Guide · Private Capital

The Meridian user guide.

Everything a family office, an investor, an issuer or a fund administrator needs to run a deal on Meridian, from the access request to a posted distribution. Written for the people who operate the work rather than the people who buy the software, and it ends with the record the whole thing leaves behind.

Meridian private capital guide KXCO Engineering 31 July 2026 Updated 23 August 2026 ~26 min read

Most private capital software covers one half of the work. Deal platforms stop at the commitment and hand you a spreadsheet for everything after it. Fund administration systems start at the commitment and have nothing to say about how the deal was found or diligenced. Meridian covers both halves, and this guide walks the whole path: originate, diligence, commit, settle, then administer the vehicle that holds the position, through capital calls, a distribution waterfall and the bank statement that proves the money moved.

01What Meridian is, and what it is not

Meridian is the place family offices, funds, broker-dealers and founders run their deal from. Members run deals. You apply to become a Member and admission is not automatic; counterparties do not apply, a Member tickets them into a room as guests, and when the deal dies the ticket ends and the guest leaves. KXCO built the rail and licenses it. Knightsbridge Financial is a Member like any other and runs its own book on it. It is not a public club, not an exchange, not retail and not FX.

Two things happen in it. Deals get originated, examined and agreed. Then the vehicles behind those deals get administered: who owns what, who owes what, who is owed what, and what the record says. AI runs the room and the human runs the deal: the room drafts the buyer questions, checks the documents against each other and tracks the deal from real activity, and it closes nothing. On the bigger deals and the bigger licenses the KXCO Ontology Round Table is the upgrade, an export of the room that puts your consultants into the same model the assistant is reasoning over.

What Meridian is not matters just as much, and it is not a disclaimer bolted on at the end. It shapes the product.

  • KXCO is a software company. It is not a party to any transaction on the platform, not a broker-dealer, not an adviser and not a fiduciary.
  • KXCO never holds the asset. Settlement goes to your own custodian or wallet. Meridian records instructions and evidence, it does not take custody.
  • Discretion stays with you. Where the software could plausibly make a judgement for you, it refuses and asks. That principle recurs throughout this guide, and it is the reason several operations require a second person rather than one click.

There is a companion guide inside the product at meridian.kxco.ai/guide. This post is the wider version, and it goes further into the vehicle layer.

02Access and verification

Meridian is closed. There is no self-service route from a landing page to a live data room, by design. Membership is by application: kxco.ai/meridian/apply goes to Shayne Heffernan at [email protected] and nowhere else, and he reads them himself.

  1. Request access. An organisation applies from the sign-in screen, giving a name, a category and a contact. Nothing is visible yet.
  2. An administrator reviews it. Approval is a human decision. Until it is granted, sign-in is refused rather than granted with an empty account, so a pending applicant cannot browse.
  3. Verification follows separately. Identity and accreditation checks are a second gate, tracked as its own status. You can explore once approved. Sensitive actions, making an offer and paying a capital call, sit behind verification.
  4. Invitations skip the queue. An administrator, or a Founders Club member, can issue a one-time invite link. Invited members enter directly.

On first sign-in two things are created for you. An organisation, which is the unit that actually holds positions and shares a diligence workspace, so your colleagues see the same work rather than each keeping a private copy. And a KXCO ID, a short fingerprint derived from a post-quantum ML-DSA-65 public key, which is the only identifier shown for you across the network.

Work belongs to the firm rather than to the person doing it. Each organisation is an environment with its own address, and somebody acting as themselves gets an environment of their own, so acting alone is a place rather than the absence of one. A deal is issued by one environment and invested in by others, which means a deal your firm stands on both sides of appears as two rows, "you are issuing" and "you are investing", and only the issuing side carries the issuer's controls. What you can see is decided by the seats you hold: an environment named in an address you have no seat in is refused in the same words as one that does not exist, because different answers would turn the address bar into a directory of other people's counterparties. A seat can also be given up.

