Pre-Clearance / Architecturejilsovereign.com/products/pre-clearance/architecture
Architecture deep-dive

JIL Corridor Architecture

Inter-custody settlement attestation - MITM resistance - beneficiary binding - BFT quorum

Hybrid architecture: high-throughput Verdict-Engine compute runs on Snowflake Financial Services Data Cloud; the trust anchor lives on JIL L1 across 10 sovereign validators in 13+ jurisdictions running 14-of-20 BFT consensus. Every transfer parameter is cryptographically bound into the signed envelope so an adversary cannot swap the destination wallet mid-flight, and receiver-side verification fails closed if any binding does not match.

175
Checks across 16 categories
14/20
BFT consensus · 13+ jx
5 bps
Per attestation · $1 floor
902(14)
FRE civil-admissible CREB™

§ 01Business Architecture

AudienceTop-tier institutional digital-asset custodians (Fireblocks, Anchorage, BitGo, Coinbase Custody, Komainu, Copper); Wave 2 (Zodia, Hex Trust, Sygnum, Standard Custody, Bakkt Trust, Gemini Custody); Wave 3 (regional and digital-asset specialist custodians, prime brokers, family offices).
BuyerChief Compliance Officer, Head of Travel Rule, Head of Settlement Operations, General Counsel.
Economic ModelTier 1 transactional 5 bps / $1 floor per attestation. Tier 2 commit blended 3-4 bps. Tier 3 enterprise annual flat with Snowflake Native App. No custody, no transmission, no contingency.
Volume CaptureInstitutional inter-custody settlement is estimated at $50B-$200B daily globally. $1B daily capture at 5 bps = ~$182M annual revenue.
PartnersSnowflake Financial Services Data Cloud (compute + Data Clean Rooms + Native App); Travel Rule networks (TRP / Notabene / Sygna) consumed as inputs; wallet intelligence (TRM / Chainalysis / Elliptic) consumed as inputs.

§ 02Hybrid Architecture

Compute Layer · Snowflake

The Verdict Engine runs on Snowflake compute. Inherits FedRAMP High, SOC 2 Type II, ISO 27001, HITRUST, PCI DSS. 175 checks across 16 categories run against partner-shared and JIL-curated data sets. Portable to AWS GovCloud / Azure Government / Oracle Cloud on customer request.

Trust Anchor · JIL L1

10 sovereign validators scaling to 20 active + 20 standby across 13+ jurisdictions. 14-of-20 BFT consensus. Ed25519 + Dilithium-III hybrid signatures with ML-DSA-65 post-quantum and Kyber KEM. Five sovereign vaults across US, Switzerland, UAE, Singapore, Brazil.

Data Clean Rooms

Snowflake Data Clean Rooms let Custodian A and Custodian B contribute counterparty data without revealing raw inputs to each other. The Clean Room emits a verdict to both parties; neither gains access to the other's underlying data.

Snowflake Native App

Corridor deployable as a Native App inside each custodian's own Snowflake account. Data residency stays inside the custodian perimeter. Preferred for Tier 2 and Tier 3 customers with existing Snowflake footprint.

Beneficiary Binding

Every settlement parameter (destination wallet hash, asset symbol, amount, originator, beneficiary KYC reference, Travel Rule payload hash, expiration timestamp) is bound into the BFT-signed envelope. A mid-flight wallet-address swap breaks the signature and is rejected by Custodian B before credit.

Trust Boundary Separation

The Snowflake compute layer never holds JIL L1 signing keys. Verdicts are produced as canonical JSON, hashed, and forwarded to JIL L1 for the BFT signing ceremony. A compromise of the compute layer cannot forge an attestation.

External data sourcesOFAC SDN + EU + UK + UN sanctions lists; Travel Rule networks (TRP, Notabene, Sygna); wallet intelligence (TRM, Chainalysis, Elliptic); custodian-provided counterparty KYC and Travel Rule payloads; FATF Recommendation 16 vendor messages; OpenSanctions; bank-fingerprint clustering.

