How it works
The pieces that make up Titan, and the path one order takes from your signature to the ledger.
The pieces
- You: a wallet or sign-in credential, and a short-lived session key in your browser that signs your orders.
- The Titan API: the only thing your app talks to. It checks every request's signature and never lets one account read another's data.
- The matching engine holds the order books, matches orders, keeps balances and positions, writes every event to a durable log and builds the commitments.
- The price oracle builds index prices from several major exchanges, which anchor the mark price used for margin and liquidation.
- The Canton ledger holds the USDCx vault, your deposit and withdrawal contracts, and one published manifest per cycle.
One order, start to finish
You sign it
Your session key signs the order: market, side, size, price, time in force, a nonce and a timestamp. Every field is covered by the signature, so nothing can be changed on the way.
It is checked
The API verifies the request. The engine verifies your session key's signature, its expiry and its size cap, then your margin.
It is matched
The engine matches on price-time priority. Fills happen in milliseconds and update your balance and position immediately.
It is recorded
The order and every fill become event leaves in your own history, in the order they happened.
It is committed
At the end of the cycle your leaves are rolled into your payload, your payload into the users root, and the users root into a manifest published on Canton. See Commitments.
You can check it
Fetch your proof for that cycle and recompute the root yourself. See Verify a cycle.
Why match off-chain
Putting every order on a ledger makes an exchange slow and makes every trader public. Titan keeps matching, the fast part, off-chain, and uses the ledger for what it is good at: holding the funds, and holding an unchangeable record of what the exchange says happened.
What this does not cover
Like any exchange, Titan's engine sees orders in order to match them, and it is the engine that checks your signatures. What the commitments add is permanence: once a cycle is published, its record cannot be changed without the change showing on the ledger.