Banks and market infrastructures are building on Canton, and the first explanation a risk team hears may come from a vendor with a product built on it. A risk or governance committee needs a narrower set of facts before that meeting: who operates the network, what a counterparty or an infrastructure operator can see, who can change the rules, and which deployments are live rather than announced. This piece sets those out from Canton's own documentation, the institutions' own releases and the SEC staff's own letter, and marks where the public record stops.

Daml contracts and sub-transaction privacy

Canton applications are written in Daml, a smart contract language built for multi-party workflows. A Daml contract names its parties: signatories, who must authorise creating or archiving it, and observers, who may view it. Digital Asset's Canton Network whitepaper, updated in January 2024, sets out that model and states the design goal that "no party sees or stores information to which it is not a party".

Canton's documentation calls the result sub-transaction privacy: a transaction is broken into "views", and each party sees only its own portion. A bank and its custodian can both be parties to one transfer and still see different parts of it, while validators hosting neither receive none of its contract data. The same documentation contrasts this with chains that replicate all state and transactions to every node.

Synchronisers and the Global Synchronizer

Privacy on its own does not stop two parties from both believing they hold the same asset. Something has to fix the order of transactions, and in Canton that job belongs to a synchroniser, called a "sync domain" in the 2024 whitepaper. According to Canton's documentation, synchronisers coordinate consensus without storing state, while validators store only the data relevant to the parties they host. The whitepaper says anyone can deploy a synchroniser, and that parties sharing one can compose atomic transactions across applications.

The Global Synchronizer is the shared synchroniser for the Canton Network. Canton describes it as "a decentralized and transparently governed interoperability service", ordering and confirming messages with "a 2/3 majority Byzantine Fault Tolerant (BFT) consensus protocol". Its MainNet went live on 25 June 2024, according to the Linux Foundation. Canton's case for it is that applications can transact atomically with each other "without having to give up control to a shared pool of validators, or introducing bridges". Bridges and messaging protocols carry trust assumptions of their own, examined in our piece on how assets move between chains and legacy rails. A single shared synchroniser that many institutions depend on raises a different dependency, which is one of the questions at the end.

Validators and Super Validators: who runs it

Canton's documentation describes two tiers of operator. A validator is a participant node that hosts parties and stores their contract data. A Super Validator, in the words of Canton's technical reference, "runs everything a regular validator runs, plus the Global Synchronizer infrastructure and governance tooling": a sequencer that orders messages, a mediator that runs the confirmation step, a CometBFT consensus node and a public Scan service. Ordering needs agreement from more than two-thirds of Super Validator nodes, so the network tolerates fewer than a third of them failing or acting maliciously.

Neither tier is open in the way staking on Ethereum is. Adding or removing a Super Validator "requires a governance vote with a threshold of existing SV approval", according to the same reference, and DL News reported in April 2026 that the vote is a supermajority. Super Validators also vote to approve new validators, and the Canton Foundation's site says applications to operate a validator node are reviewed by its Tokenomics Committee; institutions can instead connect through an approved node-as-a-service provider. On 13 September 2026 the Foundation's homepage showed 58 Super Validator nodes and 727 validators.

What each participant can and cannot see

  • A public permissionless chain, such as Ethereum: transaction data is replicated to every node and readable by anyone, and anyone holding the required stake can help process transactions. Confidentiality, where it exists, comes from additional layers such as rollups or private channels.
  • A single-operator private ledger: participants typically see what the operator's access controls allow, while the operator can reach the whole record. Privacy between users rests on that operator's controls, not on the protocol.
  • Canton: a counterparty sees the views of a transaction it is party to, and a validator stores only the contracts of the parties it hosts. Super Validators' sequencers and mediators handle Global Synchronizer transactions, but the documentation says they do not decrypt message content and work from "encrypted envelopes and metadata". What the infrastructure operators can observe is therefore metadata, not contract terms, a distinction our piece on privacy in regulated finance treats as part of confidentiality.

A supervisor is not a default viewer either. On the whitepaper's model, a party sees a contract only if the contract makes it a stakeholder, such as a signatory or an observer. It follows that supervisory visibility has to be designed into the contracts or supplied from an institution's own records.

Canton Coin: what it does

Canton Coin is the Global Synchronizer's native token. Canton's tokenomics reference gives it three functions: "paying for network usage (traffic), rewarding infrastructure operators and application providers, and governing the network through Super Validator participation." A March 2025 post on the Canton Network's own blog says the coin launched with "no pre-mine, no pre-sale, and no special allocations to founders, VCs, or foundations"; that coins are minted every ten minutes as rewards for activity while usage fees are burned; that the network aims to issue and burn approximately 2.5 billion coins a year; and that synchroniser fees are denominated in US dollars. The same post says Super Validators initially received about 80% of rewards, and that until mid-2029 applications are eligible for 62% of the reward pool, with the Super Validator share falling to 20%.

These parameters are not fixed. The tokenomics reference records that CIP-0096, a Canton Improvement Proposal, capped the per-validator liveness reward at $0 with effect from 30 April 2026. This is not investment, legal or accounting advice, and Canton Coin is described here only for what it does inside the network. For a risk committee, the relevant fact is that the token's reward rules are set by votes of the institutions that operate the infrastructure.

The Canton Foundation and who decides

The Global Synchronizer Foundation was announced on 1 July 2024 with Linux Foundation support and 18 founding members, among them Broadridge, Digital Asset, Euroclear and Tradeweb. It became the Canton Foundation on 22 September 2025, which it described as "a change in name only". It describes its own role as fostering the growth of the Global Synchronizer and facilitating its governance, ensuring "transparency and member participation in decisions made by the Synchronizer's operators". The votes themselves, on Canton Improvement Proposals, new validators and Super Validators, and network parameters, are cast by the Super Validators, according to Canton's documentation.

