Private by the ledger
A notice is a contract only the fund and that LP can read, plus the node that hosts them. Another LP asking for it by its id gets nothing back.
Today a fund emails each notice and matches LP wires from a bank export before it knows who has paid. On DRAW each notice is a Canton contract between the fund and one LP, and other LPs can’t read it. The LP pays it from its own wallet, the notice turns funded in the same transaction that moves the coin, and the fund counts it only after a read-back confirms it.
Actions in the demo, starting with creating the demo fund, need an access code from the DRAW team. The proof page needs none.
What works on DevNet: the Oct 7 scripted run passed 83 of 83 checks and skipped 2, and 2 of 2 LP payments in test Canton Coin were read back as verified funded.
Have a HackCanton login with a wallet on its node? Sign in on the seat screen to join as an LP and pay from your own Canton wallet.
LP B’s ledger, DevNet run
Example Ventures I
Call 3, initial close
Example
Settlement receipt, DevNet run
40 CC
Verified, 14 of 14Settles on the Canton Network with the CIP-0056 Token Standard
A capital call on DRAW is four steps on the ledger and a read-back. Pick a step to see an example of the record it leaves. Nothing is a status someone ticks by hand.
Example record: Invite
$1,000,000
Accept commitmentCanton enforces the first two: who can read a notice, and that funded moves with the money. The third is DRAW’s read-back, which counts only what the ledger already settled.
A notice is a contract only the fund and that LP can read, plus the node that hosts them. Another LP asking for it by its id gets nothing back.
The notice turns funded in the same transaction that moves the coin. A wrong amount, payer or reference is refused.
Refused by the ledger
A read-back step reads each settlement from the ledger and checks it. Only a settlement it confirms counts as deployable.
DevNet run, Oct 7
These are the records each party’s own query returned at the end of the DevNet run. DRAW doesn’t hide rows. The ledger never sends them. On DevNet one login made every query, each for a single party.
DevNet run 20261007T130259Z. No party saw a record it should not.
| Party | Fund | Commitments | Call | Notices |
|---|---|---|---|---|
| Fund manager | Yes | All 3 | Yes | All 3 |
| LP A | None | Own only | None | Own only |
| LP B | None | Own only | None | Own only |
| LP C | None | Own only | None | Own only |
| Unrelated party | None | None | None | None |
83/83
checks on DevNet
2 LPs funded with test Canton Coin, bad payments refused, the unpaid LP marked overdue.
100/100
generated capital calls
191 notices, 0 falsely funded, 0 privacy violations.
5/5
attacks stopped
The same flow on a database with a paid flag let 4 through.
76/76
checks, each party holding its key
The participant cannot act for a party without that party’s signature.
DRAW in brief
No. It runs on the Canton DevNet with test Canton Coin. Dollar figures are the business scenario, and the coin is what actually moves.
On LocalNet and on the HackCanton DevNet node, a scripted run had every party sign its own transactions with its own key. On DevNet the node’s operator allocated those parties for us from keys we generated, since teams can’t allocate them themselves. All five keys sat on the machine that ran the script, so it shows the ledger needs each party’s signature, not that separate people held the keys, and this live site doesn’t use those parties. An earlier version of this web app let each person make a key in the browser, and the current browser-key flow hasn’t run on LocalNet. On this live site DRAW’s backend login acts for the demo seats. An LP that signs in with its own HackCanton login acts for its own party from its own browser instead. The app says which mode you’re in.
On DevNet, yes, if your HackCanton login has a wallet on the HackCanton node. Sign in on the seat screen and join as an LP. Your notice also shows up in the node’s Canton Coin wallet as an allocation request, and pressing Accept there pays it. DRAW’s server never receives your login. Every recorded run so far signed in with the team’s own login as the LP. Actions on this demo need an access code from the DRAW team.
Canton gives each contract a fixed set of parties who can read it, and settles a token transfer and a state change in one transaction. Those two properties are what make a private notice and a provable funded status possible.
Every notice in its fund, the payments waiting against them, and two totals: deployable now and unresolved.
No. An LP’s ledger returns its own commitment and notices only. Opening another LP’s notice link shows nothing, because the ledger returns nothing.
The notice and the commitment are private. Only the fund’s party and that LP’s party can read them, plus the node that hosts them. On DevNet DRAW’s backend login reads for every demo seat. Per the Splice Scan API docs, the Canton Coin transfer that pays a notice appears in the network’s Scan service with its random reference and both party ids, whose hints such as draw-lpa are readable, while the notice and the commitment don’t. That comes from the docs, and DRAW hasn’t checked it against Scan. In production the fund would settle in a tokenized dollar through the same Token Standard allocation interface. The USDCx registry lists that interface, but DRAW hasn’t been run with USDCx.
Take a seat as the fund manager or one of three LPs. Actions on this demo need an access code from the DRAW team.
Take a seat