PEPPERMINT turns real-world assets into sovereign on-ledger units through a disciplined path: verify the asset, seal its record, issue units against it, and settle every trade delivery-versus-payment. Nothing is tokenized on trust — each unit traces back to a sealed attestation of the thing it represents.
Issuance is downstream of verification, never the other way around.
The underlying asset — title, reserve, instrument, or commodity — is documented and attested by the responsible authority before onboarding. The engine records who attested and to what, so provenance starts at the source.
The party responsible for the physical or legal asset is bound into the record alongside the nature of the claim being represented. A unit is explicit about what it entitles its holder to.
Verification artifacts are captured in a defined schema rather than free-form attachments, so the same evidence can be re-examined by an auditor later. Onboarding is a repeatable procedure, not a one-off judgment.
Units cannot be issued against an asset that has not passed the verification stage. The engine enforces the ordering rather than relying on operator discipline.
Sealing freezes the reference the units point to.
The verified asset record is committed and hash-sealed, producing a fixed reference that every issued unit points back to. The terms a holder relied on at issuance cannot be quietly changed afterward.
The seal is authorized with ML-DSA-65 (FIPS 204), binding the sealing authority to the asset record with quantum-resistant signatures. The link between authority and asset is built to outlast the assets themselves.
The seal lives in the same hash-chained ledger as the units, so any change to the asset's on-record terms is detectable. Provenance from asset to unit to holder forms one continuous, checkable chain.
Legitimate updates to an asset's status are recorded as new signed events referencing the sealed original, never as overwrites. History accumulates; it is not edited.
Every unit is a claim with a traceable backing.
Units are minted with an explicit reference to the sealed asset record that backs them. The relationship between outstanding units and their underlying is on-ledger and inspectable.
Only the authority mandated for a given asset can issue or retire its units, enforced by signature at the engine. Over-issuance beyond the sealed terms is a rejected operation.
Retiring units against redemption of the underlying is a signed, first-class event that reduces outstanding supply. The circle from issuance to redemption closes with the same rigor it opened.
Outstanding units and their backing are reconstructable directly from the ledger rather than reported out of band. Coverage is something an auditor verifies, not something an operator claims.
Delivery-versus-payment removes the gap where one side can default mid-trade.
The transfer of units and the corresponding payment settle as one indivisible operation. Either both legs commit or neither does, eliminating the window of principal risk between them.
When payment settles in sovereign currency, PEPPERMINT and the ASTER currency engine commit the asset leg and the cash leg together. A trade does not leave one party delivered and unpaid.
Units are not released to a buyer whose payment leg has not simultaneously committed. Settlement failure rolls the whole exchange back to its prior state.
A settled trade is a permanent entry in the hash-chained ledger, verifiable by both counterparties and their supervisors. Finality is cryptographic, not a matter of later reconciliation.
Talk to us about peppermint asset engine in a sovereign deployment.