DYAD — Canton-native private swap exchange
DYAD
Exposure Protocol Liquidity Desks Builders
DEVNET LIVE
CANTON NATIVE SWAP PROTOCOL

THE MARKET CAN'T
FRONT-RUN WHAT
IT CAN'T SEE.

A concentrated-liquidity AMM where every swap is a bilateral Daml contract with exactly two readers. Pool depth, trade size, execution price and counterparty are structurally absent from the rest of the network — not obfuscated, absent.

Private Swap
2 READERS
FROMBAL 41,200
12,500.00
A AAPL.cc
TOBAL 1,204,880
2,431,875.40
$ USDCx
RATE194.550
IMPACT0.04%
MEV RISKNONE
SETTLESATOMIC
VISIBLE TO YOU + COUNTERPARTY ONLY
01 — THE LEAK

EVERY PUBLIC AMM LEAKS YOUR INTENT.

On a transparent chain, visibility isn't a setting you turn off. It's the consensus model. Your order is public data before it is a fill.

PUBLIC CHAIN · MEMPOOL
Your order arrives pre-announced
SANDWICHED
BOT · BUY 40 ETH · gas 812
YOU · SWAP 12,500 AAPL.cc → USDCx
BOT · SELL 40 ETH · gas 796
REALISED SLIPPAGE
1.84%
01Pool depth
READABLE
02Trade size
READABLE
03Execution price
BROADCAST
04Counterparty
INFERABLE
02 — THE MODEL

PRIVACY ISN'T A FEATURE. IT'S THE LEDGER.

Daml defines who may see and who may act on a contract. Canton enforces it at the protocol layer. A DYAD swap names two parties — so two parties is who the trade exists for.

BILATERAL DAML CONTRACT
Two signatories. Two readers.
M
MAKER
T
TAKER
NETWORK VIEW · 612 PARTICIPANTS2 CAN READ
DISCLOSURE MATRIX
Who sees what, by construction
FULL HASH ONLY NOTHING
PARTY
EXISTS
SIZE
PRICE
CPTY
POOL
Maker
Taker
Global Synchronizer
Every other participant
Your auditor · OPT-IN
Selective disclosure runs one direction only: you grant a reader, nobody claims one. Regulatory read access is a contract choice, not a network default.
1
Quote, off-ledger

The router prices your size against private pool state held by participant nodes. No mempool, no public order, nothing to observe.

2
Bind, bilaterally

A Daml Swap contract is created naming both parties as signatories. Its projection reaches two participant nodes and stops.

3
Settle, atomically

Both legs move in one transaction under the Global Synchronizer. Validators confirm validity against a commitment — never against your data.

03 — THE BOOK

CONCENTRATED LIQUIDITY. INVISIBLE POSITIONS.

The curve is ordinary. The disclosure isn't. LPs post ranges, earn settlement fees, and never reveal their book to the desk trading against it.

POOL · AAPL.cc / USDCx · 0.05%
Depth you can use, not read
194.55
SPOT
TICK LIQUIDITY
172.00◆ ACTIVE RANGE 186.40 — 203.10218.00
LP FEES · LAST 24H
$0
Fees accrue from settlement flow — not from selling your order flow to anyone.
0
FEE TIERS
0
BRIDGES USED
LP POSITION
Private by default

Your range, size and inventory are readable by you alone. Competitors can't map your book by watching the chain, because there is nothing on the chain to watch.

04 — THE DESKS

BUILT FOR BOOKS THAT CAN'T BE READ IN PUBLIC.

SEGMENT 01
Rotate size without telling the tape

A fund moving out of AAPL.cc into USDCx does not want that decision legible to anyone reading the ledger. On DYAD the rotation is a private contract, not a public signal.

0 bps
SIGNAL LEAK
T+0
SETTLEMENT
SCENARIO A
Quarter-end rebalance

$240M equity-token exposure unwound across four sessions. No pre-trade footprint, no reconstruction of the schedule from block data.

