Start with a payment that should be simple
A textile firm in one country sells to a buyer in another. The invoice is nine hundred thousand dollars. Both companies are real, both are licensed, both have banked with the same institutions for years. The goods have shipped.
The payment takes four days. It passes through three banks that have no relationship with either company. Somewhere in the middle it stops for two days while a compliance officer, in a third country, satisfies himself about a name that resembles another name. Nobody tells the seller. The seller phones the buyer, the buyer phones his bank, and his bank says what banks say: it has left us.
Nothing in that story is a technology failure. Every system worked exactly as designed. The design is the problem.
The money moved through a chain of institutions because there is no shared place for it to move through. Each bank in the chain had to satisfy its own regulator, using its own information, at its own pace. None of them could see what the others had already checked, so each checked again. The delay was not friction to be optimised away. It was the visible cost of an arrangement in which trust cannot be transmitted, only re-established at every stop.
What a central bank actually does
Strip away the interest rate decisions and the speeches, and a central bank does something quite mechanical. It keeps the definitive ledger of who holds the national currency, and it lets the banks settle with each other on that ledger. When two commercial banks in the same country move money between them, they are not couriering value. They are asking the central bank to change two numbers.
That is why domestic payments are fast and cross-border payments are not. Inside one country there is a shared book with an authority to keep it. Between countries there is no shared book, so the banks build a chain of private relationships and pass the obligation along it. Correspondent banking is not a system. It is what institutions do in the absence of one.
The obvious fix has been obvious for a century, and it has never happened, for a reason that has nothing to do with software.
The reason it has never happened
A shared book needs someone to keep it. Whoever keeps it can freeze an account, reverse an entry, see every transaction, and set the terms of access. No sovereign nation will accept another nation, or a private company, holding that position over its currency and its citizens' payments. It is not a technical objection and it will not be argued away. It is the correct instinct of anyone responsible for a country.
Every proposal to build the shared book has failed on the same question: who holds the pen.
So the world settled for the chain of correspondents, and the four days, and the compliance officer in the third country. The cost is paid in delay, in fees, and in the quiet exclusion of countries too small to be worth a correspondent relationship at all.
What we built instead
We took the mechanical part of a central bank, the definitive ledger and the settlement, and separated it from the part nobody will surrender, which is authority over it.
Each participating nation or institution gets its own ledger. Not an account on ours. Its own, with its own currency, its own rules, and its own named institutions signing off on every block of transactions. We call that a sovereign cell. The nation writes its compliance rules into the ledger itself, so a transfer that its law forbids is refused as it happens, rather than flagged in a report the following month.
The cells then settle with each other across governed corridors. A corridor is closer to a treaty than to a pipe: both sides agree the terms in advance, both sides sign each transfer, and the receiving side re-checks the transfer against its own rules on arrival. Neither side has to trust the other's judgment, and neither side surrenders its rulebook to get the speed.
So: the functions of a central bank, and none of the position. We operate the machinery. The authority stays with the federation, which is to say with the members, and each member keeps the pen for its own book.
What that changes for the payment
The same nine hundred thousand dollars, in this arrangement, does not travel through three uninvolved banks. It moves once, across one corridor, between two ledgers whose operators are named and accountable. The compliance checks happen at both ends against rules both sides agreed to beforehand, in the moment the transfer is made, not days later in a queue.
The more consequential change is what is left behind. Every step produces a signed, timestamped record that can be independently checked afterwards by a regulator, an auditor, or a court, without asking us for anything and without taking our word for it. The evidence is a property of the transaction, not a report written about it later.
That is the part institutions tend to care about once the novelty of speed wears off. Fast payments are pleasant. Payments you can prove, years later, to someone hostile, are valuable.
What we can and cannot see
We do not know who the buyer is. We do not know who the seller is. This is deliberate and it is built into the machinery rather than promised in a policy document.
What the system checks is that both parties to a transfer carry valid credentials, issued by whoever is entitled to issue them, and that those credentials are genuinely present in the ledger the transaction claims to come from. It checks the standing of the parties without learning their identity. Identity stays with the institutions that are supposed to hold it, under the law that governs them.
This is the opposite of the usual bargain, in which a platform learns everything in exchange for making things work. A settlement layer that learns everyone's business becomes a thing that has to defend everyone's business, and eventually a thing worth attacking.
Where the power actually sits
It is fair to ask what stops us from becoming the institution nobody wanted, once enough of the world's payments run through the machinery.
Three things, and they are structural rather than promissory. Each cell's ledger belongs to its operator, who can run it, audit it and, in the fullest tier, leave with it. The institutions signing off on transactions are named and accountable rather than anonymous, so there is always an answer to the question of who agreed to this. And the record is verifiable by outsiders, which means a claim we make about what happened can be checked by someone who does not trust us.
A guarantee you have to trust is a promise. A guarantee someone else can check is a control.
The distinction matters more than any assurance we could offer. We designed for the case where we are not believed, because that is the only design a sovereign should accept.
What is not true yet
The companion to this page, the Federation Thesis, is an engineering document that states at length what is built, what is designed, and what is neither. This page would be dishonest if it left a different impression, so here is the short version.
Reference cells run today and can be demonstrated. The consensus engine described in the thesis is written and tested but is not deployed to production, and it has not yet been through an external security audit. Some of the custody arrangements a central bank would require of us are procurement decisions that have not been made. A full national deployment is a programme of work with gates, not an installation.
We publish that because the alternative is worse. An institution that discovers the gap later concludes we were hiding it, and it is right to.
Who this is for
A finance ministry that wants its own payment rails without handing the keys to a foreign platform. A central bank evaluating a digital currency and unwilling to accept a shared ledger somebody else controls. A regulated institution that has to prove, years afterwards, exactly what it did and when.
If any of that is the problem in front of you, the thesis is the technical case and the white paper is the commercial one. Request a briefing and we will show you the machinery running rather than a slide about it.
