Titandocs

Commitments

How every cycle of trading becomes one Merkle root on the Canton ledger.

Matching happens off-chain so it can be fast. The price of that speed is a question: how do you know the exchange's records are the ones it actually acted on? Titan's answer is a commitment: a fingerprint of everything that happened, published on the Canton ledger on a fixed cycle, that the exchange cannot change afterwards without it showing.

What happens every cycle

Your activity becomes event leaves

Your account activity during the cycle is recorded as event leaves, in the order it happened. The Merkle root over those leaves is your event root.

Your account is snapshotted

At the end of each cycle in which you had activity, your balance and open positions are written into a single state leaf. Its hash is your state root.

Both roots go into your payload

Your payload for the cycle holds the batch number, your own sequence number, the hash of your previous payload, your event root and your state root. The hash of the payload is your entry in the cycle's users tree.

Every active user is combined into one root

The payload hashes of everyone who was active in the cycle are sorted and combined into a single Merkle root: the users root.

One manifest is published on the ledger

Titan publishes a BatchManifest contract on Canton carrying the batch number, a timestamp, the users root and the hash of the previous manifest. That is the only thing published per cycle: one contract, however many people traded.

 your events ────► event root ──┐
 your account ───► state root ──┼──► your payload ──► leaf hash ──┐
 your previous payload hash ────┘                                  │
                                    other users' leaf hashes ──────┼──► users root
                                                                   │
   BatchManifest #n  { batchNum, timestamp, prevManifestHash, usersRoot }   on Canton

On the ledger, and off it

On the Canton ledgerOff the ledger, delivered to you
One BatchManifest per cycle, readable by anyone through the public observer party and by the auditorYour event leaves, state leaf and payload
The USDCx vaultThe sibling path that links your payload to the users root
Your deposit receipts and withdrawal requests, visible only to you and TitanYour full history of payloads

The ledger holds the fingerprints; your data comes to you over the API. You check one against the other. See Verify a cycle.

What a commitment does and does not do

A published root proves what the exchange recorded and pins it down for good. It does not stop a wrong record being written in the first place. It makes one provable: your signed orders, your leaves and the root on the ledger are that proof.

On this page