There is one rule about standing, and it is not a ladder. A Member is somebody Shayne Heffernan admitted through the application at kxco.ai/meridian/apply. A guest is ticketed into one room by that Member. Signing an NDA does not make anybody a Member, and when the deal dies the guest leaves. What differs between accounts is the plan: seats, limits and which room controls are switched on, set against your agreement. A plan governs entitlements, not standing, and not visibility of your own data.

And it is not only the software. A room is only as good as the judgement in it. KXCO's leadership and advisers have come from BlackRock, Fidelity Investments, DTCC, Bear Stearns, JP Morgan Asset Management, Mellon Bank, Capgemini, EY, Deloitte, Oracle, PA Consulting, Lenovo-IBM and Nordea: a former Senior Vice President at Bear Stearns, a former Relationship Manager in BlackRock's Official Institutions Group who raised $1.3B from sovereign wealth funds, central banks and pension funds, twenty years at Fidelity and the modernisation of DTCC core clearing behind $1.4 trillion a year, and a former CEO North America and Group CTO at Capgemini who was a Partner at EY. Knightsbridge Group trades out of New York, London, Hong Kong, Paris, Bangkok, Doha and Palm Beach, and Asia Pacific is covered by the Vice Chairman of the Hong Kong Blockchain Association. Knightsbridge Law and KXCO are both Knightsbridge Group companies, so counsel sits inside the group rather than being appointed and briefed from scratch. Those firms are where our people have worked, not a claim of endorsement or partnership; the full list is on the company page. That experience is exactly what the Round Table upgrade puts into the model beside the machine.

03The deal board, mandates and matching

Live offerings appear on the Deals board. Rather than reading everything, tell Meridian what you actually invest in.

  • Set your mandate: sectors, geographies, instruments, currencies and a ticket range.
  • Live deals are then scored from 0 to 100 against that mandate and collected under Matches. When a new deal goes live and fits, it lands in your alerts.
  • Watch a deal with the star to be told when it changes, whether or not it matches your mandate.

Matching is a filter, not a recommendation. A high score means the deal fits the parameters you typed, and nothing more than that.

04Creating an offering, and the readiness check

Issuers build an offering from Your offerings. The terms are the usual ones: title and description, sector and geography, instrument (equity, debt, a convertible loan, a private placement, a mortgage, a lien, options or a bond), settlement currency, target raise, minimum ticket, and a visibility setting that runs from network-wide to participants-only to fully private.

An offering starts as a draft. You submit it for administrator review to go live, which is the platform's editorial gate.

Four things shape how a listing presents itself. An enterprise account may name the issuing party, which is how an adviser or a family office lists a raise on behalf of the company actually issuing it; every surface that shows an issuer reads one helper, so the room, the proposal page, the invite email, the settlement sheet and the confidentiality agreement recipients sign cannot disagree about who is issuing, and renaming the issuer on a live deal returns it to review. The action button carries wording the issuer chooses, from presets such as buy now, subscribe, request an allocation or join the club, or their own words. A template saves a room structure worth reusing, so three tiers of one membership programme are three deals built from one template rather than clones of whichever existed first. And deals that form one commercial relationship can be grouped under a heading, which is only a heading: it carries no economics, no participants and no permissions, and never appears in matching.

Before you submit, the Readiness tab scores the offering on structural completeness: core terms filled, documents uploaded and approved, the standard document set for your instrument, an expected diligence list, a reachable data room and settlement configured. It checks that things are present. It does not opine on whether your deal is any good, and it does not block submission. It exists so that you find the gap rather than an investor finding it.

05The data room

Access is tiered, and a signature is not a key. The teaser is open to anyone who can see the deal. Signing the room's confidentiality undertaking, which covers confidentiality, non-solicitation and non-circumvention, an investor eligibility declaration, and the criminal liability position on inside information, records the signature and puts the signer in a queue. It does not admit them. The signer stays at teaser level, the issuer is told that somebody has signed and has not been let in, and the issuer then approves and chooses the level the reader gets. Signing is recorded as a post-quantum signature bound to the hash of the document that was actually shown.

