A shock in one tenor's collateral cannot reach another's. That isn't a policy — it's the architecture.
One shared liquidity base. A bad asset in one corner raises borrow costs and liquidation risk for every user in the pool.
Each tenor settles its own collateral and its own liquidations. A 30-day shock stays a 30-day problem.
Per-market collateral factors. Each tenor sets its own collateral requirements, tuned to that term's risk.
Isolated liquidations. Liquidation engines act within a single market — no cross-market seizure of collateral.
No shared insurance fund. Bad debt in one tenor is absorbed by that tenor alone — it is never socialized.
Need-to-know privacy. Canton discloses a position to its counterparties and validating parties only — not the whole network.
Isolation limits blast radius. It does not eliminate a bug in the code itself.
Each market still depends on accurate price feeds to value its own collateral.
A bad collateral asset can still impair the market that accepted it — just not the others.
No code reaches mainnet without a completed audit. This page updates the day a report lands.