Canton In development

How Plumb runs on Canton

This describes software that runs today.

Unlike the Midnight page, which sets out proposed work, everything here already runs — the reconciler, the convergence loop, and the Medici application it keeps in plumb. It runs in a development environment (dev.medici.loan), and we make no operational claim past that boundary: this is not in production.

What runs, and the scope of each measurement, is stated below. The edge of what we claim is stated too, in What we don't claim.

Runs today · in development
What runs today

The reconciler, converging every 60 seconds

Plumb is the identity control plane that keeps Medici's own environment converged. Two planes are reconciled against one declarative manifest, every 60 seconds, against live Canton networks in development — the identity provider and the ledger's rights model. Nothing is inferred from a dashboard; every reading is earned by a probe that ran.

Two planes, one manifest

In development

The Keycloak/OIDC identity plane and the Canton rights plane are converged against a single manifest every cycle, against live Canton networks in development (dev.medici.loan). Declared state and observed state are reconciled continuously — a right that exists on the ledger but not in the manifest is drift, and drift is healed, not logged and forgotten.

Development environment; no production claim is made.

Wipe-tested recovery

Measured

Recovery has been exercised, not assumed: the identity database dropped, every subject re-issued, and ledger-side users orphaned — then back to fully green with zero manual steps in about 4–6 minutes. The loop rebuilds the declared world from the manifest; an operator does not.

Measured on Medici's own dev environment (one identity provider, one participant, ~15 principals); recovery time varies with principal count and topology.

Private by construction

Canton model

On Canton a contract is visible only to its stakeholders, so per-principal rights and positions stay private by construction. Only the aggregates designed to be public — such as the price feed — are shared chain-wide, through a dedicated public party. Reconciling identity does not mean publishing it.

Canton's stakeholder-visibility model, as Medici uses it today.

The loop

Converge, probe, heal — on Canton

The loop is deliberately unexciting: the same three steps every 60 seconds, so that "in plumb" means the same thing today as it did yesterday. On Canton, each step maps to a concrete operation against the participant and the identity provider.

Converge

One manifest states which principals exist, and with which rights, across the identity provider and Canton's rights model. Every cycle, observed state is brought back to declared state. No cycle is optional, and no drift is left standing.

Probe

Synthetic probes prove a principal's declared capability is actually exercisable on the ledger — not merely configured. A right that reads "granted" but no longer works is caught here, because the probe tries to use it rather than trusting the record.

Heal

Detected drift is converged back to the manifest, unattended. Operational status speaks control-room language: green is converged, amber is drift, red is incident — and silence is never mistaken for health.

What it keeps in plumb

The Medici application on Canton

Plumb began as the identity control plane inside Medici's own system, and that system is what it keeps converged. Medici builds options-based index-tracking synthetic assets on Canton — positions constructed from options rather than debt, so there is no liquidation price by construction. Plumb is the same software, held to the same discipline, keeping that application's principals and rights in plumb.

The application

Devnet

The live application on Canton devnet: collateral splits into Protected and Amplified tokens with multi-attestation oracles, on-chain multi-sig governance, and an agent framework for supervised strategy execution.

Governance, on chain

Devnet

Administration and delegation are contracts, not conventions: an on-chain admin roster with a multi-sig threshold, a two-party handover with a timeout, and a circuit breaker that halts trading — all enforced by the ledger, not by a checklist.

The mechanism

Research

The public research behind Medici's synthetic assets: index tracking built on options instead of debt, with the P + N conservation invariant proven in closed form.

The boundary · what we don't claim
What we don't claim

The edge of what runs, stated plainly

Software that runs is easy to over-read as software that is finished. This list is the boundary — every item is something a reader might reasonably assume from the section above, and every one of them we do not claim.

  • This is not in production. Everything above runs in a development environment (dev.medici.loan). We make no availability, uptime, or production-readiness claim.
  • The measurements are single-environment. The recovery time and principal count are from one dev environment — one identity provider, one participant. They are observations, not guarantees, and they will vary with scale and topology.
  • The loop does not yet cover the deployment substrate. It converges the identity provider and the ledger's rights model. The deployment-substrate plane (Kubernetes) is planned, not built.
  • Secrets are not rotated automatically. Secret rotation is part of the shape of the product, not part of what runs today; it has not been written.
  • We do not custody funds or operate an exchange. Plumb is infrastructure software. It does not hold assets, execute trades on anyone's behalf, or provide investment advice.

Where this stands

Canton is where Plumb runs today, in development. Midnight is where it could go next — the same converge-and-probe loop expressed as zero-knowledge circuits — and that work is an open proposal, not started and not funded. The two pages are deliberately different tenses, because the work is.

Contact

If something here is wrong, or you want to see the loop run, we would like to hear from you.

hello@plumb.finance

Nothing here is a solicitation, an offer, or investment advice.