Why it works this way

An issuer's own judgement is the gate. If a signature admitted the signer, the roster would grow by whoever held a link, and the issuer would learn about it afterwards rather than deciding it. Approving cannot demote either: a reader who already holds a wider level keeps it, and the same request cannot be decided twice.

Per document, the issuer chooses how it may be read:

  • Downloadable. The file itself, through the notice described below.
  • View-only. The document is rasterised to images and served with no download path, and the route refuses the bytes even if the URL is guessed. Word and Excel files are converted and rasterised on the same path, where the converter is deployed.
  • Restricted. A rung no access level reaches, not even full access. It is visible to the issuer, because it is their room, and to the people named on the document itself. Naming somebody on one document reaches exactly that document and never a sibling, which is what it replaces: showing one file to one investor used to mean widening their access to every confidential document on the deal in the same movement. Grants are keyed to an email address, so one issued before somebody registers still finds them afterwards.

Where a document may be taken, the download runs through a notice, enforced on the server. Acknowledging it records a row, and the file route refuses to serve an attachment without a recent acknowledgement bound to that document and that caller, so a copied or scripted URL does not walk around it. Reading the notice records nothing, so a reader who cancels has no acknowledgement against their name.

Documents are filed in folders that nest to any depth, in an order the issuer sets. A folder is presentation, never permission: the document's own tier decides who may see it, so filing a confidential file among teaser material discloses nothing. The corollary is that folder names are themselves information, since "Litigation" tells a teaser-tier reader most of what the documents inside were protecting, so a recipient is shown a folder only where a document they may see sits beneath it. Deleting a folder lifts its contents to the parent rather than destroying them.

Every upload is approved individually before anyone sees it, and a document can be permanently removed later, which deletes the stored bytes and the rasterised pages rather than merely hiding the row.

Uploads are also screened for active content: a PDF carrying embedded JavaScript, a run-on-open action or a launch-external-program action. These are refused outright on every plan except enterprise. An account on the enterprise plan may upload one, on the understanding that the check never protected the uploader in the first place. It protects whoever later downloads the document from the room, which includes external recipients who arrived on a forwarded NDA link. So the finding is recorded rather than waved through: the uploader sees a warning naming what was found, and a signed audit entry records the markers, the document, its hash and the plan that allowed it.

Every reader's copy is watermarked on the server, not in the browser, so two recipients receive files that differ byte for byte and a leaked copy is attributable to the person who took it. Page requests are rate limited, which cuts off a sweep of a whole room while never refusing a reader turning pages at human speed, and gated surfaces refuse to print. A browser cannot decline a screenshot, but it can decline a print to PDF, which is the tidiest way to take a room away in one movement.

You get real analytics on the room: who opened what, for how long, on which page, from which device and roughly where, along with a forwarding graph showing how access spread. A shared link is either open to whoever holds it or locked to the people it was sent to. A locked link mints one invitation per recipient, and the undertaking is signed against the name and email the issuer entered rather than whatever the form posts, because the fields are read-only on arrival and the server ignores them regardless.

What the room gives you

Every read is attributed. An invitation belongs to one person, and anything opened through it is recorded under that person's signature. A document that travels leaves a chain back to the recipient who was trusted with it, and the invitation says so in those words, which is what makes the attribution stand up when it matters.

The graph records what the platform sees, and it sees a great deal. A personal link minted, a second signature given, a page opened and how long it was held. That is the evidence an issuer actually uses to decide who is serious, and it is captured without asking anybody to report on themselves.

View-only documents leave the product only as views. A locked document is served page by page, watermarked with the reader's identity, rate limited, and never handed over as a file. What reaches a counterparty is a reading, tied to a name.

06Diligence and the IC memo

This is where most of an investor's time goes, so it is built as a workspace rather than a checklist widget.

