For fund operations and administrators

Capital calls where each LP sees only its own notice.

Today a fund emails each notice and matches LP wires from a bank export before it knows who has paid. On DRAW each notice is a Canton contract between the fund and one LP, and other LPs can’t read it. The LP pays it from its own wallet, the notice turns funded in the same transaction that moves the coin, and the fund counts it only after a read-back confirms it.

Actions in the demo, starting with creating the demo fund, need an access code from the DRAW team. The proof page needs none.

What works on DevNet: the Oct 7 scripted run passed 83 of 83 checks and skipped 2, and 2 of 2 LP payments in test Canton Coin were read back as verified funded.

Have a HackCanton login with a wallet on its node? Sign in on the seat screen to join as an LP and pay from your own Canton wallet.

LP B’s ledger, DevNet run

LP A’s noticeNot visible
Fund totalsNot visible

Example Ventures I

Call 3, initial close

Example

  • LP A40 CC$400,000Due
  • LP B35 CC$350,000Due
  • LP C25 CC$250,000Due
Deployable now$0
Unresolved$1,000,000

Settlement receipt, DevNet run

40 CC

Verified, 14 of 14

Settles on the Canton Network with the CIP-0056 Token Standard

  • Canton Coin
  • Daml contracts
  • Token allocations
  • Read-back receipts
How a call moves

Issue once. Every LP pays its own notice.

A capital call on DRAW is four steps on the ledger and a read-back. Pick a step to see an example of the record it leaves. Nothing is a status someone ticks by hand.

Example record: Invite

Invitation to commitExample Ventures I, for LP A

$1,000,000

Accept commitment
Why it runs on Canton

Three things a spreadsheet can’t promise

Canton enforces the first two: who can read a notice, and that funded moves with the money. The third is DRAW’s read-back, which counts only what the ledger already settled.

Private by the ledger

A notice is a contract only the fund and that LP can read, plus the node that hosts them. Another LP asking for it by its id gets nothing back.

LP AOwn notice
LP BOwn notice
Anyone elseNothing

Funded follows the money

The notice turns funded in the same transaction that moves the coin. A wrong amount, payer or reference is refused.

Refused by the ledger

  • Wrong amount
  • Wrong payer
  • Wrong reference
  • Reused payment

Read back before it counts

A read-back step reads each settlement from the ledger and checks it. Only a settlement it confirms counts as deployable.

Deployable$750,000
Unresolved$250,000

DevNet run, Oct 7

Who sees what

Each party reads its own ledger.

These are the records each party’s own query returned at the end of the DevNet run. DRAW doesn’t hide rows. The ledger never sends them. On DevNet one login made every query, each for a single party.

DevNet run 20261007T130259Z. No party saw a record it should not.

Records each party can read
PartyFundCommitmentsCallNotices
Fund managerYesAll 3YesAll 3
LP ANoneOwn onlyNoneOwn only
LP BNoneOwn onlyNoneOwn only
LP CNoneOwn onlyNoneOwn only
Unrelated partyNoneNoneNoneNone
The record so far

Every number was written by a test.

Open the proof
DevNet

83/83

checks on DevNet

2 LPs funded with test Canton Coin, bad payments refused, the unpaid LP marked overdue.

LocalNet, package 0.2.0

100/100

generated capital calls

191 notices, 0 falsely funded, 0 privacy violations.

LocalNet

5/5

attacks stopped

The same flow on a database with a paid flag let 4 through.

LocalNet, package 0.2.0

76/76

checks, each party holding its key

The participant cannot act for a party without that party’s signature.

Questions

Know what you’re looking at.

DRAW in brief

Network
Canton DevNet, HackCanton node
Settles in
Test Canton Coin
Standard
CIP-0056 allocations and allocation requests
Contracts
Daml package draw 0.3.0, as the live site runs it
Is this real money?

No. It runs on the Canton DevNet with test Canton Coin. Dollar figures are the business scenario, and the coin is what actually moves.

Who holds the keys?

On LocalNet and on the HackCanton DevNet node, a scripted run had every party sign its own transactions with its own key. On DevNet the node’s operator allocated those parties for us from keys we generated, since teams can’t allocate them themselves. All five keys sat on the machine that ran the script, so it shows the ledger needs each party’s signature, not that separate people held the keys, and this live site doesn’t use those parties. An earlier version of this web app let each person make a key in the browser, and the current browser-key flow hasn’t run on LocalNet. On this live site DRAW’s backend login acts for the demo seats. An LP that signs in with its own HackCanton login acts for its own party from its own browser instead. The app says which mode you’re in.

Can I pay from a real Canton wallet?

On DevNet, yes, if your HackCanton login has a wallet on the HackCanton node. Sign in on the seat screen and join as an LP. Your notice also shows up in the node’s Canton Coin wallet as an allocation request, and pressing Accept there pays it. DRAW’s server never receives your login. Every recorded run so far signed in with the team’s own login as the LP. Actions on this demo need an access code from the DRAW team.

Why Canton?

Canton gives each contract a fixed set of parties who can read it, and settles a token transfer and a state change in one transaction. Those two properties are what make a private notice and a provable funded status possible.

What does the fund manager see?

Every notice in its fund, the payments waiting against them, and two totals: deployable now and unresolved.

Can an LP see the other LPs?

No. An LP’s ledger returns its own commitment and notices only. Opening another LP’s notice link shows nothing, because the ledger returns nothing.

Who can see the payment?

The notice and the commitment are private. Only the fund’s party and that LP’s party can read them, plus the node that hosts them. On DevNet DRAW’s backend login reads for every demo seat. Per the Splice Scan API docs, the Canton Coin transfer that pays a notice appears in the network’s Scan service with its random reference and both party ids, whose hints such as draw-lpa are readable, while the notice and the commitment don’t. That comes from the docs, and DRAW hasn’t checked it against Scan. In production the fund would settle in a tokenized dollar through the same Token Standard allocation interface. The USDCx registry lists that interface, but DRAW hasn’t been run with USDCx.

Run a capital call end to end.

Take a seat as the fund manager or one of three LPs. Actions on this demo need an access code from the DRAW team.

Take a seat