§ 03Process Flow

Snowflake (compute) JIL L1 (trust anchor) Custodian rails Custodian A intentSigned JSON envelope Verdict Engine (Snowflake)175 checks · Data Clean Room Canonical verdict hashHash-only on the wire Counterparty policiesInbound caps · CL-Room 14-of-20 BFT signing ceremony Beneficiary binding · Ed25519 + Dilithium-III + ML-DSA-65 Bound fields Wallet hash Asset + amount KYC ref Travel Rule Tranche idx Expiry Custodian A movesAsset moves on own rails Custodian B verifiesBindings match · credit allowed MITM swap caughtBinding mismatch · fail closed CourtChain™ CREB™ - FRE 902(14) - 15+ year retention
01
Intent submitted
Custodian A signs and submits a transfer-intent envelope via REST, Native App, or SDK.
02
Engine + Clean Room
Verdict Engine runs 175 checks in Snowflake; Clean Room reconciles both custodian inputs without revealing raw data.
03
BFT signing
Verdict hash forwarded to JIL L1. 14-of-20 BFT quorum signs the envelope with hybrid Ed25519 + Dilithium-III.
04
Custodians act
Both custodians receive the signed verdict. Custodian A moves asset on its own rails. Custodian B verifies bindings before credit.
05
CREB™ sealed
CREB™ anchored on CourtChain™. Bundle reference returned to both parties. 15+ year retention. Civil-admissible under FRE 902(14).

§ 04MITM Resistance - the threat model

Threat

Mid-flight wallet swap

An adversary inside the transmission path or compromising one custodian's UI tries to swap the destination wallet between the moment of attestation and the moment of credit.

Defense

Beneficiary binding

The destination wallet address hash is one of the parameters cryptographically bound into the BFT-signed envelope. Any swap breaks the signature; receiver verification fails closed.

Witness

14-of-20 BFT

The signature is produced by a quorum across 13+ jurisdictions. Compromising the Snowflake compute layer alone does not produce a forged attestation; L1 keys never touch compute.

§ 05Plain English Example

Worked example · Fireblocks -> Anchorage, $250M USDC

Negotiation layer in action

Fireblocks signals intent to send $250M USDC from a sub-account to Anchorage Custody for a hedge-fund client. Anchorage's inbound policy caps acceptance at $50M / 24-hour window for this counterparty and asset. Corridor reads both transfer policies, runs the 175-check Verdict Engine in a Snowflake Clean Room (Travel Rule payload validated, OFAC + sanctions clean, source-of-funds attested, wallet-intelligence clusters clean, anomaly scan clean), and proposes a five-tranche schedule: $50M / $50M / $50M / $50M / $50M over five business days.

Both compliance desks confirm the schedule. Each tranche is independently attested at execution time by JIL L1 at 14-of-20 BFT. On Day 3 a new entity is added to the OFAC SDN list; Corridor surfaces an exception before the Day 3 tranche signs. Compliance reviews the exception, confirms the counterparty is unaffected, and releases the leg. The remaining legs complete. One CREB™ bundle covers the negotiated sequence; each tranche is referenced by its individual L1 anchor; the bundle is the artifact a future regulator or auditor uses to reconstruct the entire transaction.

§ 06Capabilities Summary

Verdict Engine175 deterministic checks across 16 categories: Travel Rule, OFAC + global sanctions, source-of-funds, wallet intelligence, counterparty KYC, jurisdictional eligibility, transfer-pattern anomaly, recipient-policy intersection.
ComputeSnowflake Financial Services Data Cloud (FedRAMP High + SOC 2 Type II + ISO 27001 + HITRUST + PCI DSS inherited). Portable to AWS GovCloud / Azure Government / Oracle Cloud.
Trust anchorJIL L1, 10 sovereign validators scaling to 20 + 20 standby across 13+ jurisdictions. 14-of-20 BFT. Ed25519 + Dilithium-III hybrid + ML-DSA-65 post-quantum + Kyber KEM.
Beneficiary bindingWallet hash + asset + amount + originator + beneficiary KYC ref + Travel Rule payload hash + tranche index + expiry, all bound into the signed envelope. Mid-flight swap fails closed.
Custody postureNo custody. No transmission. No bridge. No wrapper. Assets move on the custodians' own rails; JIL is never in the funds path.
EvidenceCourtChain™ CREB™ per attestation. FRE 902(14) self-authenticating. 15+ year retention. Reproducible by any party without JIL's cooperation.
LatencySub-2 seconds for standard checks. Under 10 seconds for full deep screen. Tranche scheduling computed in the same envelope.
IntegrationREST API, Snowflake Native App, or SDK embed (Python / Go / TypeScript / Java).