For the investor

Open a diligence workspace for your firm on any deal. It belongs to your organisation, so your whole team works the same file, and it is invisible to other investors on the same deal.

  • Work a tracked checklist. Each item moves through not started, requested, received, reviewed, flagged and cleared, carrying your note, a risk flag and a link to the document that evidences it. The list is seeded from a template matched to the instrument, plus whatever the issuer said to expect.
  • Run your own pipeline: screening, in diligence, then commit or pass, with the rationale captured for your investment committee record.
  • Ask for what is missing. A request for information on an item goes to the issuer as a tracked question, not a chat message. Their answer lands against that item and moves it to received.
  • Suggest coverage with AI. Meridian reads the data room and marks each item covered, partial or missing, with citations to the pages it relied on. This runs on a separate axis from your own status and never overwrites it.
  • Generate an IC memo. A first draft covering thesis, terms, financials, key risks and a recommendation, built from the deal's own facts and your own findings, which you then edit, finalise and export as a PDF.

For the issuer

  • Publish an expected diligence list, which seeds every investor's workspace so they start from your checklist rather than inventing one. A single click fills it from a template matched to your instrument.
  • See who is in diligence: each party's stage, progress, risk flags and open requests, and answer every information request from one inbox.
Know this before you type

The issuer and platform administrators can see everything in an investor's workspace, including notes and risk flags. There is no private scratch space on a deal. That was a deliberate choice in favour of a single shared record, taken with the trade-off understood. If a thought should not be visible to the issuer, keep it out of the workspace.

AI suggestions are a drafting aid. They are not advice, not a recommendation, and not a substitute for reading the document. The citations exist so you can check the claim rather than trust it.

07Offers, commitments and settlement

An offer carries an amount, a currency and terms, and requires verification. You can make it personally or through one of your vehicles, which matters later: whatever you name here becomes the holder of the resulting position.

The issuer screens the offer and accepts it, which creates a binding commitment. The commitment records both who acted and which vehicle holds it, and flows into the portfolio.

On the Settlement tab the issuer sets out how to pay:

  • Per-chain deposit addresses across Armature L1, Ethereum, Bitcoin, Arbitrum, Base, Polygon, BNB and Tron, each with a QR code.
  • A payment link that opens the settlement view. A signed-in member sees it, and so does a counterparty who arrived on a room link, provided that link carries more than the teaser and the reader presents the access token issued at the moment they signed. Holding the URL is not enough. A teaser-only link renders no beneficiary details at all, rather than a refusal, because early circulation is the stage where there is nothing to pay for. Every reveal is recorded against the name and address on the signature.
  • A settlement instruction sheet combining the addresses, fiat wire details and a payment reference, on screen, printable or as a branded PDF. Bank account numbers are held encrypted at rest with the key outside the database, which is what makes the sheet payable: a masked number is not something any rail settles from.

A fiat payment request carries the payee's linked bank account, chosen by currency and then by verified status, and attached at the moment the request is raised, so an invoice already sent keeps naming the account it was raised against rather than following a later change. Where the payer is the one moving money, the act is confirmed rather than fired on one click: paying a capital call restates the amount in full, the deal, the due date and any note from the issuer, with the exact figure repeated on the button.

Read this twice

Deposit addresses and bank details are entered by the issuer, not verified by KXCO. Always confirm settlement details with the issuer over an independent channel before you transfer anything. Digital asset transfers do not reverse.

08Vehicles and the cap table

Few family offices invest as a single legal person. Meridian therefore models the structure directly, as a tree of any depth: a family office over a manco, over a fund, over an SPV, over a portfolio company, with trusts, holdcos, GP entities and individuals alongside.

A parent must sit in the same organisation as its child, because the tree describes one group's internal containment. An outside party with an interest in your vehicle is not a parent link, it is a line on the cap table.

How the cap table works

Percentages are the unit, and they are exact. Ownership is held as a precise percentage rather than a share count inferred through somebody's conversion assumption, so what the cap table says is what the documents say.

