SOVEX
CBDC Data Centers Sovereign AI Tokenization Deep Tech Architecture About Team Request access
Architecture / The engines / PEPPERMINT asset engine

PEPPERMINT asset engine.

PEPPERMINT turns real-world assets into sovereign on-ledger units through a disciplined path: verify the asset, seal its record, issue units against it, and settle every trade delivery-versus-payment. Nothing is tokenized on trust — each unit traces back to a sealed attestation of the thing it represents.

An asset earns its way onto the ledger before a single unit exists

Issuance is downstream of verification, never the other way around.

01

Attested existence

The underlying asset — title, reserve, instrument, or commodity — is documented and attested by the responsible authority before onboarding. The engine records who attested and to what, so provenance starts at the source.

02

Custodian and claim

The party responsible for the physical or legal asset is bound into the record alongside the nature of the claim being represented. A unit is explicit about what it entitles its holder to.

03

Structured onboarding

Verification artifacts are captured in a defined schema rather than free-form attachments, so the same evidence can be re-examined by an auditor later. Onboarding is a repeatable procedure, not a one-off judgment.

04

No verification, no units

Units cannot be issued against an asset that has not passed the verification stage. The engine enforces the ordering rather than relying on operator discipline.

The verified record is cryptographically sealed so its terms cannot drift

Sealing freezes the reference the units point to.

01

Immutable reference

The verified asset record is committed and hash-sealed, producing a fixed reference that every issued unit points back to. The terms a holder relied on at issuance cannot be quietly changed afterward.

02

Post-quantum signing

The seal is authorized with ML-DSA-65 (FIPS 204), binding the sealing authority to the asset record with quantum-resistant signatures. The link between authority and asset is built to outlast the assets themselves.

03

Tamper-evident lineage

The seal lives in the same hash-chained ledger as the units, so any change to the asset's on-record terms is detectable. Provenance from asset to unit to holder forms one continuous, checkable chain.

04

Amendments as events

Legitimate updates to an asset's status are recorded as new signed events referencing the sealed original, never as overwrites. History accumulates; it is not edited.

Units are issued against the sealed asset, not against a promise

Every unit is a claim with a traceable backing.

01

Backed unit creation

Units are minted with an explicit reference to the sealed asset record that backs them. The relationship between outstanding units and their underlying is on-ledger and inspectable.

02

Authorized supply

Only the authority mandated for a given asset can issue or retire its units, enforced by signature at the engine. Over-issuance beyond the sealed terms is a rejected operation.

03

Redemption and burn

Retiring units against redemption of the underlying is a signed, first-class event that reduces outstanding supply. The circle from issuance to redemption closes with the same rigor it opened.

04

Auditable coverage

Outstanding units and their backing are reconstructable directly from the ledger rather than reported out of band. Coverage is something an auditor verifies, not something an operator claims.

Assets and payment change hands in a single atomic exchange

Delivery-versus-payment removes the gap where one side can default mid-trade.

01

Atomic delivery-versus-payment

The transfer of units and the corresponding payment settle as one indivisible operation. Either both legs commit or neither does, eliminating the window of principal risk between them.

02

Cross-engine with ASTER

When payment settles in sovereign currency, PEPPERMINT and the ASTER currency engine commit the asset leg and the cash leg together. A trade does not leave one party delivered and unpaid.

03

No unmatched delivery

Units are not released to a buyer whose payment leg has not simultaneously committed. Settlement failure rolls the whole exchange back to its prior state.

04

Final and provable

A settled trade is a permanent entry in the hash-chained ledger, verifiable by both counterparties and their supervisors. Finality is cryptographic, not a matter of later reconciliation.

Build it sovereign.

Talk to us about peppermint asset engine in a sovereign deployment.