The Foundation's board page, as viewed in September 2026, lists executives from DTCC, HSBC, BNY, Broadridge, Euroclear, Tradeweb, Cumberland and Digital Asset among its members, and names Dr Johnna Powell of DTCC as chair of the board of both the Canton Foundation and Linux Foundation Decentralized Trust. The general method for establishing who can change a protocol is set out in our piece on protocol control in diligence. For Canton, the answer runs through votes of approved, named institutions, so an institution's influence depends on whether it, or a provider it relies on, operates a Super Validator.

Which institutions are using it, and at what stage

DTCC: a pilot under SEC staff no-action relief, with launch announced for October 2026. On 11 December 2025 the staff of the SEC's Division of Trading and Markets issued a no-action letter to DTC covering the "Preliminary Base Version" of the DTCC Tokenization Services, which the letter describes as a pilot. Participants may elect to have entitlements to DTC-held securities recorded using distributed ledger technology, limited to securities in the Russell 1000 Index, US Treasury bills, notes and bonds, and ETFs tracking major indices, with tokens held in registered wallets on an approved blockchain. The letter does not name Canton. It is a staff position rather than a Commission rule, and it is withdrawn three years after the pilot launches.

On 15 July 2026 DTCC announced that DTC-held assets had been converted into tokens and used in "real production trades" in a DTC production environment, across workflows including collateral pledge, securities lending, Treasury repo delivery-versus-payment and central counterparty margin. More than 30 firms took part, among them BlackRock, Goldman Sachs, J.P. Morgan, CME Group and Nasdaq. The conversions "occurred on LFDT's Besu (DTCC's private network) and Canton (a public network)", and DTCC said the service would launch in October 2026. Its tokenization service page lists Canton among the eligible networks, alongside DTCC's Besu-based Collateral AppChain and Stellar.

Broadridge: live. Broadridge's Distributed Ledger Repo page says the platform is "Built on Canton Technology" and reports $7.5 trillion in settled volume for June 2026, an average of $357 billion a day, figures its 7 July 2026 release also gives. That release does not name the underlying ledger, and neither source says whether the platform settles on the Global Synchronizer or on another Canton synchroniser. Collateral that moves this way still raises the custody, settlement and legal-finality questions set out in our piece on tokenised collateral infrastructure.

The Canton Foundation's site names many more institutions as members and node operators. The deployment stage of each is a claim to check against that institution's own release.

Canton on the Paris 2026 programme

Canton had its own track at Proof of Talk Paris 2026. On 2 June, Jorgen Ouaknine was the guest in the fireside "Building Canton: A Conversation with the Foundation Board", moderated by Jacquelyn Melinek, and returned on 3 June for "Building DLT Infrastructure for Next Generation Capital Markets", moderated by Gareth Jenkinson. Also on 3 June, Dan Simerman, Sacha Ghebali, Luis Cuello and Ben Milne spoke on the panel "Building Applications on Canton", moderated by Danish Chaudhry, and Heslin Kim, Luca Burlando and David Palmer on "How Regulated Institutions Deploy on Canton", moderated by Yiannis Varelas. The same afternoon, 14:00–15:30, the programme ran a Proof of Pitch Canton Track. Titles, stages and times are on the Paris 2026 agenda.

What is still unresolved

Canton's critics have made their case in public. DL News reported on 9 April 2026 that critics argue the daily US Treasury repo volume Canton reports should not be treated like activity on other blockchains. Austin Campbell, whom the outlet described as "a Wall Street veteran turned crypto industry figurehead", called it "purely a post trade reporting secondary data feed" and asked: "If Canton vanished tomorrow, would there be any impact to the repo market?" In the same article, Yuval Rooz, interviewed as Canton Network's chief executive, argued that the real-world assets institutions tokenise are permissioned by nature: "The world is not permissionless. Even if we wanted it to be permissionless, it's just not." Canton's own whitepaper describes "a broader decentralized public permissioned network". On the evidence above, it is public in that institutions connect and transact across it, and permissioned in that approved institutions run and govern it.

Three further points remain open.

  1. Distribution. DL News reported that a large amount of Canton Coin was accumulated by Super Validator institutions that joined the network early, and that critics argue this created an uneven playing field that will discourage other institutions from committing.
  2. Record-keeping. The whitepaper says participant and synchroniser operators can configure their nodes to prune historical data, trading auditability against obligations such as the right to erasure under the EU's General Data Protection Regulation, and can move history to offline storage instead. Which policy applies depends on who runs each node that holds a given record.
  3. Supervision. The SEC staff letter is specific to DTC's service and does not name Canton. Two international reports on tokenisation from October 2024, by the BIS and the CPMI and by the Financial Stability Board, treat the technology in general terms and do not name Canton. No standard-setter or supervisory assessment of Canton by name was found in preparing this piece.

Questions a risk committee should ask

  • Who can approve a change to the Global Synchronizer's code or parameters, what approval threshold applies, and does our institution, or a provider we rely on, operate a Super Validator with a vote?
  • What will Canton Coin do in our operations: paying traffic fees, earning rewards for nodes or applications we run, or both? How would we hold and record any coin we receive?
  • Where a supervisor needs visibility, what provides it in production: the supervisor's party as an observer on the relevant contracts, or reporting from our own node? Has the supervisor accepted that route?
  • Which pruning policy applies on each node, ours, our counterparty's and the synchroniser's, that holds records we may need for a dispute or an audit?
  • What happens to our pending transactions if the Global Synchronizer loses the more-than-two-thirds agreement it needs to keep ordering them, or if a Super Validator we connect through is removed?
  • Which of a vendor's claims describe its own live deployment, and which describe another institution's pilot or announcement?