Scoping follows the obvious rule. Whoever runs the vehicle sees the whole table. A holder sees their own row, and the total is withheld from that view, so one investor cannot infer another's position by subtraction.

A deliberate refusal

Deleting a vehicle leaves its positions in place, orphaned. It never cascades into deleting the commitments and distributions attached to it. Money that really moved does not disappear because somebody tidied up a structure diagram.

09Capital calls

A call names an amount and a due date, and splits it across the holders as the cap table stood on the call date. A 500,000 call against a 90 / 5 / 5 table produces obligations of 450,000, 25,000 and 25,000.

Two rules shape how this behaves day to day.

  • Overdue status is always current. An obligation is overdue the moment its due date has passed without payment, and the status you see reflects that moment, not a flag set some earlier day.
  • Every payment carries its own value date, the day the money actually arrived, not the day somebody typed it in. A part payment in March and the balance in June are two dated contributions. This is not administrative neatness: preferred return accrues from the value date, so getting it wrong changes what people are owed.

The obvious mistakes are refused rather than absorbed. You cannot overpay an obligation, and the refusal names the outstanding figure. You cannot pay against a draft call. A payment cannot predate the call it settles. Withdrawing a call keeps its obligations and payments intact, because the money genuinely arrived, and it can still receive payments afterwards.

10Distributions and the waterfall

A vehicle's terms are four numbers: the preferred return rate, whether it is simple or compound, the GP catch-up percentage and the carried interest percentage. Only a manager can set them.

A distribution then runs four tiers in a fixed order: return of capital, preferred return, GP catch-up, then the carry split. The order is not configurable.

Some specifics that matter if you are checking the arithmetic:

  • Preferred return accrues on capital still outstanding, not on the amount originally contributed.
  • Invalid terms are refused rather than mis-paid. A catch-up rate at or below the carry rate is not accepted.
  • Capital is split by who held the vehicle when it was drawn, not by who holds it now. A draw date that predates the cap table is refused, and the message tells you when ownership actually starts.
  • Rounding is stated. Each tier's GP share rounds down and the remainder goes to investors.
  • Only settled money counts. Contributions come from paid capital calls, so an unpaid call cannot inflate the return-of-capital tier.
  • Carry with no GP appointed is refused, rather than quietly redistributed to investors.

Preparing, posting and correcting

A preview writes nothing, and refuses to show you a result that does not reconcile. A draft can be prepared by an administrator. Only a manager can post, and once posted it is immutable, with the terms used frozen onto the event so that it can still be explained after the terms change.

A mistake is corrected by reversal, not deletion: a linked contra event carrying negative allocations, with the original marked reversed and the reason recorded. Cumulative totals therefore stay right by simple addition, and the history never rewrites itself. Per-holder notices are generated as PDFs, for posted events only, and a holder sees their own allocations with the gross withheld.

11Bank reconciliation

Import a statement as CSV or OFX and match the money in against the capital call payments it settles. Two details are worth knowing.

First, ambiguous dates are never assumed. 01/02/2026 is two different days depending on where the file came from, so a file whose dates are ambiguous is refused until you state the order.

Second, a line is unmatched, matched or explicitly ignored with a reason. Nothing is silently dropped, so an unexplained line stays visible until somebody explains it.

Automatic matching needs two things, not one. The amount must exactly clear an outstanding obligation, and the line must identify who paid, by carrying the expected reference or the holder's name. Amount alone is never enough, however few candidates are left. Anything the software cannot positively identify is left for a person.

Meridian imports statements. It holds no banking credentials, has no direct feed into an account and cannot move money.

Meridian never touches your bank. It reads the statement you export and nothing more: no credentials are held, no account feed is connected, and no payment can be initiated from here. A compromise of this platform cannot move money.

12Management fees

A vehicle carries one fee schedule: an annual rate in percentage points, a basis, a frequency of monthly, quarterly, semiannual or annual, and a start date with an optional end.

