokenized M1

The amount is a 1:1 mirror of a regulated bank deposit — value that never leaves the issuing bank's balance sheet — transferable only under protocol compliance.

TOKEN EXTENSIONS · EUR-M1

Cross-currency, one operation

Payment-versus-payment: both currency legs settle together or not at all. No correspondent chain, no timing gap.

EUR → CHF · PVP

Policy runs before value moves

Transfer hooks evaluate jurisdiction and sanctions in-line. A failed check means nothing moves — there is no unwind queue.

2 HOOKS · IN-LINE

Reversibility, governed

The permanent delegate authority enables confirmed-fraud clawback inside the reversibility window — under network rules, never unilaterally.

PERMANENT_DELEGATE
Burn-and-mint

Two ledgers. One operation.

The origin leg burns, the destination leg mints — one operation, no partial state to unwind.

BANK A · MEM-04ORIGIN
EUR-M1 · 27,060,000− BURNED
USD-M1 · 41,200,000
GILT-2031 · 12,000,000
BANK B · MEM-11DESTINATION
CHF-M1 · 25,114,000+ MINTED
CHF-M1 · 8,410,000
USD-M1 · 3,275,000
PVP · NO PARTIAL STATEBURN LEG · ORIGINT+387MS
Programmable reversibility

Irreversible — eventually. Governed — always.

From settlement through the governed clawback window to sealed — scrub the timeline.

T+0 · SETTLE · 387MS
REVERSIBILITY WINDOW · CLAWBACK UNDER NETWORK RULES
SEALED · PERMANENT

Settling — the atomic swap executes

Burn and mint legs execute as one operation. There is no intermediate state to unwind.

T+0 → T+387MS

Inside the window — reversal is governed

Confirmed fraud can be clawed back by the permanent delegate inside the configurable 24–72h window — under network rules, never unilaterally.

24–72H · PERMANENT_DELEGATE

Sealed — the record is permanent

The window closes. The entry is irreversible and lives in the compliance log for supervisory audit.

LOG #48291 · IRREVERSIBLE
Compliance log

One entry. Three million siblings.

One legible receipt, then its place among millions — every entry inspectable by a supervisor.

Timestamp · SignatureCorridor · AmountHooks
T+381MS · SIG 0x2f81…c04aUSD→EUR · 12.40MHOOKS PASSED
T+384MS · SIG 0x9bd3…7e11USD→GBP · 4.85MHOOKS PASSED
T+385MS · SIG 0x51c7…d928USD→JPY · 8.11MHOOKS PASSED
T+387MS · SIG 0x8f2e…41aaEUR→CHF · 27.06MHOOKS PASSED
T+389MS · SIG 0xe30b…5f66GBP→SGD · 1.92MHOOKS PASSED
T+390MS · SIG 0x44aa…0d21EUR→USD · 6.53MHOOKS PASSED
T+393MS · SIG 0x7c19…b8e0CHF→USD · 2.28MHOOKS PASSED
ENTRY #48291 · COMPLIANCE LOG
SIG 0x8f2e…41aa
CORRIDOR
EUR → CHF · PVP
AMOUNT
27,060,000
HOOKS
2 PASSED · IN-LINE
FINALITY
T+387MS
T+387MS · SIG 0x8f2e…41aaEUR→CHF · 27.06MHOOKS PASSED
ENTRY #48291 · ONE OF 3,412,908 · ALL AUDITABLE
In detail · The numbers

The rail, measured.

Benchmarked on a single Solstice cluster, DvP-01 workload.

65k/sec
Sustained transactions · single cluster
387ms
Atomic finality · p99 end to end
1 slot
Deterministic — final, not probable
Chapter 03 · The decade after next

Post-quantum armor.

The threat

Settlement records live for decades. "Harvest now, decrypt later" targets exactly this data — recorded today, broken when the machine arrives.

The answer

Solstice is PQC-native: every key exchange, every signature, every hash — NIST-standard post-quantum cryptography, from the first commit.

The result

No migration event. No retrofit. The armor is the architecture — records trustworthy in 2045.

01 / 03
LEDGERslot 48,201,337
ML-KEM-1024 · key exchange
ML-DSA-87 · signatures
SHA-3-256 · hashing
NIST PQC · FIPS 203 / 204 aligned
Epilogue · The spec sheet

The machine, in eight rows.

Consensus to message standard — and what settles on it today. Click any row for the detail.

Spec sheet · click a rowDetail
Consensus model
PoH + Tower BFT · permissioned validator set · f < n/3
Model
PoH + Tower BFT
Validators
Permissioned · named set
Safety
f < n/3 Byzantine
Finality
387ms p99 atomic · single-slot deterministic
P99
387ms atomic
Slot
Single-slot deterministic
Reorgs
None — final is final
Throughput
65,000 TPS sustained · 400ms block slot
Sustained
65,000 TPS
Slot time
400ms
Peak
~150,000 TPS tested
Key exchange
ML-KEM-1024 · NIST PQC standard
Scheme
ML-KEM-1024
Standard
NIST FIPS 203
Scope
Protocol + key management
Signature scheme
ML-DSA-87 · 48ms verify avg
Scheme
ML-DSA-87
Standard
NIST FIPS 204
Verify
48ms average
Hash function
SHA-3-256 · Poseidon for zk-friendly subtree commits
Primary
SHA-3-256
Commits
Poseidon · zk-friendly
Use
Subtree commitments
Settlement model
Atomic multi-asset DvP · all legs land or none do
Mode
Atomic multi-asset DvP
Guarantee
All legs land or none do
Pre-funding
Not required
Message standard
ISO 20022 aligned · pacs.008 / pacs.009 mapped
Standard
ISO 20022
Mapped
pacs.008 / pacs.009
Rails
Fedwire / FedNow aligned
Settles todayTokenized deposits · Atomic DvP · Programmable reversibility · Cross-border FX
ArrivingAgent-initiated payments · Treasuries, MMFs & RWAs

Get started

Ready to build on Solstice?

Talk to our team about how Solstice Protocol can modernize your institution's settlement infrastructure.

Contact us ↗Read the docs