SURFACE · 03 / OMA · ON-CHAIN

Open Modular Account.

The institution's on-chain control plane. An ERC-7579 modular smart account that enforces the compiled mandate before settlement, executes multi-leg trades atomically, and emits cryptographic evidence by construction. Open source, deliberately.

oma · per-mandate accountlive
accounterc-7579 · modular
policy_commit0x9f4a…c1
bundlev2026.06 · 142 rules
status● ENFORCING
verdictsadmit · reject · escalate

Validator → Executor → Hook.

OMA runs inside the institution’s own trust boundary: policy, execution, and evidence as three composable modules on a per-mandate smart account, fed by the off-chain judgment core, executing against protocol rails including STN.

fig.02 / oma architecturepolicy gate · atomic execution · evidence hook
OFF-CHAIN SERVICESPCE · POLICYAIA · RECEIPTSMPC SIGNINGPMS WRITE-BACKOMA · ERC-7579 CONTROL PLANEOpen Modular AccountVALIDATOR · POLICY GATEmandate · concentration · sanctions → decisionIdEXECUTOR · ATMatomic multi-leg · callsRoot merkle · all or nothingHOOK · EVIDENCEEvidenceEmitted{planHash · decisionId · txHash}PINNED POLICY COMMITcompiled by PCE · versioned · counsel-attested03 / OPEN SUBSTRATE · INSIDE THE INSTITUTION'S TRUST BOUNDARYPROTOCOL RAILSSTN · SETTLEVENUE ROUTERERC-3643 ASSETSCHAIN · L1/L2FIG 02 · OMA · THE ON-CHAIN CONTROL PLANE

Three modules. One mandate check.

MODULE · 01
Validator · Policy Gate
Evaluates every leg against the pinned policy bundle (allocation, concentration, counterparty, sanctions) and returns a signed decisionId: admit, reject, or escalate, each with rule IDs and reasons.
MODULE · 02
Executor · ATM
Packs admitted legs into one atomic multi-leg transaction under a callsRoot Merkle commitment. All legs finalize together, or all revert. No settlement-failure tail, no T+1 reconciliation.
MODULE · 03
Hook · Evidence
Emits an EvidenceEmitted record per settlement (planHash, decisionId, callsRoot, txHash), bound to the same policy commit. Audit without reconstruction.

Mandates are compiled, not filed.

decision trajectory · excerpttrajectory.json
01// compiled by PCE · pinned on the account
02{
03  policyCommit: "0x9f4a…",
04  rule: {
05    id: "single_issuer_pct",
06    source: "IMA §4.2 · exposure ≤ 8.0%",
07    cap: 8.0,
08  },
09  verdict: {
10    intent: "SELL 12K UNITS · SCX-T",
11    result: "ESCALATE",
12    reason: "post-trade 8.4% vs cap 8.0%",
13  },
14}

The PCE compiles the mandate and the applicable regulation into a typed, versioned, counsel-attested policy bundle, pinned to the account by its commit hash. The Validator evaluates every leg against it before settlement, deterministically.

Verdicts carry rule IDs and reasons. Rejections are blocked outright; soft-band breaches escalate to a named officer whose override, with its rationale, becomes part of the record. Same policy hash, same intent, same verdict: an auditor can replay any decision, forever.

KEY PROPERTY
If it isn’t in the mandate, it doesn’t settle. And when it escalates, a human decides, on the record.
§ 06 / Access Testing

Join the waitlist for access testing.

Access is rolling out to a scoped cohort of regulated institutions through structured, milestone-gated pilots. Drop your details and we'll coordinate briefings, mandate intake, and pilot onboarding as your category opens.

§ JOIN WAITLIST · ACCESS TESTING
< 60 SEC
◦ INSTITUTIONAL EMAIL REQUIRED · PERSONAL ADDRESSES NOT ACCEPTED
CONFIDENTIAL · NO SPAM · CATEGORY-ORDERED ROLLOUT