The accrued figure is always current. What has accrued is worked out from the schedule, the periods elapsed and the base as it stood at the start of each period, so the number you read is never stale.

Two conventions are worth stating, because each changes the number:

  • A complete period charges the annual rate divided by the periods in a year. Two percent a year billed quarterly is 0.5 percent of the base, not two percent scaled by 92 over 365. That is what a schedule means by quarterly, and it makes consecutive quarters equal regardless of how many days they contain.
  • The period in progress is pro-rated by days elapsed, so a fee is never charged for time that has not passed.

The basis is either capital called or capital paid in. Both are chosen because both are knowable for a vehicle. A NAV basis is deliberately absent: Meridian holds no valuation for a vehicle, since valuations attach to a deal position rather than to the vehicle itself, so offering a NAV basis would compute against nothing and quietly return zero.

Performance fees are not here either. Carried interest is the waterfall's fourth tier and is already handled there, and a second mechanism would be a second answer to the same question.

Reading the schedule and the accrual needs the full cap table right, so a manager or a fund administrator can both see it. Changing the schedule is the manager alone.

13Currencies and consolidated reporting

Consolidation works on two rules.

  • Money is never stored converted. Amounts stay in the currency they happened in, and conversion happens only at the moment something is shown added up. A stored converted figure is wrong the day after it is written.
  • Every converted figure reports its rate, the rate's date and its source, shown next to the total rather than buried. A consolidated total whose rate you cannot see is a number nobody can check.
A missing rate is refused, never treated as parity

If no rate is available for a currency, Meridian does not fall back to 1 and does not drop the currency. It lists that currency with its untouched native amount, leaves it out of the total, and marks the total as incomplete. Both of the alternatives produce a figure that reads as authoritative and is wrong.

One honest note on where rates come from. They are entered records, each carrying its own source and date, and adding them is a platform administrator action rather than something a vehicle manager does. Meridian is not wired to a live market data feed, so a consolidated total is only as current as the most recent rate somebody entered, which is precisely why the date is displayed beside it.

Every converted figure carries its rate and the date that rate was entered. A consolidated total is therefore auditable to the day: you can see precisely which rate produced which number, rather than taking a single blended figure on trust.

14Who can do what

Owning a vehicle and operating it are separate questions. Ownership is the cap table. Operating rights are granted per vehicle, and a grant can name a person or an outside firm, which is how a third-party fund administrator works on your vehicles without joining your organisation.

One rule governs the whole design: the administrator prepares, the manager approves.

ActionManagerDeputy managerFund administratorHolder
Read the full cap tableyesyesyesown row
Change ownershipyesnonono
Edit vehicle termsyesyesnono
Issue a capital callyesyesyesno
Record a payment receivedyesyesyesno
Model a distributionyesyesyesno
Post a distributionyesnonono
Reconcile the bankyesyesyesno
Read the fee schedule and accrualyesyesyesno
Change the fee scheduleyesyesnono
See consolidated multi-currency totalsyesyesyesno
Grant and revoke operating rightsyesyesnono

Note the asymmetry between the two money operations. An administrator may issue a capital call, but only a manager may post a distribution or change ownership.

Deputy manager is what an organisation's admin holds on its own vehicles, and it is also grantable in its own right, because "run this vehicle but do not move money" is a real arrangement somebody will want to express. It is everything a manager can do except posting a distribution and changing ownership. An explicit grant still outranks what a seat implies, so a manager's rights can be given deliberately rather than inherited.

15Security and the record

  • Post-quantum identity. Every member holds a KXCO ID derived from an ML-DSA-65 key, the signature standard published by NIST as FIPS 204. It is the only identifier shown across the network.
  • Signatures bind to content. An e-signature is an ML-DSA-65 signature over the SHA-256 hash of the exact document presented, so a later edit is detectable rather than arguable.
  • A tamper-evident audit trail. Every state change is signed and recorded, including the administrative ones: an approval, a plan change, a posted distribution. The trail is designed so that alteration is detectable, not so that it is merely discouraged.
  • Access is scoped by default. Endpoints refuse before they read. A holder gets their own row, an administrator gets what it needs to prepare work, and no role can quietly widen itself.