SCENARIO B
Redemption funding

Convert tokenised treasuries to stable settlement cash on the day, without the market pricing your outflow before you're done.

SCENARIO C
Mandate-level audit

Grant your administrator a standing read party. They see every fill; the market still sees none of them.

SEGMENT 02
Quote tight when nobody can copy you

Inventory and range placement stay unreadable, so spreads reflect risk instead of the cost of being observed. Toxic flow can't target what it can't locate.

4
FEE TIERS
NONE
MEV SURFACE
SCENARIO A
Inventory shielding

Skew your curve without publishing the skew. Range edges are contract state, not chain state.

SCENARIO B
Two-sided in size

Post blocks without advertising them. Takers see executable depth; the network sees a commitment hash.

SCENARIO C
Programmatic rebalancing

Automated range shifts via the ledger API — deterministic finality, no reorg exposure, no gas auction.

SEGMENT 03
Fund payroll without publishing the balance sheet

Treasury conversions between deposit tokens and stables settle same-second, with counterparties and amounts confined to the two participant nodes involved.

24/7
AVAILABILITY
DvP
ATOMIC LEGS
SCENARIO A
FX on ledger

USDCx to EURCx at size, without a public print that moves your next fill.

SCENARIO B
Overnight sweep

Idle balances into tokenised bills at 17:05 and back at 08:55 — a private, repeatable contract choice.

SCENARIO C
Policy guardrails

Counterparty allow-lists and size caps enforced in Daml, not in a spreadsheet after the fact.

SEGMENT 04
Give your asset a secondary market on day one

Any Canton-native holding can be paired. Transfer restrictions, lock-ups and eligibility checks travel with the token and are enforced inside the swap choice.

ANY
DAML HOLDING
ON-CHAIN
ELIGIBILITY
SCENARIO A
Permissioned pools

Restrict a pool to a named investor set. The pool exists only for parties who qualify to see it.

SCENARIO B
Lock-up aware curves

Unlock schedules are contract logic, so an ineligible fill simply cannot be constructed.

SCENARIO C
Custodian read party

Custody and admin see positions in real time through an explicit observer, not a data feed.

05 — THE STACK

SIXTY LINES OF DAML. NO BRIDGE.

The privacy isn't cryptography we bolted on. It's the authorization model of the contract, enforced by the Canton protocol on every participant node.

Swap.daml
-- one contract, two readers, nothing else
template PrivateSwap
  with
    maker    : Party
    taker    : Party
    offered  : Holding   -- AAPL.cc
    wanted   : Holding   -- USDCx
    curve    : TickRange
    expiry   : Time
  where
    signatory maker
    observer  taker      -- the entire audience

    choice Settle : (ContractId Holding, ContractId Holding)
      controller taker
      do
        now <- getTime
        assertMsg "expired" (now < expiry)
        px <- quote curve offered.amount
        -- both legs, one atomic transaction
        a <- exercise offered.cid (Transfer taker)
        b <- exercise wanted.cid  (Transfer maker px)
        pure (a, b)
Sub-transaction privacy
Nodes store only the projection they are party to.
Deterministic finality
Committed is settled. No reorgs, no probabilistic waiting.
No wrapped IOUs
Native holdings move. Nothing is minted against a bridge.
Ledger API first
gRPC and JSON endpoints your OMS already knows how to call.
ROADMAP
Devnet · v1 curve, audits underwayNOW
Mainnet beta · LP incentives in CCQ4 26
RFQ + AMM hybrid routingQ1 27
Cross-synchronizer settlementQ2 27
EARLY LIQUIDITY PROGRAMME

TRADE LIKE NOBODY'S
WATCHING. BECAUSE
NOBODY IS.

Devnet access, pool parameters and the technical brief. For desks and LPs deploying on Canton.

NO SPAM · TECHNICAL BRIEF + DEVNET KEYS