Protocol Architecture

Attested Convergent Finality Explained

Definition

Attested Convergent Finality, or ACF, is the consensus model of the JIL L1, the shared ledger several institutions rely on at the same time. The short version is closed operation, open verification.

Closed operation means JIL operates every validator on the JIL L1. They are named, with one accountable operator in the jurisdictions they sit in. There are no anonymous participants, and JIL does not present them as independent third parties, because they are not. When a result is wrong, one company owns it.

Open verification means the checking is not ours to control. Any institution entitled to the record can verify JIL's work on its own hardware, continuously, and can publish a contradiction on its own authority, without needing JIL's cooperation or permission. Because that verification sits outside the path a transaction takes, a customer can check JIL without being able to stop JIL. Customers also keep their own signed copies of the records that concerned them, so JIL cannot quietly rewrite history: the evidence lives in more places than one.

Why It Matters

Public networks got one thing right and one thing badly wrong. Right: anyone can check the work. Wrong: nobody is accountable for it. Operators are anonymous, results can be reordered after the fact, the rules are set by whoever holds the most influence at the time, and a bank that needs a name on the failure has none to point at.

Traditional vendor databases are the mirror image. There is a company on the contract and a name on the failure, which is real progress, but the customer has no way to check the work. You get a report, an audit once a year, and a promise. If the vendor's copy and your copy disagree, the vendor's copy usually wins.

ACF takes the accountable operator from one model and the outside verification from the other. That combination is the quadrant regulated finance has actually been asking for, and the one nobody has occupied.

How JIL Sovereign Addresses This

The benefits are ordinary and dull, which is the point. Every entry is attributable to a named signer. Finality is deterministic and single block, so a settled result stays settled and there are no reorganisations. Signatures are post-quantum, so records signed today stay defensible for their full evidentiary life. When the system cannot be certain, it stops rather than proceeding, because a halt is investigable and a wrong result recorded as final is not. And the record is court ready: what you hold is evidence you can produce yourself.

Parts of ACF are in operation today and parts are still being built.

How the three models compare

Question Public network Traditional vendor database JIL Sovereign, Attested Convergent Finality
Who operates the network Anonymous, unnamed operators One vendor, closed to inspection JIL only, every node named, one company accountable for all of them
Outside verification Anyone can verify Nobody outside can verify Any entitled institution can verify continuously on its own hardware
Can checking the work stop the service Verification is part of operation Not offered Verification sits outside the transaction path and cannot halt service
Accountability for a wrong result No named party to hold responsible Named vendor, but you cannot check the claim Named operator plus a claim you can check yourself
Rewriting history Reordering after the fact is possible The vendor holds the only copy Customers hold their own signed records
Finality Probabilistic, confirmations accumulate Whatever the vendor's database currently says Deterministic and single block, no reorganisations
Behaviour under uncertainty Proceeds and resolves later Proceeds, usually silently Stops rather than finalising a result it is not certain of
Signature cryptography Mostly classical elliptic curve Vendor's choice, rarely disclosed Post-quantum ML-DSA-65, FIPS 204

Frequently Asked Questions

Who operates the L1 validators?

JIL Sovereign Technologies, Inc. operates every L1 validator. They are named, and one company operates every node and answers for the result. There are no anonymous participants and no third-party operators. JIL does not describe them as independent, because they are not. Accountability here comes from naming the operator, not from hiding it behind a crowd.

What happens if something goes wrong?

The system stops rather than finalising a result it is not certain of. That is a deliberate trade. A refusal to proceed is visible, alertable and investigable; a wrong result recorded as final is none of those things. For a financial record, correctness outranks availability, so uncertainty produces a halt rather than a guess.