The cryptographic foundation is public and independently scanned. You can read it rather than take our word for it: see the thirteen post-quantum packages we publish on npm and GitHub.

16Signatures, templates and the certificate

Signing is not a bolt-on here. A signature is the moment a deal becomes an obligation, so it is built into the record rather than delegated to a third party who keeps the evidence somewhere you cannot reach.

  • Send your own paper, or start from ours. Upload the document you already have, or pick from twenty-one prebuilt agreements that arrive with their signature blocks already positioned. Either way the next step is naming the parties.
  • Keep what you send often. Save a document with its whole field layout as a template. Your firm's NDA is placed once and sent for the rest of the year. The template holds its own copy of the paper, so replacing the original later never changes what the template sends.
  • Place what each party fills. Signature, initials, printed name, date and free text, plus tick boxes for the confirmations and elections an institutional agreement makes separately from the signature. A required tick box holds the signature until it is ticked, which is what turns a representation into a condition of signing.
  • Choose the order. Send to everybody at once, or in sequence so party three never sees the document before party one has agreed to anything.
  • Copy the people who need the executed document and are not signing it. Counsel, the fund administrator, compliance. They receive the executed copy when it completes, addressed as what they are, and the record shows when each of them got it.
  • Set a date it has to be signed by. The deadline is named in the invitation and in every reminder, so nobody discovers it by being refused. Move it whenever you need to and every signature already collected is kept, with the outstanding parties told the new date.
  • Reminders go out for you. At three days, at seven and at fourteen, to the party whose turn it actually is.
  • A refusal comes with a reason. Almost every decline in practice is procedural: the wrong entity, the wrong signatory, a term still being negotiated. Which one it is decides what you do next, so the signer is asked and you are told.
  • Send it to the right person instead. Reassign a signature to the correct signatory without withdrawing the document or losing the signatures already on it.
  • The signer leaves holding both halves. The document they signed and the certificate that proves they signed it, offered at their own signature rather than at the end, so the first party on a four-party agreement is not empty-handed while the others take their time.
  • Your board tells you what needs you. A request that cannot be completed is named as such, with the reason and the thing to do about it, instead of sitting in a list looking like everything else.

The certificate is written to be filed. It names who signed and when they opened it, what they typed, the exact bytes the signature covers, the hash of those bytes, the signature itself and the key that produced it, with the steps to check all of it. It is the document your counsel keeps.

17Checking the record yourself

Evidence you have to ask us for is evidence that depends on us. Everything below is checkable by your own people, with tools that are not ours.

  • The signing key is published. The platform's public key sits at a public address with the verification recipe beside it, so a signature can be checked by somebody who has never had an account here.
  • Any implementation will do. The certificate publishes the signed bytes exactly as they were signed. Hash them, verify the ML-DSA-65 signature against the published key, and hash the file you hold to confirm it is the document the signature covers. Nothing in that sequence requires KXCO software.
  • The trail is sealed, not merely stored. Runs of audit entries are hashed into a root, each root chained to the one before it and signed. A row altered, removed or inserted changes the root and breaks the signature, and removing a whole run breaks the next root.
  • And the seal is written somewhere we cannot rewrite. Each sealed root goes onto Armature L1, and so does the digest of every signature. That is what fixes the date: a record whose root was written to a chain in August cannot cover anything invented in September, so the age of your evidence stops resting on our word and starts resting on a block.
  • Look it up yourself. The certificate names the chain, the transaction and an endpoint to ask. Fetch the transaction, find the digest inside it, and read the date off the block it sits in. Your counsel can do that without an account, without our help and without telling us they did.

Taken together, that answers all three questions a counterparty asks about an agreement: what was signed, by whom, and when.